Last seven days
- First activity
- Aug 15, 2026
- Last activity
- Aug 15, 2026
- Feed role
- C2
- Host form
- 0 IP / 5 hostnames
The Gentlemen is a ransomware-as-a-service operation that emerged in late 2025 and rapidly became one of the most prolific ransomware threats of 2026.
Profile source: Mallory opens in a new tabTheGentlemen
The Gentlemen is a ransomware-as-a-service operation that emerged in late 2025 and rapidly became one of the most prolific ransomware threats of 2026. The group is widely tracked under aliases including gentleman, gentlemen, gentleman_group, gentlemen_ransomware_group, gentlemen_raas_affiliates, Storm-2697, and related naming variants. Reporting indicates the operation was founded by a former Qilin affiliate and is supported by a core team of roughly nine operators plus a broader affiliate base.
The group is financially motivated and operates a mature affiliate model with aggressive revenue sharing that has helped it recruit operators quickly. It has been associated with high victim volumes across multiple reporting periods, including leadership in South America and strong global placement in Q2 and July 2026. The Gentlemen has targeted organizations across North America, South America, Southeast Asia, and Western Europe, and has been observed affecting sectors including government, education, healthcare, industrial organizations, retail, professional services, technology, and hospitality.
The Gentlemen commonly gains initial access through internet-facing edge infrastructure such as firewalls, VPN appliances, SSL VPNs, and exposed FortiGate systems. Reported access methods include exploitation of known vulnerabilities, credential brute-forcing, and use of purchased access from brokers or bot operators. Post-compromise behavior includes obtaining administrator privileges, disabling security tooling, exfiltrating data, and deploying ransomware.
A distinguishing feature of the operation is its operator-supplied tooling for defense evasion. The group distributes and maintains an in-house EDR-killer framework known as GentleKiller, along with other associated tools such as HexKiller, ThrottleBlood, and HavocKiller. GentleKiller uses bring-your-own-vulnerable-driver techniques to load signed but vulnerable kernel drivers and terminate security processes at kernel level before encryption. Variants have impersonated legitimate software and targeted hundreds of processes across dozens of security products. The group has also been linked to rapid incorporation of newly disclosed driver exploits and to affiliate tooling specifically intended to disable endpoint detection and response controls.
Leaked internal data and chat logs have provided unusual visibility into the operation. Those materials indicate that The Gentlemen centrally develops parts of its platform and used AI coding assistants to build its ransomware management panel in a matter of days, while also using AI tools to accelerate development of new ransomware versions. The operation has also been described as providing affiliates with a pre-packaged intrusion kit and playbooks that lower the barrier to entry and standardize attack workflows.
The Gentlemen is assessed as a major RaaS actor rather than a state-directed intrusion set. Its activity is characterized by scalable affiliate operations, data theft, security-tool suppression, and ransomware deployment against a broad international victim base.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.