Overview

Platforms: Windows · Linux · NAS · BSD · VMware ESXi
Variants: Go-based (Windows/Linux/NAS/BSD cross-platform) · C-based ESXi locker · C-based Windows (in-development)
Extensions: .umc16h · .7mtzhh · .fjn1jw · .axfsmg · .ojuopo
ATT&CK software: GentleKiller · SystemBC · ThrottleBlood.sys · Mimikatz · Cobalt Strike · Impacket · NetExec · BloodHound/SharpHound · Responder · PsExec · Chisel · AnyDesk
Initial access: Exploit Public-Facing Application · Valid Accounts · External Remote Services · Phishing
Top countries: US · GB
Observed sectors: Manufacturing · Technology · Healthcare
Tracked victims: 869

Victims

Grupolider CLAIMED
September 21, 2026 AO Distribution 4 tracker sources
Grupolider is an Angolan diversified holding company founded in 1999, headquartered in Catete (Luanda province).
ACA Pescara CLAIMED
September 14, 2026 IT Road transport 3 tracker sources
ACA Pescara public housing agency of the Province of Pescara (Abruzzo, Italy).
Hattiesburg Eye Clinic CLAIMED
September 14, 2026 US Healthcare 3 tracker sources
1974-founded family ophthalmology practice in Hattiesburg, Mississippi.
Indic CLAIMED
September 14, 2026 IN Technology 3 tracker sources
INDiC Electronic Solutions Houston-based manufacturer's rep firm founded in 2001 by Jim Nussrallah, covering 6 industrial states.
Aurora Technologies CLAIMED
September 14, 2026 US Technology 3 tracker sources
Aurora Technologies / ATI orth America's largest fabricator and stocking distributor of thermosets, thermoplastics and other non-metallic materials.
Show more victims (12)
Goteborgsregionens Tekniska Gymnasium CLAIMED
September 14, 2026 SE Schools 3 tracker sources
GTG technical upper-secondary school (gymnasium) owned by 13 Gothenburg-area municipalities (via the Göteborgsregionens kommunalförbund).
Alchin Long Group CLAIMED
September 14, 2026 AU Construction 3 tracker sources
Alchin Long Group Australian hardware conglomerate founded in 1969.
Gelarti CLAIMED
September 14, 2026 PE Food and drinks businesses 3 tracker sources
Gelarti Peru's leading gourmet ice-cream parlor chain.
Balkan Polymers CLAIMED
September 14, 2026 BG Manufacturing 3 tracker sources
Balkan Polymers Serbian polymer recycling group founded in 2011 in Zrenjanin by Aleksandar Nikolić.
Cedars Foods CLAIMED
September 14, 2026 US Food and drinks businesses 3 tracker sources
Cedars Foods America's #1 hummus & falafel brand.
Agenzia Vittoria Assicurazioni CLAIMED
September 14, 2026 IT Insurance services 3 tracker sources
Vittoria Assicurazioni "Lodi Stazione" agency (#393 in the network).
Downrite Engineering CLAIMED
September 14, 2026 US Professional Services 3 tracker sources
Downrite Engineering 1983-founded, family-owned Florida specialty contractor (Flaxman family, now led by 2nd-generation Brandon Flaxman, ~200 employees.
Neff Drexel CLAIMED
September 14, 2026 CH Attorney 3 tracker sources
Neff & Drexel AG Swiss multimedia retailer and integrator founded in 1967 in Gais (Appenzell) as a family Radio-TV shop.
Iveta CLAIMED
September 14, 2026 HR Education 3 tracker sources
Iveta Croatian family confectionery & bakery from Split.
Humboldt CLAIMED
September 14, 2026 BR Schools 3 tracker sources
Colegio Humboldt 300gb DATA Germany's official school in São Paulo.
High Oakham Primary School CLAIMED
September 14, 2026 GB Schools 3 tracker sources
High Oakham Primary School community primary school in Mansfield, Nottinghamshire.
Tentac CLAIMED
September 14, 2026 JP Information Technologies Consulting 3 tracker sources
TENTAC Co., Ltd world's leading maker of robotic tool changers.

