The Gentlemen is a rapidly growing ransomware-as-a-service operation, also tracked by Microsoft as Storm-2697, that emerged in mid-2025 and became one of the most active ransomware brands in 2026. The operation is associated with a human-operated intrusion model, aggressive affiliate recruitment, and a high affiliate revenue share. Multiple reports link its operators to prior activity connected with the Qilin ecosystem, including the ArmCorp affiliate crew, and leaked internal data has exposed a small but organized core team coordinating affiliates, tooling, victim handling, and ransom negotiations.
The malware family is best known for a Go-based encryptor targeting Windows environments and for broader cross-platform locker activity reported against Linux and ESXi systems. The Windows encryptor uses strong hybrid cryptography based on per-file Curve25519 and XChaCha20, supports extensive command-line control, and commonly combines encryption with double extortion through data theft. It performs substantial defense evasion before encryption, including disabling security controls, deleting shadow copies, clearing event logs, removing forensic artifacts, terminating backup, virtualization, database, and security processes, and in some cases establishing persistence through scheduled tasks and autorun mechanisms. Some reporting also attributes to the group a dedicated EDR-killing framework and repeated use of bring-your-own-vulnerable-driver techniques to disable endpoint protection.
A distinguishing feature of The Gentlemen is aggressive self-propagation and lateral movement. The Windows encryptor can operate in a worm-like spread mode that turns an infected host into a distribution point and attempts remote execution across reachable systems using multiple parallel techniques, including SMB-based copy operations, PsExec, WMI, scheduled tasks, services, PowerShell remoting, and Group Policy-based deployment. Separate reporting also describes domain-wide deployment through NETLOGON and malicious Group Policy changes. The group’s intrusion tradecraft includes Active Directory reconnaissance, credential theft, NTLM relay activity, privilege escalation, and broad post-compromise automation intended to accelerate enterprise-wide impact.
Initial access is consistently associated with exploitation of internet-facing edge infrastructure, especially VPNs, firewalls, and other perimeter appliances, alongside brute-force activity, stolen or leaked credentials, and cooperation with initial access brokers. Public reporting repeatedly links the group to exploitation or active tracking of vulnerabilities affecting Fortinet, SonicWall, Citrix, Cisco, Windows SMB-related components, and other enterprise edge technologies. Some incidents also indicate use of phishing from compromised internal accounts, but edge-device compromise and credential-based access are the dominant patterns.
The Gentlemen has targeted organizations globally across North America, South America, Europe, Africa, and Asia. Frequently cited victim sectors include manufacturing, healthcare, education, transportation, finance, business services, technology, logistics, and other industrial or critical infrastructure-adjacent organizations. South America has been highlighted as a particularly affected region in 2026, while manufacturing appears repeatedly as a priority sector. The operation’s scale, rapid growth, strong affiliate enablement, defense-evasion tooling, and unusually aggressive propagation behavior make it one of the more consequential ransomware threats observed in 2026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-33073 – NTLM reflection / NTLM relay qbit references RelayKing and shares output showing domains being scanned for NTLM relay issues, including checks that explicitly cover CVE-2025-33073. This is strong evidence that they are not just reading about the vulnerability but have integrated RelayKing into their standard reconnaissance process. | The Gentlemen ransomware-as-a-service (RaaS) operation is a relatively new group that emerged around mid-2025... The leaked Rocket backend and internal chats show that this scale is driven not by a loose crowd, but by a small, tightly coordinated core...
The group’s active tracking and evaluation of modern CVEs such as CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073 . ... CVE-2024-55591 – FortiOS management interface This vulnerability affects the FortiOS management interface and fits directly into their broader focus on Fortinet appliances as high-value initial access points. | The Gentlemen ransomware-as-a-service (RaaS) operation is a relatively new group that emerged around mid-2025... The leaked Rocket backend and internal chats show that this scale is driven not by a loose crowd, but by a small, tightly coordinated core...
CVE-2025-32433 – Erlang SSH vulnerability (Cisco context) In the logs, qbit shares a proof-of-concept (PoC) for CVE-2025-32433, and zeta88 comments on its quality and applicability. This shows that the group is not simply aware of the CVE but is actively evaluating whether it can be used in real operations, specifically in environments where Cisco or Erlang-based SSH services are exposed. | The Gentlemen ransomware-as-a-service (RaaS) operation is a relatively new group that emerged around mid-2025... The leaked Rocket backend and internal chats show that this scale is driven not by a loose crowd, but by a small, tightly coordinated core...
