Credential Theft
- DumpBrowserSecrets
- Hydra
- KslDump
- KslKatz
- XenAllPasswordPro
The Gentlemen is a rapidly growing ransomware-as-a-service operation, also tracked as Storm-2697, that emerged in mid-2025 after operators associated with the Qilin ecosystem split off and launched an independent program.
Profile source: Mallory opens in a new tabThe Gentlemen
The Gentlemen is a rapidly growing ransomware-as-a-service operation, also tracked as Storm-2697, that emerged in mid-2025 after operators associated with the Qilin ecosystem split off and launched an independent program. It has become one of the most active ransomware brands globally through aggressive affiliate recruitment, unusually favorable revenue sharing, and a packaged intrusion workflow that lowers the barrier for affiliates. The operation is widely associated with the actor alias hastalamuerte and has been linked in public reporting to the former ArmCorp affiliate crew.
The malware family is notable for cross-platform ransomware capability and aggressive propagation. Its primary Windows encryptor is written in Go and obfuscated, while additional variants have been reported in C for other environments including ESXi. The ransomware targets Windows, Linux, NAS, BSD, and ESXi environments, uses hybrid public-key and symmetric cryptography, and supports partial encryption for speed on large files. It commonly combines encryption with data theft for double extortion and can deploy across a domain using Group Policy abuse, administrative shares, PsExec, PowerShell remoting, WMI, WinRM, scheduled tasks, and related remote execution methods. A standout feature is a worm-like spread mode that can recursively propagate from a single foothold across reachable network systems.
The Gentlemen’s operators and affiliates typically prioritize enterprise intrusions over mass phishing. Reported initial access methods include exploitation of internet-facing edge infrastructure such as VPNs, firewalls, and other perimeter devices, brute-force attacks, use of stolen or leaked credentials, and cooperation with initial access brokers. Public reporting also links the operation to inventories of pre-compromised edge devices and to exploitation or active tracking of multiple high-profile vulnerabilities affecting enterprise access infrastructure and Windows environments.
Post-compromise behavior includes Active Directory reconnaissance, credential theft, privilege escalation, lateral movement, exfiltration, and broad defense evasion. The operation has used custom backdoors, proxy malware, remote administration tools, and commodity offensive tooling to maintain access and stage ransomware. It is especially notable for repeated use of EDR- and AV-killing frameworks, including bring-your-own-vulnerable-driver techniques to terminate protected security products at kernel level. Additional anti-recovery and anti-forensics behavior includes disabling Microsoft Defender, stopping backup, database, virtualization, and security services, deleting shadow copies, clearing Windows event logs, wiping free space in some modes, and self-deleting after execution. Persistence has been observed via scheduled tasks, registry autoruns, and remote access tooling.
Victimology indicates broad global targeting across dozens of countries, with recurring impact in manufacturing, professional and business services, technology, healthcare, transportation, financial services, construction, logistics, and other enterprise sectors. The operation appears opportunistic but strongly enterprise-focused, with emphasis on organizations where operational disruption increases payment pressure. Like many Russian-speaking ransomware operations, it has been reported to avoid targeting CIS entities.
The Gentlemen is best understood as a mature, human-operated RaaS platform that integrates proven ransomware tradecraft, cross-platform lockers, strong affiliate support, double extortion, and unusually aggressive self-propagation into a fast-scaling extortion ecosystem.
F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098Ec12c4d58541cc4f75ae19b65295a52c559570054c0979ec20b87084317d1bfa50405f7149c3b5c5fdf249727c12741ca176d5f1ccba3ce188a546d28e00293ce0eb534874efd615ae590cf6aa3858ba4Reported operators
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
This year saw the emergence of The Gentlemen, a prominent example of a group operating under the ransomware-as-a-service (RaaS) model.
In an analysis of the ransomware in late last year, LevelBlue's Cybereason team described The Gentlemen as a "highly adaptive, fast-moving ransomware operation" that combines mature ransomware techniques with RaaS features, double extortion, cross-platform lockers, and flexible propagation, and affiliate support.
The Gentlemen за неполный год из осколка Qilin превратился во второго по активности RaaS-оператора в мире. Microsoft Threat Intelligence ведёт их инфраструктуру как Storm-2697.
The Gentlemen is an active ransomware and extortion operation that emerged publicly in the second half of 2025 and rapidly scaled into a high-volume threat actor.
Exploited software
MITRE ATT&CK
Reporting
Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.
Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.