Operational Activity

Recent Observations

Systematic observation of group activity
February 2026
Kaspersky researchers identified and began systematic observation of the group's activity.
Ramping up of ransomware activities
January 2026
The group increased its operational tempo and ransomware activities.
EDR killer framework development and usage
The group maintains and utilizes a specialized EDR killer framework designed to neutralize security software.

TTPs

ATT&CK coverage: 18 techniques
T1486 Data Encrypted for Impact
VERIFIED
Deployment of ransomware, written in Go for Windows/Linux/NAS and C for ESXi, via Group Policy Objects (GPOs) to encrypt files across the victim network.
T1490 Inhibit System Recovery
VERIFIED
Execution of vssadmin and wmic commands to delete volume shadow copies, often performed as part of credential collection and defense impairment.
T1562.001 Impair Defenses: Disable or Modify Tools
VERIFIED
Utilization of a proprietary/homegrown EDR killer suite (GentleKiller) and BYOVD (Bring Your Own Vulnerable Driver) techniques to terminate security software.
Show more TTPs (15)
T1070.001 Indicator Removal: Clear Windows Event Logs
VERIFIED
Clearing of Security, System, and Application event logs to remove forensic artifacts.
T1567 Exfiltration Over Web Service
VERIFIED
Exfiltration of sensitive data to public cloud resources or approved platforms as part of a double-extortion model.
T1190 Exploit Public-Facing Application
VERIFIED
Exploitation of vulnerabilities in edge devices/firewalls/VPNs (e.g., CVE-2024-55591 Fortinet FortiOS/FortiProxy) for initial access.
T1078 Valid Accounts
VERIFIED
Use of compromised/stolen/valid domain and local accounts, including brute force or leaked credentials, for initial access and lateral movement (T1078.002 Domain Accounts observed).
T1133 External Remote Services
VERIFIED
Abuse of VPN/SSL-VPN services and remote access for initial access.
T1566 Phishing
VERIFIED
Phishing mentioned as one of several initial access vectors in broader RaaS context (less emphasized than edge exploitation but reported).
T1059 Command and Scripting Interpreter
VERIFIED
Heavy use of PowerShell (T1059.001) and Windows Command Shell (T1059.003) for execution, defense evasion, deployment, and lateral movement.
T1027 Obfuscated Files or Information
VERIFIED
Obfuscation of payloads (Go obfuscator, Base64-encoded PowerShell commands, packing with Enigma/Themida).
T1562 Impair Defenses
VERIFIED
Impairment of defenses via GentleKiller/BYOVD EDR killers, disabling Defender (T1562.001), registry modifications, and process termination.
T1070 Indicator Removal
VERIFIED
Clearing of Security, System, and Application Event Logs (T1070.001); file deletion and log wiping.
T1484 Domain or Tenant Policy Modification
VERIFIED
Abuse of Group Policy Objects (GPO) for domain-wide deployment and disabling Defender (T1484.001).
T1053 Scheduled Task/Job
VERIFIED
Creation and use of scheduled tasks for persistence, execution of ransomware, and lateral movement.
T1021 Remote Services
VERIFIED
Lateral movement via RDP (T1021.001), SMB/Windows admin shares (T1021.002), PsExec, and remote scheduled tasks.
T1570 Lateral Tool Transfer
VERIFIED
Lateral tool transfer and self-propagation (worm-like behavior with --spread flag, NETLOGON share distribution).
T1219 Remote Access Software
VERIFIED
Use of legitimate remote access tools like AnyDesk for persistence and C2.

CVEs

Fortinet FortiOS and FortiProxy authentication bypass vulnerability exploited for initial access in The Gentlemen intrusions (edge device/VPN compromise).
Pre-authentication remote code execution (RCE) in Erlang/OTP SSH server via SSH protocol message handling flaw, also affecting Cisco telecom products.
The Gentlemen ransomware operators have exploited this vulnerability as part of a Bring Your Own Vulnerable Driver (BYOVD) chain to terminate protected security processes and facilitate ransomware deployment.
Show more CVEs (2)
Windows SMB Client elevation of privilege vulnerability (NTLM reflection/relay) known to be exploited by The Gentlemen.
React2Shell pre-authentication RCE vulnerability known to be exploited by The Gentlemen.

