Overview
Platforms:
Windows · Linux · NAS · BSD · VMware ESXi
Variants:
Go-based (Windows/Linux/NAS/BSD cross-platform) · C-based ESXi locker · C-based Windows (in-development)
Extensions:
.umc16h · .7mtzhh · .fjn1jw · .axfsmg · .ojuopo
ATT&CK software:
GentleKiller · SystemBC · ThrottleBlood.sys · Mimikatz · Cobalt Strike · Impacket · NetExec · BloodHound/SharpHound · Responder · PsExec · Chisel · AnyDesk
Initial access:
Exploit Public-Facing Application · Valid Accounts · External Remote Services · Phishing
Top countries:
US · GB
Observed sectors:
Manufacturing · Technology · Healthcare
Tracked victims:
869
Victims
Grupolider
CLAIMED
Grupolider is an Angolan diversified holding company founded in 1999, headquartered in Catete (Luanda province).
ACA Pescara
CLAIMED
ACA Pescara public housing agency of the Province of Pescara (Abruzzo, Italy).
Hattiesburg Eye Clinic
CLAIMED
1974-founded family ophthalmology practice in Hattiesburg, Mississippi.
Indic
CLAIMED
INDiC Electronic Solutions Houston-based manufacturer's rep firm founded in 2001 by Jim Nussrallah, covering 6 industrial states.
Aurora Technologies
CLAIMED
Aurora Technologies / ATI orth America's largest fabricator and stocking distributor of thermosets, thermoplastics and other non-metallic materials.
Show more victims (12)
Goteborgsregionens Tekniska Gymnasium
CLAIMED
GTG technical upper-secondary school (gymnasium) owned by 13 Gothenburg-area municipalities (via the Göteborgsregionens kommunalförbund).
Alchin Long Group
CLAIMED
Alchin Long Group Australian hardware conglomerate founded in 1969.
Gelarti
CLAIMED
Gelarti Peru's leading gourmet ice-cream parlor chain.
Balkan Polymers
CLAIMED
Balkan Polymers Serbian polymer recycling group founded in 2011 in Zrenjanin by Aleksandar Nikolić.
Cedars Foods
CLAIMED
Cedars Foods America's #1 hummus & falafel brand.
Agenzia Vittoria Assicurazioni
CLAIMED
Vittoria Assicurazioni "Lodi Stazione" agency (#393 in the network).
Downrite Engineering
CLAIMED
Downrite Engineering 1983-founded, family-owned Florida specialty contractor (Flaxman family, now led by 2nd-generation Brandon Flaxman, ~200 employees.
Neff Drexel
CLAIMED
Neff & Drexel AG Swiss multimedia retailer and integrator founded in 1967 in Gais (Appenzell) as a family Radio-TV shop.
Iveta
CLAIMED
Iveta Croatian family confectionery & bakery from Split.
Humboldt
CLAIMED
Colegio Humboldt 300gb DATA Germany's official school in São Paulo.
High Oakham Primary School
CLAIMED
High Oakham Primary School community primary school in Mansfield, Nottinghamshire.
Tentac
CLAIMED
TENTAC Co., Ltd world's leading maker of robotic tool changers.
Operational Activity
Recent Observations
Systematic observation of group activity
February 2026
Kaspersky researchers identified and began systematic observation of the group's activity.
Ramping up of ransomware activities
January 2026
The group increased its operational tempo and ransomware activities.
EDR killer framework development and usage
The group maintains and utilizes a specialized EDR killer framework designed to neutralize security software.
TTPs
ATT&CK coverage:
18 techniques
T1486
Data Encrypted for Impact
VERIFIEDDeployment of ransomware, written in Go for Windows/Linux/NAS and C for ESXi, via Group Policy Objects (GPOs) to encrypt files across the victim network.
T1490
Inhibit System Recovery
VERIFIEDExecution of vssadmin and wmic commands to delete volume shadow copies, often performed as part of credential collection and defense impairment.
T1562.001
Impair Defenses: Disable or Modify Tools
VERIFIEDUtilization of a proprietary/homegrown EDR killer suite (GentleKiller) and BYOVD (Bring Your Own Vulnerable Driver) techniques to terminate security software.
