The Gentlemen, also tracked as Storm-2697, has rapidly expanded into one of the most active ransomware-as-a-service operations, with reporting indicating it has been active since at least July 2025 and may have previously operated as the ArmCorp affiliate of Qilin. The group uses ransomware variants written in C and Go, relies on multiple initial access methods, and has developed custom tooling including a Go-based backdoor and the GentleKiller framework designed to disable EDR protections. Researchers said the operation formalized its RaaS model around September 2025 and attracted affiliates by offering an unusually high 90% share of ransom payments.
The group’s activity accelerated sharply in 2026, with one cited count attributing 580 claimed victims across 77 countries through July 7, including 103 in the manufacturing sector, and 117 claimed victims in June alone. In May 2026, The Gentlemen also partnered with HasanBroker’s BreachForums to recruit affiliates, penetration testers, and initial access brokers, while an alleged insider reportedly leaked an internal database the same month. The campaign’s scale has pushed The Gentlemen to the second-most active RaaS program of 2026 by victim count, underscoring the need for organizations to prioritize patching exploited vulnerabilities, hardening MFA and EDR defenses, segmenting networks, and ensuring resilient backups.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The group's claimed victim volume surged in 2026, with June 2026 identified as its peak month at 117 claimed victims.
Unit 42 reports that an alleged insider leaked an internal database belonging to The Gentlemen during May 2026.
In May 2026, The Gentlemen partnered with HasanBroker's BreachForums to recruit affiliates, penetration testers, and initial access brokers.
Reporting cited by Unit 42 says the group transitioned into a formal ransomware-as-a-service operation around September 2025. The program reportedly offered affiliates a 90% share of ransom payments.
Unit 42 says The Gentlemen ransomware operation, also tracked as Storm-2697, has been active since at least July 2025 and likely previously operated as the ArmCorp affiliate of Qilin.
A source cited by Unit 42 counted 580 claimed victims through July 7, 2026, spanning 77 countries, including 103 in manufacturing. The report says this made The Gentlemen the second most active RaaS program of 2026 by victim count.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.