Skip to content

The Gentlemen

The Gentlemen is a human-operated ransomware-as-a-service operation, tracked as Storm-2697 and GOLD SHERWOOD, active since mid-2025.

Profile source: Mallory opens in a new tab

The Gentlemen

Family profile

The Gentlemen is a human-operated ransomware-as-a-service operation, tracked as Storm-2697 and GOLD SHERWOOD, active since mid-2025. It uses a double-extortion model: affiliates steal organizational data, encrypt victim systems, and threaten public disclosure to compel payment. The operation recruits affiliates and provides an intrusion toolkit that includes ransomware, data-exfiltration utilities, reconnaissance tools, and mechanisms for disabling endpoint defenses.

The primary encryptor is Go-based and targets Windows environments, with cross-platform variants reported for Linux and ESXi. It uses hybrid Curve25519 and XChaCha20 encryption, supports partial encryption of large files, can target local drives and network shares, and can optionally wipe free disk space or remove itself after execution. It establishes persistence through scheduled tasks and uses privilege escalation to run encryption with elevated permissions. Before encryption, it can terminate security and backup-related processes and services, weaken Microsoft Defender, remove shadow copies, and clear Windows event logs.

A distinguishing feature is a worm-like propagation capability that uses SMB sharing and multiple parallel remote-execution mechanisms, including remote service creation, scheduled tasks, WMI, PowerShell remoting, and PsExec. This enables rapid lateral movement and domain-wide ransomware deployment from a single compromised host. Affiliates have also used valid domain credentials, RDP, Group Policy, and domain-controller infrastructure to spread within victim networks.

The operation commonly obtains initial access through compromised VPN credentials, brute-force activity, purchased access, and exploitation of internet-facing edge infrastructure, particularly firewall and VPN appliances. Post-compromise activity includes network and Active Directory reconnaissance, account enumeration, credential theft, privilege escalation, data staging and exfiltration, defense evasion, backup tampering, and ransomware deployment. BYOVD-based EDR-killing tools, including the GentleKiller framework, are a central component of its defense-evasion tradecraft.

The Gentlemen has targeted organizations across numerous sectors and regions, with observed victims in education, transportation, healthcare, finance, manufacturing, technology, business services, and other industrial organizations. Activity has been reported globally, including North and South America, Europe, Africa, and Asia.

Capabilities

  • Brute Force
  • Byovd
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Operational record

5
Indicators
1
YARA rules
3
Ransom notes
2
Leak sites
1 available

Credential Theft

  • DumpBrowserSecrets
  • Hydra
  • KslDump
  • KslKatz
  • XenAllPasswordPro

Defense Evasion

  • EDRStartupHinder
  • GFreeze
  • GLinker

Discovery Enum

  • ADFind
  • BloodHound
  • Censys
  • CertiHound
  • MANSPIDER
  • PowerZure
  • Shodan
  • gogo scanner
  • ldapdomaindump

Exfiltration

  • rclone

Networking

  • Chisel-ng
  • ProxyChains
  • Tor / Onion C2
  • openconnect

Offsec

  • Custom Go Locker (Windows/Linux/NAS)
  • NetExec (nxc)
  • PetitPotam
  • PrivHound
  • RegPwn
  • RelayKing
  • Responder
  • TrustedSec Titanis
  • Velociraptor
  • ZeroPulse
  • ntlmrelayx

RMM Tools

  • AnyDesk

Published indicators

Tox

1 total
  • F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098E

Sha1

4 total
  • c12c4d58541cc4f75ae19b65295a52c559570054
  • c0979ec20b87084317d1bfa50405f7149c3b5c5f
  • df249727c12741ca176d5f1ccba3ce188a546d28
  • e00293ce0eb534874efd615ae590cf6aa3858ba4

Recent claims

Reported operators

Threat actors

9 named in public reporting
GOLD SHERWOOD

GOLD SHERWOOD began operating The Gentlemen RaaS scheme in mid-2025 as a double-extortion model, in which affiliates steal data to hold for ransom before encrypting files.

Akira

The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.

Spikey Scorpius

The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.

HasanBroker

The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.

TheGentlemen

The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.

LARVA-368

The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.

Phantom Mantis

In an analysis of the ransomware in late last year, LevelBlue's Cybereason team described The Gentlemen as a "highly adaptive, fast-moving ransomware operation" that combines mature ransomware techniques with RaaS features, double extortion, cross-platform lockers, and flexible propagation, and affiliate support.