Show more TTPs (15)
T1070.001
Indicator Removal: Clear Windows Event Logs
VERIFIEDClearing of Security, System, and Application event logs to remove forensic artifacts.
T1567
Exfiltration Over Web Service
VERIFIEDExfiltration of sensitive data to public cloud resources or approved platforms as part of a double-extortion model.
T1190
Exploit Public-Facing Application
VERIFIEDExploitation of vulnerabilities in edge devices/firewalls/VPNs (e.g., CVE-2024-55591 Fortinet FortiOS/FortiProxy) for initial access.
T1078
Valid Accounts
VERIFIEDUse of compromised/stolen/valid domain and local accounts, including brute force or leaked credentials, for initial access and lateral movement (T1078.002 Domain Accounts observed).
T1133
External Remote Services
VERIFIEDAbuse of VPN/SSL-VPN services and remote access for initial access.
T1566
Phishing
VERIFIEDPhishing mentioned as one of several initial access vectors in broader RaaS context (less emphasized than edge exploitation but reported).
T1059
Command and Scripting Interpreter
VERIFIEDHeavy use of PowerShell (T1059.001) and Windows Command Shell (T1059.003) for execution, defense evasion, deployment, and lateral movement.
T1027
Obfuscated Files or Information
VERIFIEDObfuscation of payloads (Go obfuscator, Base64-encoded PowerShell commands, packing with Enigma/Themida).
T1562
Impair Defenses
VERIFIEDImpairment of defenses via GentleKiller/BYOVD EDR killers, disabling Defender (T1562.001), registry modifications, and process termination.
T1070
Indicator Removal
VERIFIEDClearing of Security, System, and Application Event Logs (T1070.001); file deletion and log wiping.
T1484
Domain or Tenant Policy Modification
VERIFIEDAbuse of Group Policy Objects (GPO) for domain-wide deployment and disabling Defender (T1484.001).
T1053
Scheduled Task/Job
VERIFIEDCreation and use of scheduled tasks for persistence, execution of ransomware, and lateral movement.
T1021
Remote Services
VERIFIEDLateral movement via RDP (T1021.001), SMB/Windows admin shares (T1021.002), PsExec, and remote scheduled tasks.
T1570
Lateral Tool Transfer
VERIFIEDLateral tool transfer and self-propagation (worm-like behavior with --spread flag, NETLOGON share distribution).
T1219
Remote Access Software
VERIFIEDUse of legitimate remote access tools like AnyDesk for persistence and C2.
CVEs
Fortinet FortiOS and FortiProxy authentication bypass vulnerability exploited for initial access in The Gentlemen intrusions (edge device/VPN compromise).
Pre-authentication remote code execution (RCE) in Erlang/OTP SSH server via SSH protocol message handling flaw, also affecting Cisco telecom products.
The Gentlemen ransomware operators have exploited this vulnerability as part of a Bring Your Own Vulnerable Driver (BYOVD) chain to terminate protected security processes and facilitate ransomware deployment.
Show more CVEs (2)
Windows SMB Client elevation of privilege vulnerability (NTLM reflection/relay) known to be exploited by The Gentlemen.
React2Shell pre-authentication RCE vulnerability known to be exploited by The Gentlemen.
Infrastructure
Data Leak Site (DLS)
Tor-based data leak site used for publishing victim data and extortion activities. The site was operational by mid-July 2025.
ONLINE
Twitter/X Account
X/Twitter account used by the operators to publicly post about victims and exert pressure for ransom payments.
Tox Communication
Primary communication channel for ransom negotiations, referenced in the ransomware note and identified as the primary contact method for victims.
Attribution
GOLD SHERWOOD
PROBABLE
Vendor tracking name
Tracking name attributed to The Gentlemen by Gurucul.
hastalamuerte
VERIFIED
Vendor tracking name
Alias attributed to the lead administrator of The Gentlemen.
zeta88
PROBABLE
Vendor tracking name
Alias associated with the lead administrator of The Gentlemen.
Relationships
Qilin RaaS
VERIFIED
Affiliate relationship
The Gentlemen is assessed as a former Qilin affiliate crew (formerly known as ArmCorp) that spun off to establish its own RaaS operation following a payment dispute in July 2025.
