The Gentlemen is a ransomware family distributed through a Russian-speaking ransomware-as-a-service operation active since mid-2025. Its operators are tracked as GOLD SHERWOOD by Sophos and Storm-2697 by Microsoft. The operation uses double extortion: affiliates steal sensitive information before encrypting systems and threaten to publish the stolen data. Targeting is opportunistic and global, affecting manufacturing, technology, healthcare, government, education, and other sectors.
The Windows encryptor is written in Go, uses Garble obfuscation, and combines Curve25519 key exchange with XChaCha20 encryption. It supports self-propagation using available credentials and authentication tokens. Enterprise deployment and propagation use administrative mechanisms including PsExec, WMI, PowerShell, network shares, and Group Policy Objects. The ransomware creates ransom notes throughout scanned directories and excludes selected system files and executable content to preserve operating-system functionality. Windows, Linux, and ESXi variants are available, and Linux/NAS encryption has been documented.
Affiliates commonly obtain initial access through compromised Fortinet SSL VPN credentials or vulnerable internet-facing FortiGate appliances, including exploitation of CVE-2024-55591. Phishing has also been documented. Post-compromise activity includes network and directory reconnaissance, credential dumping, privileged-account manipulation, RDP-based lateral movement, and persistent remote-access tunnels. Sensitive data is exfiltrated using utilities such as Rclone, WinSCP, and other cloud-storage or file-transfer clients. Before encryption, attackers disable endpoint protections, disrupt backup and recovery services, clear event logs, and stop business-critical processes. The operation supplies EDR-disabling tools, including GentleKiller, and affiliates employ bring-your-own-vulnerable-driver techniques. Some affiliates deploy EtherRAT before ransomware execution; its blockchain-based command-and-control functionality belongs to that separate implant rather than to The Gentlemen encryptor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Gentlemen's operations are heavily associated with compromised Fortinet FortiGate appliances. Researchers observed the group exploiting CVE-2024-55591, using stolen or purchased VPN credentials, and leveraging vulnerable edge devices to gain access to corporate networks.
The Gentlemen’s rumored exploitation of newer vulnerabilities such as CVE-2025-32433 and CVE-2025-33073 likely helped drive its significant increase in attacks from May onward. | Since it first emerged in mid-2025, The Gentlemen has claimed responsibility for 675 ransomware attacks. 600 of these attacks occurred in 2026 (up to the end of July).
The Gentlemen’s rumored exploitation of newer vulnerabilities such as CVE-2025-32433 and CVE-2025-33073 likely helped drive its significant increase in attacks from May onward. | Since it first emerged in mid-2025, The Gentlemen has claimed responsibility for 675 ransomware attacks. 600 of these attacks occurred in 2026 (up to the end of July).
The Russian-speaking RaaS operation emerged in July/August 2025. The leaked corpus documents its FortiGate-focused intrusion chain, custom tooling, data theft, Linux/NAS encryption, and extortion negotiations.
We also observed traces suggesting the exploitation of CVE-2020-1472 (Zerologon) and the vulnerabilities associated with MS17-010.
We also observed traces suggesting the exploitation of CVE-2020-1472 (Zerologon) and the vulnerabilities associated with MS17-010.
The actor attempted to exploit CVE-2025-24799, an unauthenticated SQL injection vulnerability in GLPI, using both a PoC and sqlmap to retrieve user information from the database.
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-55182 (React2Shell) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Common Vulnerabilities Exploited CVE-2023-27532 Veeam Backup & Replication Missing authentication targeted for backup destruction Critical Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
Common Vulnerabilities Exploited CVE-2024-37085 VMware ESXi Authentication bypass ESXi locker deployment vector High Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft’s analysis describes a Go-based Windows encryptor that uses Garble obfuscation, Curve25519 key exchange and the XChaCha20 encryption algorithm. It also supports self-propagation.
Since it first emerged in mid-2025, The Gentlemen has claimed responsibility for 675 ransomware attacks. 600 of these attacks occurred in 2026 (up to the end of July).
On 5 October 2026, CloudSEK identified a Russian-speaking The Gentlemen ransomware affiliate who used the Model Context Protocol (MCP) to execute malicious commands during live intrusions.