ArmCorp

The Gentlemen за неполный год из осколка Qilin превратился во второго по активности RaaS-оператора в мире. Microsoft Threat Intelligence ведёт их инфраструктуру как Storm-2697.

Hastalamuerte

The Gentlemen is an active ransomware and extortion operation that emerged publicly in the second half of 2025 and rapidly scaled into a high-volume threat actor.

Exploited software

Vulnerabilities linked to The Gentlemen

9 CVEs

MITRE ATT&CK

The Gentlemen in ATT&CK

92 distinct techniques

Techniques

92 techniques
T1486 Data Encrypted for Impact T1018 Remote System Discovery T1059.001 PowerShell T1489 Service Stop T1135 Network Share Discovery T1490 Inhibit System Recovery T1021.002 SMB/Windows Admin Shares T1053.005 Scheduled Task T1562 Impair Defenses T1057 Process Discovery T1047 Windows Management Instrumentation T1112 Modify Registry T1070.004 File Deletion T1069 Permission Groups Discovery T1562.001 Disable or Modify Tools T1070 Indicator Removal T1082 System Information Discovery T1484.001 Group Policy Modification T1561 Disk Wipe T1021 Remote Services T1548 Abuse Elevation Control Mechanism T1105 Ingress Tool Transfer T1543.003 Windows Service T1053 Scheduled Task/Job T1041 Exfiltration Over C2 Channel T1547.001 Registry Run Keys / Startup Folder T1567 Exfiltration Over Web Service T1570 Lateral Tool Transfer T1485 Data Destruction T1046 Network Service Discovery T1068 Exploitation for Privilege Escalation T1070.001 Clear Windows Event Logs T1657 Financial Theft T1033 System Owner/User Discovery T1059.003 Windows Command Shell T1007 System Service Discovery T1083 File and Directory Discovery T1218.002 Control Panel T1021.006 Windows Remote Management T1003 OS Credential Dumping T1090 Proxy T1059 Command and Scripting Interpreter T1518 Software Discovery T1036.005 Match Legitimate Resource Name or Location T1027 Obfuscated Files or Information T1053.003 Cron T1547.009 Shortcut Modification T1573.002 Asymmetric Cryptography T1106 Native API T1491.001 Internal Defacement T1564.003 Hidden Window T1569.002 Service Execution T1036.004 Masquerade Task or Service T1078 Valid Accounts T1562.004 Disable or Modify System Firewall T1189 Drive-by Compromise T1566 Phishing T1090.003 Multi-hop Proxy T1203 Exploitation for Client Execution T1491 Defacement T1078.002 Valid Accounts: Domain Accounts T1133 External Remote Services T1190 Exploit Public-Facing Application T1072 Software Deployment Tools T1136 Create Account T1543 Create or Modify System Process T1547 Boot or Logon Autostart Execution T1187 Forced Authentication T1557 Adversary-in-the-Middle T1110 Brute Force T1552 Unsecured Credentials T1555 Credentials from Password Stores T1087 Account Discovery T1087.002 Account Discovery: Domain Account T1482 Domain Trust Discovery T1526 Cloud Service Discovery T1021.001 Remote Services: Remote Desktop Protocol T1021.004 Remote Services: SSH T1563 Remote Service Session Hijacking T1005 Data from Local System T1039 Data from Network Shared Drive T1074 Data Staged T1074.001 Data Staged: Local Data Staging T1114 Email Collection T1048 Exfiltration Over Alternative Protocol T1048.001 Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol T1537 Transfer Data to Cloud Account T1071 Application Layer Protocol T1071.001 Application Layer Protocol: Web Protocols T1219 Remote Access Software T1572 Protocol Tunneling T1573 Encrypted Channel

Reporting

Research mentioning The Gentlemen

Aug 26
Zdnet Zero Day

July was the worst month for ransomware victim claims in 2026 - or was it? | ZDNET

Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.

Aug 10
Cert Dk

Angreb med ransomware rammer universiteter hårdere | DKCERT

Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise. At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.

Jul 24
Infosecurity Magazine News

Ransomware Attacks Targeting Universities on the Rise - Infosecurity Magazine

Jul 22
Belgium Ccb News

Threat Intelligence Report: Qilin (Agenda) Ransomware | CCB Belgium

Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.

Jul 22
Itsecurityguru

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

Jul 21
Cyber Security News

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.

Jul 21
Infosecurity Magazine News

A New Ransomware Threat Actor Emerges Every Week, Warns Report - Infosecurity Magazine

Jul 21
Emsisoft

The State of Ransomware in Q2 2026

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.