Gentlemen, also known as The Gentlemen, is a financially motivated ransomware family and ransomware-as-a-service operation that emerged in mid-2025. Its operators are tracked by Microsoft as Storm-2697 and by Sophos as GOLD SHERWOOD. The operation conducts double-extortion attacks, stealing sensitive information before encrypting systems and threatening public disclosure to pressure victims. It targets medium and large organizations worldwide, including healthcare, manufacturing, insurance, transportation, education, and energy organizations.
Gentlemen provides Go-based lockers for Windows, Linux, and BSD environments, including network-attached storage, and a C-based locker for VMware ESXi. Its encryption combines X25519 key exchange with XChaCha20, generating per-file cryptographic material. Small files are encrypted completely, while larger files can be partially encrypted to accelerate deployment. The Windows locker targets local storage and network shares and supports domain-wide deployment through Group Policy. Optional propagation functionality uses supplied domain credentials or the current session, with remote execution through PsExec, WMI, and PowerShell. Linux variants support logical-volume block-device encryption, while the ESXi variant shuts down virtual machines before encrypting their disks.
Before encryption, Gentlemen disables Microsoft Defender protections, terminates security tools and database, backup, and virtualization services, deletes Volume Shadow Copies, and clears logs. Its execution requires a password argument, restricting unintended execution and impeding automated analysis. Configurable behavior includes delayed execution, silent encryption that preserves filenames and timestamps, free-space overwriting, and self-deletion. Affiliates also use vulnerable drivers and kernel-level process-termination tooling to impair endpoint defenses.
Observed intrusions begin through compromised VPN credentials, exposed firewall-management interfaces, and vulnerable internet-facing infrastructure. Affiliates enumerate enterprise systems and backups, harvest credentials, obtain privileged access, and move laterally using legitimate accounts and remote administration tools. Data is exfiltrated using legitimate transfer utilities before encryption. These campaigns can progress from observed post-compromise activity to ransomware deployment in less than 24 hours.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Azazel was operating as an affiliate of the Gentlemen ransomware group using their tooling, negotiation channels, and ransom note template.
The Gentlemen ransomware operation is moving from access to full network encryption at striking speed... Its double-extortion approach adds pressure: files are stolen first, then encrypted.
Microsoft Threat Intelligence recently uncovered a dangerous global cyber security operation. Specifically, security researchers are tracking the rapidly growing Gentlemen ransomware threat across multiple continents. This sophisticated platform functions as a ransomware-as-a-service model for financially motivated cybercriminals.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation whose infrastructure and tooling Azazel used to compromise organisations and conduct extortion. The affiliate harvested CI/CD secrets, exfiltrated data, and published victims through his independent LEAKNED site while allegedly withholding proceeds from the Gentlemen operator. The report documents production database destruction in one engagement but does not establish ransomware encryption in the described attacks.
Ransomware operation that claimed responsibility for stealing Veradigm patient records and publishing Veradigm on its leak site. The group has conducted hundreds of attacks since emerging in the prior fall and reportedly also targeted Nutex and AnMed.
A double-extortion ransomware operation whose affiliates obtain access through exposed or unpatched remote infrastructure and stolen VPN credentials, disable EDR/antivirus and backup services, exfiltrate selected data, and rapidly encrypt Windows environments. The locker can be deployed locally, via network shares, or domain-wide through centralized logon shares and remote execution; related builds support Linux and ESXi.
A Go-based ransomware-as-a-service operation employing a double-extortion model. Affiliates obtain access through stolen VPN credentials and vulnerable firewalls, then use RDP, Cloudflared tunnels, credential dumping, Rclone exfiltration, BYOVD-based EDR-disabling tooling, and backup tampering before encrypting victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.