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-55182 (React2Shell) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Common Vulnerabilities Exploited CVE-2023-27532 Veeam Backup & Replication Missing authentication targeted for backup destruction Critical Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
Common Vulnerabilities Exploited CVE-2024-37085 VMware ESXi Authentication bypass ESXi locker deployment vector High Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
In an analysis of the ransomware in late last year, LevelBlue's Cybereason team described The Gentlemen as a "highly adaptive, fast-moving ransomware operation" that combines mature ransomware techniques with RaaS features, double extortion, cross-platform lockers, and flexible propagation, and affiliate support.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware uses WMI via wmic.exe to create remote processes.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
The commands copy the malware executable into C:\Temp, creates a hidden Server Message Block (SMB) share named share$ pointing to that directory, and modifies registry settings to allow anonymous access.
The malware executes the following command sequence to create three Windows services on the target host.
The GupdateS value under HKEY_LOCAL_MACHINE (HKLM) provides device-wide persistence that allows the malware to run at startup for all users, while the GupdateU value under HKEY_CURRENT_USER (HKCU) provides user-scoped persistence within the current profile.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
Their research shows the ransomware follows a very deliberate sequence, starting with password validation and privilege escalation, then moving into defense evasion, encryption, and finally network-wide spreading.
the custom ransomware locker ... as well as the GPO-based spread mechanism and the locker’s 'spread' module.
The malware executes the following command sequence to create three Windows services on the target host.
The GupdateS value under HKEY_LOCAL_MACHINE (HKLM) provides device-wide persistence that allows the malware to run at startup for all users, while the GupdateU value under HKEY_CURRENT_USER (HKCU) provides user-scoped persistence within the current profile.
To further impede recovery efforts, the malware deletes all Volume Shadow Copies using both vssadmin and wmic... It then clears the System, Application, and Security event logs using wevtutil to remove key audit trails.
After dropping PsExec, the malware attempts to enumerate and discover remote systems on the network, including workstations, servers, and domain controllers.
The -- spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session’s authentication token.
the malware pulls in a legitimate system tool called PsExec... and starts scanning the network for reachable machines, including regular workstations, servers, and domain controllers.
The malware stops a list of running processes using the command: The table below summarizes the different categories and processes being targeted.
The -- spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session’s authentication token.
the custom ransomware locker, the RaaS panel and builder ... as well as the GPO-based spread mechanism and the locker’s 'spread' module.
The malware binary carries an embedded copy of PsExec and drops it to C:\Temp\psexec.exe on the infected device. If the embedded PsExec payload cannot be extracted successfully, the malware falls back to downloading PsExec directly from Microsoft’s Sysinternals Live service.
delete Volume Shadow Copies twice over using two separate commands for reliability. It also clears command history and deletes backup and recovery tools to make restoring systems without paying much harder.
Finally, once the environment is prepared and critical data is in their control, they deploy their custom ransomware 'locker,' which is designed to spread quickly across the network... and encrypt systems in a coordinated manner.
In addition to terminating processes, the malware disables and stops a list of Windows services.
To further impede recovery efforts, the malware deletes all Volume Shadow Copies using both vssadmin and wmic.
Before starting file encryption, the malware executes a sequence of commands to disable defensive controls and remove potential forensic artifacts.
The PowerShell commands disable Microsoft Defender real-time monitoring to remove active protection on the infected device. The malware then adds its own executable to the Defender exclusion list to avoid detection. Finally, it excludes the entire C:\ volume from scanning.
177 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Relatively new ransomware operator identified as the dominant threat in South America, with significant activity also in North America and strong focus on healthcare, manufacturing, construction, and IT services.
Relatively new ransomware operator identified as the dominant threat in South America, with notable activity against healthcare, manufacturing, and IT services.
Ransomware group/family involved in industrial-sector extortion activity; the content says it targeted edge devices before moving deeper into corporate networks.
Mentioned only as another ransomware example in recovery guidance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.