The Gentlemen
Ransomware-as-a-Service (RaaS) operation · Financial — ransomware and extortion
Tactics, Techniques & Procedures (TTPs)
- Pre-stockpiled FortiGate VPN access inventory — access acquired before campaigns begin
- BYOVD (Bring Your Own Vulnerable Driver) for kernel privilege escalation and EDR bypass
- GPO-based domain-wide simultaneous ransomware detonation
- Go-based cross-platform locker targeting Windows, Linux, and VMware ESXi
- SystemBC proxy malware for encrypted C2 traffic obfuscation
- 90% affiliate commission model attracting high-skill operators from dismantled groups
Known Targets
Analyst Notes
Founded mid-2025 by a former Qilin affiliate following a profit-sharing dispute. Reached global top-3 in Q1 2026 with 340+ confirmed victims. Deliberately targets non-US markets — which reduces the law enforcement pressure that US-focused groups attract. The 90% affiliate revenue share (vs the industry-standard 70-80%) has attracted a disproportionate number of high-skill operators from disrupted groups including Qilin and former ALPHV/BlackCat affiliates.
Also Known As
Intelligence Reports
The Gentlemen Ransomware Hijacks Hospital's Facebook Page to Pressure AnMed Health
The Gentlemen ransomware group escalated its extortion of nonprofit health system AnMed by seizing control of the hospital's Facebook page to publicize ransom demands, two weeks after an initial breach claiming 6TB of patient data.
The Gentlemen: From Zero to 340 Victims in Nine Months -- Inside the RaaS Group Rewriting the Ransomware Playbook
Launched in mid-2025 by a disgruntled Qilin affiliate, The Gentlemen ransomware-as-a-service operation reached third place globally in Q1 2026 through pre-stockpiled FortiGate access, a 90% affiliate commission, and a deliberate strategy to target non-US markets that most groups neglect.