Credential Theft
- DumpBrowserSecrets
- Hydra
- KslDump
- KslKatz
- XenAllPasswordPro
The Gentlemen is a human-operated ransomware-as-a-service operation, tracked as Storm-2697 and GOLD SHERWOOD, active since mid-2025.
Profile source: Mallory opens in a new tabThe Gentlemen
The Gentlemen is a human-operated ransomware-as-a-service operation, tracked as Storm-2697 and GOLD SHERWOOD, active since mid-2025. It uses a double-extortion model: affiliates steal organizational data, encrypt victim systems, and threaten public disclosure to compel payment. The operation recruits affiliates and provides an intrusion toolkit that includes ransomware, data-exfiltration utilities, reconnaissance tools, and mechanisms for disabling endpoint defenses.
The primary encryptor is Go-based and targets Windows environments, with cross-platform variants reported for Linux and ESXi. It uses hybrid Curve25519 and XChaCha20 encryption, supports partial encryption of large files, can target local drives and network shares, and can optionally wipe free disk space or remove itself after execution. It establishes persistence through scheduled tasks and uses privilege escalation to run encryption with elevated permissions. Before encryption, it can terminate security and backup-related processes and services, weaken Microsoft Defender, remove shadow copies, and clear Windows event logs.
A distinguishing feature is a worm-like propagation capability that uses SMB sharing and multiple parallel remote-execution mechanisms, including remote service creation, scheduled tasks, WMI, PowerShell remoting, and PsExec. This enables rapid lateral movement and domain-wide ransomware deployment from a single compromised host. Affiliates have also used valid domain credentials, RDP, Group Policy, and domain-controller infrastructure to spread within victim networks.
The operation commonly obtains initial access through compromised VPN credentials, brute-force activity, purchased access, and exploitation of internet-facing edge infrastructure, particularly firewall and VPN appliances. Post-compromise activity includes network and Active Directory reconnaissance, account enumeration, credential theft, privilege escalation, data staging and exfiltration, defense evasion, backup tampering, and ransomware deployment. BYOVD-based EDR-killing tools, including the GentleKiller framework, are a central component of its defense-evasion tradecraft.
The Gentlemen has targeted organizations across numerous sectors and regions, with observed victims in education, transportation, healthcare, finance, manufacturing, technology, business services, and other industrial organizations. Activity has been reported globally, including North and South America, Europe, Africa, and Asia.
F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098Ec12c4d58541cc4f75ae19b65295a52c559570054c0979ec20b87084317d1bfa50405f7149c3b5c5fdf249727c12741ca176d5f1ccba3ce188a546d28e00293ce0eb534874efd615ae590cf6aa3858ba4Reported operators
GOLD SHERWOOD began operating The Gentlemen RaaS scheme in mid-2025 as a double-extortion model, in which affiliates steal data to hold for ransom before encrypting files.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
In an analysis of the ransomware in late last year, LevelBlue's Cybereason team described The Gentlemen as a "highly adaptive, fast-moving ransomware operation" that combines mature ransomware techniques with RaaS features, double extortion, cross-platform lockers, and flexible propagation, and affiliate support.
The Gentlemen за неполный год из осколка Qilin превратился во второго по активности RaaS-оператора в мире. Microsoft Threat Intelligence ведёт их инфраструктуру как Storm-2697.
The Gentlemen is an active ransomware and extortion operation that emerged publicly in the second half of 2025 and rapidly scaled into a high-volume threat actor.
Exploited software
MITRE ATT&CK
Reporting
Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.
Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise. At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.
Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.
Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.