Affiliates
Affiliate program identified. The Gentlemen operates a RaaS program and publicly recruits affiliates and intrusion partners.
The Gentlemen Affiliates
The program recruits penetration testers and other technically skilled actors as affiliates via underground forums. Affiliates are provided with ransomware builds in Go and C, along with centralized tooling for defense evasion and lateral movement, typically operating under a 90% revenue share model.
First seen:
September 2025
Timeline
2026-06-18
Publication of ESET EDR killer analysis
ESET Research publicly released analysis of the Gentlemen ransomware gang's EDR killer framework, GentleKiller.
2026-05-04
Internal backend database leak
The Gentlemen administrator acknowledged an internal Rocket.Chat backend database breach, exposing sensitive operational data.
2026-05
Partnership with BreachForums
The Gentlemen announced an official partnership with BreachForums to recruit affiliates, penetration testers, and initial access brokers.
Show more events (10)
2026-03-19
Group-IB publication of TTP overview.
2026-01-01
Increased activity reported
The group emerged as a highly active entity in the ransomware ecosystem.
2025-09-09
Publication of initial Trend Micro research
Trend Micro published research on The Gentlemen, providing one of the first detailed studies of the group.
2025-09
Transition to independent RaaS model
The group transitioned from a private entity/Qilin affiliate to an independent RaaS model, offering an affiliate program.
2025-08
Initial private ransomware campaign
Trend Micro investigated the initial ransomware campaign by The Gentlemen as a private group.
2025-07-22
Payment dispute with Qilin
Threat actor hastalamuerte opened an arbitration thread on RAMP regarding a payment dispute with Qilin over withheld commission.
2025-07-17
First Windows sample uploaded
The first known ransomware sample from The Gentlemen was uploaded to VirusTotal, containing a URL for the group's dedicated leak site.
2025-07
Initial activity as a RaaS program.
2025-06
The Gentlemen RaaS operation emerged
The Gentlemen RaaS operation emerged in the ransomware landscape.
2025-05
The Gentlemen (formerly ArmCorp) active
Operators previously active as ArmCorp, an elite affiliate crew within the Qilin ransomware syndicate, began operations.
Sources
No Manners Here: Investigating The Gentlemen
Palo Alto Networks Unit 42
The Gentlemen: Ransomware Analysis
Check Point Research
Show more sources (47)
The Gentlemen RaaS and GentleKiller
Securonix
RaaS Trends: The Gentlemen
Kaspersky
Thegentlemen - Ransomware.live
Ransomware.live
Unmasking The Gentlemen Ransomware
Trend Micro
Unmasking The Gentlemen Ransomware
Trend Micro
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy
Check Point Research
The Gentlemen: A Threat Profile
Vali Cyber
DFIR Report – The Gentlemen & SystemBC
DFIR Report (via secondary channel)
Ransomware-Tool-Matrix/GroupProfiles/TheGentlemen.md
BushidoUK (GitHub, aggregated from multiple CTI)
The Gentlemen Ransomware Analysis
Mallory.ai
The Gentlemen: A New Affiliate's Playbook
BreachCache
Ungentlemanly behavior: Insights into a ransomware operation
Sophos Counter Threat Unit
Unmasking the Gentlemen Ransomware TTPs
Trend Micro
The Gentlemen Ransomware
Blackpoint Cyber
CVE-2025-7771 Detail
National Vulnerability Database (NVD) / Kaspersky Labs
Thus Spoke…The Gentlemen
Check Point Research
'Gentlemen' Ransomware Abuses Vulnerable Driver to Kill Security Gear
Dark Reading (reporting Kaspersky Labs research)
Gentlemen Ransomware Reference
ManageEngine
The Gentlemen
Analyst1
thegentlemen ransomware group
Breach House
Unit42-timely-threat-intel/2026-07-08-The-Gentlemen-C-Based-Ransomware-samples.txt
Palo Alto Networks Unit 42
gentlemen-decryptor
Bedrock Safeguard Inc.
Ransomware Notes — Thegentlemen
Ransomlook
Ransomware Leak Sites Guide
Searchlight Cyber
The Gentlemen Ransomware | WatchGuard Technologies
WatchGuard Technologies
The Gentlemen: A New Affiliate's Playbook
BreachCache