threat_intelligence1610 wordsRead on Arc Codex

The Gentlemen ransomware: Inside one of the fastest

The Gentlemen ransomware: Inside one of the fastest-growing extortion operations Born from a Qilin affiliate operation, The Gentlemen has rapidly become one of the world's most active ransomware groups Key takeaways - The Gentlemen grew from affiliate roots into a major ransomware brand. The group's operators appear to have leveraged relationships, expertise, and credibility developed as the ArmCorp affiliate team to accelerate growth after launching their own ransomware-as-a-service (RaaS) operation. - Success is driven by operational efficiency rather than novel malware. The group relies on proven access techniques, strong affiliate incentives, credential theft, and exploitation of vulnerable edge devices to achieve scale. - The May 2026 Rocket.Chat leak provided rare visibility into operations. The exposure of internal communications revealed details about victim selection, tooling, affiliate coordination, and business processes normally hidden from defenders. The Gentlemen is a financially motivated ransomware-as-a-service (RaaS) double-extortion operation. Originally appearing as affiliate activity under other ransomware programs, the core operators established The Gentlemen as an independent brand in mid-2025 and began recruiting experienced affiliates with a 90% share of ransom proceeds. This generous affiliate share is one of several reasons why the group has been able to expand so quickly. As of this writing, The Gentlemen has claimed more than 750 victims worldwide, and it continues to add new victims at a steady pace. Multiple reporting sources now rank the group alongside Qilin as the most active ransomware groups by victim volume this year. Here’s a quick look at the group: | Category | Assessment | | Threat type | Ransomware-as-a-service; double extortion | | Emergence | Affiliate activity tracked from March 2025; independent The Gentlemen program in July 2025; affiliate recruitment expanded in September 2025 | | Tracking names | The Gentlemen; Microsoft: Storm-2697; PRODAFT: Phantom Mantis, with administrator tracked as LARVA-368 | | Motivation | Financial | | Business model | Affiliates reportedly retain 90% of ransom proceeds | | Primary access | Exposed edge devices, especially Fortinet appliances; purchased or stolen credentials; other internet-facing services | | Platforms | Windows plus reported Linux, network-attached storage, Berkeley Software Distribution (BSD), and VMware ESXi locker support | | Extortion | Data theft, encryption, leak-site publication, and direct pressure through affiliate-controlled communications | | Status | Active as of August 14, 2026 | Group name and logo The group operates under the name “The Gentlemen.” The origin of the name is unknown, but researchers have noted it may be inspired by the 2019 film of the same name. Others have speculated the branding could be an attempt to establish trust with victims (“pay us and we’ll leave you alone”) or a nod to the clever sophistication of Thomas Crown or The Saint. Ultimately, the classic archetype like the ‘gentleman criminal’ may not have a single source of inspiration, and it may have no greater meaning. Everything we’ve seen of The Gentlemen suggests it is a polished, business-oriented ransomware operation rather than an opportunistic hacking crew. Origin story and group operations The core members of The Gentlemen appear to have operated as a prolific ransomware affiliate crew known as ArmCorp. ArmCorp was known to be a Qilin affiliate but was also observed testing resources from other RaaS groups like Medusa and Lockbit. Research published in June 2026 identified the leader of ArmCorp as LARVA-368, who has been tracked online using aliases hastalamuerte and zeta88. Other reports have also linked LARVA-368 to aliases nobody0 and santamuerte. On July 17, 2025, the first known ransomware sample from The Gentlemen was uploaded to VirusTotal. The sample contained a URL for The Gentlemen's dedicated leak site, suggesting that ArmCorp had been preparing to launch an independent operation. On July 22, 2025, an ArmCorp operator using the alias hastalamuerte accused Qilin’s administrators of withholding approximately $48,000 from the group. The Gentlemen emerged as a private group in August, and launched as a RaaS operation in September 2025. ArmCorp’s pre-established relationships are believed to have boosted the credibility and growth of The Gentlemen in its early weeks. By the time the group launched its own ransomware-as-a-service operation in 2025, it already possessed the skills, experience and relationships needed to attract affiliates and scale far more quickly than a typical new ransomware brand. The group’s Russian-language communications, recruitment on Russian-speaking forums, and reported avoidance of Commonwealth of Independent States (CIS) targets support an assessment that it operates within the Russian-speaking cybercrime ecosystem. Researchers have not found evidence of any nation-state collaboration with The Gentlemen. A significant operational-security failure occurred in May 2026 when portions of The Gentlemen's internal Rocket.Chat infrastructure were leaked following a compromise linked to hosting provider 4VPS. The resulting archive exposed internal communications, victim targeting workflows, custom tooling, financial interactions, and affiliate coordination. One notable result of the leak was reporting that linked LARVA-368 to Alexander Andreevich Yapaev from the Russian city of Izhevsk. See Brian Krebs’ reporting here for details on that investigation. Attack chain Initial access The Gentlemen's operations are heavily associated