Origin and context:
The Gentlemen is a cybercrime group specialized in ransomware that emerged in July 2025. Despite its recent appearance, the group demonstrated from the outset a level of technical maturity and operational discipline atypical for new actors, leading researchers from firms such as Trend Micro, Group-IB, and Cybereason to suspect that it could be experienced operators coming from previous ransomware ecosystems or a rebranding of an already existing group.
The group is presumed to originate from Russian-speaking regions, due to its operators applying an explicit restriction that prohibits attacking organizations located in Russia and in member countries of the Commonwealth of Independent States (CIS), a common practice among cybercriminal actors with ties to that region.
Operating model: RaaS and Double extortion
The Gentlemen operates under a Ransomware-as-a-Service (RaaS) scheme, in which the main operators develop and maintain the malicious infrastructure (including the encryptor, the dark web leak site, negotiation support, and customizable builder options) while independent affiliates carry out the attacks. As a recruitment incentive, the group offers its affiliates a 90% commission on the ransoms obtained, one of the highest rates recorded in the criminal ecosystem.

Promotion publication on The Gentlemen RaaS DarkWeb
Their core strategy is double extortion: the attackers first exfiltrate sensitive data from the victim and then encrypt their systems, threatening to publish the stolen information on leak sites if the ransom is not paid. This combines operational damage with reputational and regulatory risk for the affected organizations.
Technical capabilities
The ransomware is developed in Go and is cross-platform, with variants for Windows, Linux, ESXi, NAS, and BSD. Among its technical features are:
- Encryption using XChaCha20 and Curve25519, modern and robust schemes that make recovery without the attacker’s key difficult.
- Password verification as an execution parameter, which prevents accidental activation and complicates analysis in sandboxing environments.
- Automatic persistence mechanisms: automatic restart and run-on-boot execution.
- Lateral propagation via WMI, PowerShell Remoting, and shared network drives.
- Defense evasion through the BYOVD (Bring Your Own Vulnerable Driver) technique, which allows disabling EDR solutions by exploiting legitimate but vulnerable drivers.
- Abuse of Group Policy Objects (GPO) to compromise entire domains and custom tools to disable specific security products.
- Data exfiltration via encrypted channels using WinSCP, with persistent remote access via AnyDesk.
- Silent execution modes and timestamp preservation to hinder forensic analysis.
Global scope and impact
The group’s growth has been extraordinarily rapid. They published their first 48 victims in September and October 2025. By early 2026, their leak site listed more than 200 organizations in over 50 countries. In the first quarter of 2026, The Gentlemen was the third most active ransomware group globally with 192 recorded incidents, only behind Qilin (338) and Akira (197).
Even more revealing, the analysis of a compromised C2 server carried out by Check Point Research exposed more than 1,570 infected corporate networks that had never been published on the leak site, indicating that the real scale of the operation is significantly larger than publicly known.
The most affected sectors include manufacturing, construction, healthcare, insurance, energy, and government. Attacks have been confirmed in North America, South America, Europe, Asia-Pacific, and the Middle East, not limited to any specific region.
According to SOCRadar, Mexico is in the Top 10 countries with 3 affected victims.

Top 10 target countries by The Gentlemen Ransomware
Recommendations
- Implement multi-factor authentication (MFA) on all privileged accesses and Internet-exposed services.
- Deploy EDR solutions with behavior-based detection and keep them updated.
- Audit and restrict the use of legitimate remote access tools such as AnyDesk.
- Actively monitor GPOs and changes in domain configurations.
- Maintain offline backups and periodically verify their integrity and restoration capability.
- Implement network segmentation to limit lateral movement in case of compromise.