Skip to content

The Gentlemen

The Gentlemen is a rapidly growing ransomware-as-a-service operation, also tracked as Storm-2697, that emerged in mid-2025 after operators associated with the Qilin ecosystem split off and launched an independent program.

Profile source: Mallory opens in a new tab

The Gentlemen

Family profile

The Gentlemen is a rapidly growing ransomware-as-a-service operation, also tracked as Storm-2697, that emerged in mid-2025 after operators associated with the Qilin ecosystem split off and launched an independent program. It has become one of the most active ransomware brands globally through aggressive affiliate recruitment, unusually favorable revenue sharing, and a packaged intrusion workflow that lowers the barrier for affiliates. The operation is widely associated with the actor alias hastalamuerte and has been linked in public reporting to the former ArmCorp affiliate crew.

The malware family is notable for cross-platform ransomware capability and aggressive propagation. Its primary Windows encryptor is written in Go and obfuscated, while additional variants have been reported in C for other environments including ESXi. The ransomware targets Windows, Linux, NAS, BSD, and ESXi environments, uses hybrid public-key and symmetric cryptography, and supports partial encryption for speed on large files. It commonly combines encryption with data theft for double extortion and can deploy across a domain using Group Policy abuse, administrative shares, PsExec, PowerShell remoting, WMI, WinRM, scheduled tasks, and related remote execution methods. A standout feature is a worm-like spread mode that can recursively propagate from a single foothold across reachable network systems.

The Gentlemen’s operators and affiliates typically prioritize enterprise intrusions over mass phishing. Reported initial access methods include exploitation of internet-facing edge infrastructure such as VPNs, firewalls, and other perimeter devices, brute-force attacks, use of stolen or leaked credentials, and cooperation with initial access brokers. Public reporting also links the operation to inventories of pre-compromised edge devices and to exploitation or active tracking of multiple high-profile vulnerabilities affecting enterprise access infrastructure and Windows environments.

Post-compromise behavior includes Active Directory reconnaissance, credential theft, privilege escalation, lateral movement, exfiltration, and broad defense evasion. The operation has used custom backdoors, proxy malware, remote administration tools, and commodity offensive tooling to maintain access and stage ransomware. It is especially notable for repeated use of EDR- and AV-killing frameworks, including bring-your-own-vulnerable-driver techniques to terminate protected security products at kernel level. Additional anti-recovery and anti-forensics behavior includes disabling Microsoft Defender, stopping backup, database, virtualization, and security services, deleting shadow copies, clearing Windows event logs, wiping free space in some modes, and self-deleting after execution. Persistence has been observed via scheduled tasks, registry autoruns, and remote access tooling.

Victimology indicates broad global targeting across dozens of countries, with recurring impact in manufacturing, professional and business services, technology, healthcare, transportation, financial services, construction, logistics, and other enterprise sectors. The operation appears opportunistic but strongly enterprise-focused, with emphasis on organizations where operational disruption increases payment pressure. Like many Russian-speaking ransomware operations, it has been reported to avoid targeting CIS entities.

The Gentlemen is best understood as a mature, human-operated RaaS platform that integrates proven ransomware tradecraft, cross-platform lockers, strong affiliate support, double extortion, and unusually aggressive self-propagation into a fast-scaling extortion ecosystem.

Capabilities

  • Brute Force
  • Byovd
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance

Operational record

5
Indicators
1
YARA rules
3
Ransom notes
1
Leak sites
0 available

Credential Theft

  • DumpBrowserSecrets
  • Hydra
  • KslDump
  • KslKatz
  • XenAllPasswordPro

Defense Evasion

  • EDRStartupHinder
  • GFreeze
  • GLinker

Discovery Enum

  • ADFind
  • BloodHound
  • Censys
  • CertiHound
  • MANSPIDER
  • PowerZure
  • Shodan
  • gogo scanner
  • ldapdomaindump

Exfiltration

  • rclone

Networking

  • Chisel-ng
  • ProxyChains
  • Tor / Onion C2
  • openconnect

Offsec

  • Custom Go Locker (Windows/Linux/NAS)
  • NetExec (nxc)
  • PetitPotam
  • PrivHound
  • RegPwn
  • RelayKing
  • Responder
  • TrustedSec Titanis
  • Velociraptor
  • ZeroPulse
  • ntlmrelayx

RMM Tools

  • AnyDesk

Published indicators

Tox

1 total
  • F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098E

Sha1

4 total
  • c12c4d58541cc4f75ae19b65295a52c559570054
  • c0979ec20b87084317d1bfa50405f7149c3b5c5f
  • df249727c12741ca176d5f1ccba3ce188a546d28
  • e00293ce0eb534874efd615ae590cf6aa3858ba4

Recent claims

Reported operators

Threat actors

9 named in public reporting
Akira

The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.

Spikey Scorpius

The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.

HasanBroker

The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.

Storm-2697

The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.

LARVA-368

The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.