with compromised Fortinet FortiGate appliances. Researchers observed the group exploiting CVE-2024-55591, using stolen or purchased VPN credentials, and leveraging vulnerable edge devices to gain access to corporate networks. Leaked communications also show operators maintaining large inventories of Fortinet targets and actively sharing VPN credentials and configuration files. The group has also been linked to phishing campaigns, credential harvesting, stealer logs, and purchased access from the broader cybercrime ecosystem. Internal discussions captured in the May 2026 leak reveal an interest in Outlook Web App (OWA) credentials, Okta environments and compromised email accounts that can be used to expand access or identify additional targets. Lateral movement and privilege escalation After gaining access, affiliates conduct extensive internal reconnaissance using tools such as Mimikatz variants, Lightweight Directory Access Protocol (LDAP) enumeration utilities and browser credential extraction tools as well as several legitimate administrative utilities and Socket Secure (SOCKS) tunnels for reconnaissance and lateral movement. The group also has its own custom tooling, including the G-BOT command-and-control (C2) framework and a modified version of Velociraptor. Data exfiltration Before deploying ransomware, the attack steals financial records, customer information, and other sensitive data for use in the double-extortion scheme. Files are collected from network shares, servers, business applications, and cloud-connected environments, then transferred using tools such as WinSCP, Rclone, cloud-storage utilities, and other file-transfer mechanisms. The group is also known to research its victims to identify the most valuable data and determine an appropriate ransom demand. Encryption and ransomware deployment Once data theft is complete, the attack stops virtual machines, databases, backup services, Docker containers, and other business-critical processes to maximize disruption and reduce recovery options. The ransomware uses XChaCha20 and Curve25519 encryption and can spread through Active Directory (AD) environments using Windows Management Instrumentation (WMI), PowerShell, PsExec, Group Policy Objects (GPOs), and other administrative tools. The ransomware propagates through ‘simultaneous, distinct lateral movement methods,’ which allows it to have a greater and faster impact across large enterprise networks. A ransom note named ‘README-GENTLEMEN.txt’ is dropped in every scanned directory. Exclusions The ransomware is designed to avoid encrypting certain types of files. Executables, libraries, scripts, and some system files are left intact to keep the victim’s operating system working despite the encryption event. This allows the victim to access and read README-GENTLEMEN.txt, which includes the instructions for payment. You can see the full list of file exclusions in this Microsoft report. Protect yourself The Gentlemen have taken mature ransomware tradecraft and created a professional service that rewards affiliates generously and gives them multiple ways to move from access to impact. Make sure you are following best practices and watching for anomalous activity. - Reduce edge-device exposure. Promptly patch supported firewall and virtual private network appliances, prioritizing actively exploited vulnerabilities. Replace unsupported devices, restrict administrative interfaces to trusted management paths, and review configurations, local accounts, and authentication integrations after a suspected compromise. - Make stolen credentials less useful. Require phishing-resistant multifactor authentication for remote and privileged access, disable dormant accounts, and restrict remote desktop access. Monitor for unusual sign-ins, separate administrative identities from everyday user accounts, and limit standing domain administrator privileges. - Detect rapid lateral movement. Monitor for unusual or widespread use of Group Policy, PsExec, Windows Management Instrumentation, PowerShell remoting, scheduled tasks, and remote desktop. Watch domain controllers and shared locations for unexpected files, and use network segmentation to prevent a single privileged identity or management channel from reaching the entire environment. - Resist defense evasion. Enable tamper protection and vulnerable-driver blocking, and investigate attempts to disable endpoint detection and response services, modify exclusions, clear event logs, or load unexpected signed drivers. Control and monitor remote-access and file-transfer tools such as AnyDesk and WinSCP. - Prepare to contain and recover. Maintain offline or immutable backups and regularly test the restoration of identity systems, virtualization platforms, and critical business services. Establish an emergency process for disabling compromised privileged accounts and malicious Group Policy Objects, and preserve volatile memory when it is safe and operationally feasible. Barracuda can help Only Barracuda provides multi-faceted protection that covers all the major threat vectors, protects your data, and automates incident response. The BarracudaONE AI-powered platform protects your email, data, applications, and networks, and is strengthened by a 24/7 managed XDR service. It unifies your security defenses and provides deep, intelligent threat detection and response. Visit our website to see how Barracuda can help you protect your business. 2026 Email Threats Report Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected Subscribe to the Barracuda Blog. Sign up to receive threat spotlights, industry commentary, and more. The Managed XDR Global Threat Report Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.