Skip to content

TheGentlemen

The Gentlemen is a ransomware-as-a-service operation that emerged in late 2025 and rapidly became one of the most prolific ransomware threats of 2026.

Profile source: Mallory opens in a new tab

TheGentlemen

Family profile

The Gentlemen is a ransomware-as-a-service operation that emerged in late 2025 and rapidly became one of the most prolific ransomware threats of 2026. The group is widely tracked under aliases including gentleman, gentlemen, gentleman_group, gentlemen_ransomware_group, gentlemen_raas_affiliates, Storm-2697, and related naming variants. Reporting indicates the operation was founded by a former Qilin affiliate and is supported by a core team of roughly nine operators plus a broader affiliate base.

The group is financially motivated and operates a mature affiliate model with aggressive revenue sharing that has helped it recruit operators quickly. It has been associated with high victim volumes across multiple reporting periods, including leadership in South America and strong global placement in Q2 and July 2026. The Gentlemen has targeted organizations across North America, South America, Southeast Asia, and Western Europe, and has been observed affecting sectors including government, education, healthcare, industrial organizations, retail, professional services, technology, and hospitality.

The Gentlemen commonly gains initial access through internet-facing edge infrastructure such as firewalls, VPN appliances, SSL VPNs, and exposed FortiGate systems. Reported access methods include exploitation of known vulnerabilities, credential brute-forcing, and use of purchased access from brokers or bot operators. Post-compromise behavior includes obtaining administrator privileges, disabling security tooling, exfiltrating data, and deploying ransomware.

A distinguishing feature of the operation is its operator-supplied tooling for defense evasion. The group distributes and maintains an in-house EDR-killer framework known as GentleKiller, along with other associated tools such as HexKiller, ThrottleBlood, and HavocKiller. GentleKiller uses bring-your-own-vulnerable-driver techniques to load signed but vulnerable kernel drivers and terminate security processes at kernel level before encryption. Variants have impersonated legitimate software and targeted hundreds of processes across dozens of security products. The group has also been linked to rapid incorporation of newly disclosed driver exploits and to affiliate tooling specifically intended to disable endpoint detection and response controls.

Leaked internal data and chat logs have provided unusual visibility into the operation. Those materials indicate that The Gentlemen centrally develops parts of its platform and used AI coding assistants to build its ransomware management panel in a matter of days, while also using AI tools to accelerate development of new ransomware versions. The operation has also been described as providing affiliates with a pre-packaged intrusion kit and playbooks that lower the barrier to entry and standardize attack workflows.

The Gentlemen is assessed as a major RaaS actor rather than a state-directed intrusion set. Its activity is characterized by scalable affiliate operations, data theft, security-tool suppression, and ransomware deployment against a broad international victim base.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 15, 2026
Last activity
Aug 15, 2026
Feed role
C2
Host form
0 IP / 5 hostnames

Leading locations

  • US3
  • NL1

Leading providers

  • Cogent Communications, LLC2
  • Datacamp Limited1
  • Host Sailor Ltd1

Infrastructure traits

  • Hosting 2

MITRE ATT&CK

TheGentlemen in ATT&CK

99 distinct techniques

Techniques

99 techniques
T1486 Data Encrypted for Impact T1190 Exploit Public-Facing Application T1078 Valid Accounts T1041 Exfiltration Over C2 Channel T1587.001 Malware T1657 Financial Theft T1567.001 Exfiltration to Code Repository T1562 Impair Defenses T1537 Transfer Data to Cloud Account T1211 Exploitation for Defense Evasion T1583.005 Botnet T1548 Abuse Elevation Control Mechanism T1110 Brute Force T1133 External Remote Services T1210 Exploitation of Remote Services T1027 Obfuscated Files or Information T1070 Indicator Removal T1068 Exploitation for Privilege Escalation T1027.002 Software Packing T1036 Masquerading T1018 Remote System Discovery T1649 Steal or Forge Authentication Certificates T1570 Lateral Tool Transfer T1195 Supply Chain Compromise T1021.002 SMB/Windows Admin Shares T1218 System Binary Proxy Execution T1090 Proxy T1136 Create Account T1047 Windows Management Instrumentation T1218.007 Msiexec T1059.001 PowerShell T1003 OS Credential Dumping T1568 Dynamic Resolution T1071 Application Layer Protocol T1547.001 Registry Run Keys / Startup Folder T1053.005 Scheduled Task T1098 Account Manipulation T1560 Archive Collected Data T1136.001 Local Account T1105 Ingress Tool Transfer T1053 Scheduled Task/Job T1059.007 JavaScript T1219 Remote Access Tools T1003.001 LSASS Memory T1562.001 Disable or Modify Tools T1620 Reflective Code Loading T1059.003 Windows Command Shell T1071.001 Web Protocols T1102.001 Dead Drop Resolver T1003.002 Security Account Manager T1112 Modify Registry T1087 Account Discovery T1136.002 Domain Account T1572 Protocol Tunneling T1082 System Information Discovery T1057 Process Discovery T1070.004 File Deletion T1489 Service Stop T1055 Process Injection T1080 Taint Shared Content T1580 Cloud Infrastructure Discovery T1539 Steal Web Session Cookie T1021 Remote Services T1135 Network Share Discovery T1069 Permission Groups Discovery T1490 Inhibit System Recovery T1213 Data from Information Repositories T1484.001 Group Policy Modification T1566 Phishing T1561 Disk Wipe T1543.003 Windows Service T1106 Native API T1036.001 Invalid Code Signature T1005 Data from Local System T1048 Exfiltration Over Alternative Protocol T1070.001 Clear Windows Event Logs T1567 Exfiltration Over Web Service T1595 Active Scanning T1587 Develop Capabilities T1046 Network Service Discovery T1021.004 SSH T1574.011 Services Registry Permissions Weakness T1574 Hijack Execution Flow T1003.003 NTDS T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay T1562.009 Safe Mode Boot T1491 Defacement T1040 Network Sniffing T1497 Virtualization/Sandbox Evasion T1016 System Network Configuration Discovery T1059 Command and Scripting Interpreter T1222 File and Directory Permissions Modification T1033 System Owner/User Discovery T1482 Domain Trust Discovery T1518 Software Discovery T1014 Rootkit T1555.003 Credentials from Web Browsers T1588.003 Code Signing Certificates T1553.002 Code Signing

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.