TheGentlemen

This year saw the emergence of The Gentlemen, a prominent example of a group operating under the ransomware-as-a-service (RaaS) model.

phantom_mantis

In an analysis of the ransomware in late last year, LevelBlue's Cybereason team described The Gentlemen as a "highly adaptive, fast-moving ransomware operation" that combines mature ransomware techniques with RaaS features, double extortion, cross-platform lockers, and flexible propagation, and affiliate support.

ArmCorp

The Gentlemen за неполный год из осколка Qilin превратился во второго по активности RaaS-оператора в мире. Microsoft Threat Intelligence ведёт их инфраструктуру как Storm-2697.

Hastalamuerte

The Gentlemen is an active ransomware and extortion operation that emerged publicly in the second half of 2025 and rapidly scaled into a high-volume threat actor.

Exploited software

Vulnerabilities linked to The Gentlemen

9 CVEs

MITRE ATT&CK

The Gentlemen in ATT&CK

88 distinct techniques

Techniques

88 techniques
T1567 Exfiltration Over Web Service T1021.002 SMB/Windows Admin Shares T1562 Impair Defenses T1059.001 PowerShell T1486 Data Encrypted for Impact T1570 Lateral Tool Transfer T1070.004 File Deletion T1485 Data Destruction T1046 Network Service Discovery T1068 Exploitation for Privilege Escalation T1053 Scheduled Task/Job T1021 Remote Services T1543.003 Windows Service T1070.001 Clear Windows Event Logs T1657 Financial Theft T1562.001 Disable or Modify Tools T1490 Inhibit System Recovery T1033 System Owner/User Discovery T1018 Remote System Discovery T1489 Service Stop T1135 Network Share Discovery T1059.003 Windows Command Shell T1007 System Service Discovery T1083 File and Directory Discovery T1053.005 Scheduled Task T1057 Process Discovery T1047 Windows Management Instrumentation T1112 Modify Registry T1069 Permission Groups Discovery T1218.002 Control Panel T1021.006 Windows Remote Management T1003 OS Credential Dumping T1090 Proxy T1059 Command and Scripting Interpreter T1041 Exfiltration Over C2 Channel T1518 Software Discovery T1484.001 Group Policy Modification T1036.005 Match Legitimate Resource Name or Location T1027 Obfuscated Files or Information T1053.003 Cron T1547.009 Shortcut Modification T1573.002 Asymmetric Cryptography T1106 Native API T1491.001 Internal Defacement T1564.003 Hidden Window T1569.002 Service Execution T1036.004 Masquerade Task or Service T1078 Valid Accounts T1562.004 Disable or Modify System Firewall T1105 Ingress Tool Transfer T1189 Drive-by Compromise T1566 Phishing T1090.003 Multi-hop Proxy T1070 Indicator Removal T1203 Exploitation for Client Execution T1491 Defacement T1078.002 Valid Accounts: Domain Accounts T1133 External Remote Services T1190 Exploit Public-Facing Application T1072 Software Deployment Tools T1136 Create Account T1543 Create or Modify System Process T1547 Boot or Logon Autostart Execution T1187 Forced Authentication T1557 Adversary-in-the-Middle T1110 Brute Force T1552 Unsecured Credentials T1555 Credentials from Password Stores T1087 Account Discovery T1087.002 Account Discovery: Domain Account T1482 Domain Trust Discovery T1526 Cloud Service Discovery T1021.001 Remote Services: Remote Desktop Protocol T1021.004 Remote Services: SSH T1563 Remote Service Session Hijacking T1005 Data from Local System T1039 Data from Network Shared Drive T1074 Data Staged T1074.001 Data Staged: Local Data Staging T1114 Email Collection T1048 Exfiltration Over Alternative Protocol T1048.001 Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol T1537 Transfer Data to Cloud Account T1071 Application Layer Protocol T1071.001 Application Layer Protocol: Web Protocols T1219 Remote Access Software T1572 Protocol Tunneling T1573 Encrypted Channel

Reporting

Research mentioning The Gentlemen

Jul 22
Belgium Ccb News

Threat Intelligence Report: Qilin (Agenda) Ransomware | CCB Belgium

Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.

Jul 22
Itsecurityguru

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

Jul 21
Cyber Security News

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.

Jul 21
Emsisoft

The State of Ransomware in Q2 2026

Jul 20
Cysecurity News

Ransomware activity climbs in Q2 2026 as leading gangs consolidate attacks and AI streamlines extortion efforts - CySecurity News - Latest Information Security and Hacking Incidents

Jul 17
Cyberveille

Rapport GRIT Q2 2026 : 2 279 victimes de ransomware, Qilin et The Gentlemen dominent | CyberVeille

Jul 16
ReliaQuest

Ransomware and Cyber Extortion in Q2 2026

Nov 20
Csirt Sk

Aktuálna kampaň APT skupiny Qilin zasahuje aj Slovensko | CSIRT.SK

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.