A new ransomware group known as Gentlemen has launched a series of attacks targeting organizations in at least 17 countries, employing a double extortion model that involves both data exfiltration and encryption. The ransomware, developed in the Go programming language, leverages advanced techniques such as Group Policy Object (GPO) manipulation and Bring Your Own Vulnerable Driver (BYOVD) tactics to disable security defenses and propagate laterally within corporate networks. Industries affected include healthcare, manufacturing, and insurance, with the group specifically focusing on medium to large enterprises. The malware requires a specific --password argument to execute, serving as an anti-analysis measure, and offers operators various command-line options to control its behavior and evade detection.
Analysts have identified Gentlemen as one of the most active emerging ransomware threats of 2025, with rapid expansion across North America, South America, and the Middle East. The group’s sophisticated evasion and propagation methods, combined with its aggressive targeting of sensitive data, underscore the urgent need for enhanced monitoring and defensive measures in enterprise environments. The campaign’s use of double extortion ensures that even organizations with robust backup strategies remain vulnerable to data leaks and reputational damage if ransoms are not paid.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting revealed that Gentlemen uses Group Policy Object manipulation and Bring Your Own Vulnerable Driver techniques to disable security tools, move laterally, and evade detection. The disclosures also described its use of X25519 and XChaCha20 encryption, selective file-segment encryption, and the README-GENTLEMEN.txt ransom note.
Following its initial appearance, Gentlemen ransomware spread to medium and large organizations across at least 17 countries in North America, South America, and the Middle East. The campaign affected multiple industries and used double extortion, combining data theft with file encryption.
Gentlemen ransomware was first observed in August 2025. Researchers identified it as a Go-based ransomware family designed for cross-platform attacks and protected by a required password argument for execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.