The Russian-speaking RaaS operation emerged in July/August 2025. The leaked corpus documents its FortiGate-focused intrusion chain, custom tooling, data theft, Linux/NAS encryption, and extortion negotiations.
The Russian-speaking RaaS operation emerged in July/August 2025. The leaked corpus documents its FortiGate-focused intrusion chain, custom tooling, data theft, Linux/NAS encryption, and extortion negotiations.
GOLD SHERWOOD exploite le schéma RaaS The Gentlemen depuis mi-2025, sur un modèle de double extorsion : vol de données avant chiffrement.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware uses WMI via wmic.exe to create remote processes.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
The commands copy the malware executable into C:\Temp, creates a hidden Server Message Block (SMB) share named share$ pointing to that directory, and modifies registry settings to allow anonymous access.
The malware executes the following command sequence to create three Windows services on the target host.
The GupdateS value under HKEY_LOCAL_MACHINE (HKLM) provides device-wide persistence that allows the malware to run at startup for all users, while the GupdateU value under HKEY_CURRENT_USER (HKCU) provides user-scoped persistence within the current profile.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
Their research shows the ransomware follows a very deliberate sequence, starting with password validation and privilege escalation, then moving into defense evasion, encryption, and finally network-wide spreading.
[They deployed] The Gentlemen ransomware through a malicious Group Policy Object.
The malware executes the following command sequence to create three Windows services on the target host.
The GupdateS value under HKEY_LOCAL_MACHINE (HKLM) provides device-wide persistence that allows the malware to run at startup for all users, while the GupdateU value under HKEY_CURRENT_USER (HKCU) provides user-scoped persistence within the current profile.
The commands copy the malware executable into C:\Temp, creates a hidden Server Message Block (SMB) share named share$ pointing to that directory, and modifies registry settings to allow anonymous access.
[They deployed] The Gentlemen ransomware through a malicious Group Policy Object.
After dropping PsExec, the malware attempts to enumerate and discover remote systems on the network, including workstations, servers, and domain controllers.
the malware pulls in a legitimate system tool called PsExec... and starts scanning the network for reachable machines, including regular workstations, servers, and domain controllers.
The malware stops a list of running processes using the command: The table below summarizes the different categories and processes being targeted.
The -- spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session’s authentication token.
the custom ransomware locker, the RaaS panel and builder ... as well as the GPO-based spread mechanism and the locker’s 'spread' module.
The malware binary carries an embedded copy of PsExec and drops it to C:\Temp\psexec.exe on the infected device. If the embedded PsExec payload cannot be extracted successfully, the malware falls back to downloading PsExec directly from Microsoft’s Sysinternals Live service.
delete Volume Shadow Copies twice over using two separate commands for reliability. It also clears command history and deletes backup and recovery tools to make restoring systems without paying much harder.
The Gentlemen ransomware [was] deployed... DeadLock applies a similar mechanism to victim communications after encryption.
In addition to terminating processes, the malware disables and stops a list of Windows services.
sc config VeeamBackupSvc start= disabled; sc config SQLWriter start= disabled; sc config BackupExecAgent start= disabled.
217 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
65 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows ransomware used in a double-extortion operation combining data theft, encryption and threats to publish stolen information. Its Go-based encryptor uses obfuscation and can propagate using available credentials and authentication tokens. Operators also maintain tools to disrupt endpoint security. Microsoft published its technical analysis in May 2026; the content does not establish the malware’s first discovery date.
A ransomware-as-a-service operation whose affiliate, Azazel, abused an AI coding assistant’s MCP tool interface for operational command and control. The reported campaign involved credential harvesting from GitLab CI/CD variables and repository history, ongoing data theft, and extortion. The article does not describe the ransomware’s encryption implementation or confirm its deployment on particular victims.
Ransomware associated with the RaaS program used by Azazel. The affiliate also operated an independent leak site, LEAKNED, to publish stolen victim data and collect extortion proceeds outside the program. The reference does not describe the ransomware's encryption implementation.
Ransomware deployed after credential theft, lateral movement, and exfiltration of sensitive data to Wasabi storage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.