Infrastructure

Data Leak Site (DLS)
Tor-based data leak site used for publishing victim data and extortion activities. The site was operational by mid-July 2025.
ONLINE
Twitter/X Account
X/Twitter account used by the operators to publicly post about victims and exert pressure for ransom payments.
Tox Communication
Primary communication channel for ransom negotiations, referenced in the ransomware note and identified as the primary contact method for victims.

Attribution

GOLD SHERWOOD PROBABLE
Vendor tracking name
Tracking name attributed to The Gentlemen by Gurucul.
hastalamuerte VERIFIED
Vendor tracking name
Alias attributed to the lead administrator of The Gentlemen.
zeta88 PROBABLE
Vendor tracking name
Alias associated with the lead administrator of The Gentlemen.

Relationships

Qilin RaaS VERIFIED
Affiliate relationship
The Gentlemen is assessed as a former Qilin affiliate crew (formerly known as ArmCorp) that spun off to establish its own RaaS operation following a payment dispute in July 2025.

Affiliates

Affiliate program identified. The Gentlemen operates a RaaS program and publicly recruits affiliates and intrusion partners.
The Gentlemen Affiliates
The program recruits penetration testers and other technically skilled actors as affiliates via underground forums. Affiliates are provided with ransomware builds in Go and C, along with centralized tooling for defense evasion and lateral movement, typically operating under a 90% revenue share model.
First seen: September 2025

Timeline

2026-06-18
Publication of ESET EDR killer analysis
ESET Research publicly released analysis of the Gentlemen ransomware gang's EDR killer framework, GentleKiller.
2026-05-04
Internal backend database leak
The Gentlemen administrator acknowledged an internal Rocket.Chat backend database breach, exposing sensitive operational data.
2026-05
Partnership with BreachForums
The Gentlemen announced an official partnership with BreachForums to recruit affiliates, penetration testers, and initial access brokers.
Show more events (10)
2026-03-19
Group-IB publication of TTP overview.
2026-01-01
Increased activity reported
The group emerged as a highly active entity in the ransomware ecosystem.
2025-09-09
Publication of initial Trend Micro research
Trend Micro published research on The Gentlemen, providing one of the first detailed studies of the group.
2025-09
Transition to independent RaaS model
The group transitioned from a private entity/Qilin affiliate to an independent RaaS model, offering an affiliate program.
2025-08
Initial private ransomware campaign
Trend Micro investigated the initial ransomware campaign by The Gentlemen as a private group.
2025-07-22
Payment dispute with Qilin
Threat actor hastalamuerte opened an arbitration thread on RAMP regarding a payment dispute with Qilin over withheld commission.
2025-07-17
First Windows sample uploaded
The first known ransomware sample from The Gentlemen was uploaded to VirusTotal, containing a URL for the group's dedicated leak site.
2025-07
Initial activity as a RaaS program.
2025-06
The Gentlemen RaaS operation emerged
The Gentlemen RaaS operation emerged in the ransomware landscape.
2025-05
The Gentlemen (formerly ArmCorp) active
Operators previously active as ArmCorp, an elite affiliate crew within the Qilin ransomware syndicate, began operations.

Sources

Show more sources (47)
DFIR Report – The Gentlemen & SystemBC
DFIR Report (via secondary channel)
Ransomware-Tool-Matrix/GroupProfiles/TheGentlemen.md
BushidoUK (GitHub, aggregated from multiple CTI)
The Gentlemen Ransomware
Blackpoint Cyber
CVE-2025-7771 Detail
National Vulnerability Database (NVD) / Kaspersky Labs
Thus Spoke…The Gentlemen
Check Point Research
'Gentlemen' Ransomware Abuses Vulnerable Driver to Kill Security Gear
Dark Reading (reporting Kaspersky Labs research)
gentlemen-decryptor
Bedrock Safeguard Inc.