The Gentlemen Ransomware Becomes Fastest Scaling Threat in 2026
A new ransomware-as-a-service operation calling itself The Gentlemen has exploded from obscurity to become the second most prolific ransomware group on the planet in under nine months, claiming over 500 victims across 70 countries and accounting for roughly 10 percent of all global ransomware activity by April 2026. Security researchers are calling it the fastest-scaling ransomware operation on record, surpassing even the early trajectory of LockBit 3.0, long considered the benchmark for rapid RaaS growth.
Origins in a Payment Dispute
The Gentlemen emerged in mid-2025 from a payment dispute within the Qilin ransomware-as-a-service program. The group’s founding operator, using the alias “hastalamuerte” and also tracked as “zeta88,” was previously an affiliate crew leader within Qilin. On July 22, 2025, this individual publicly accused Qilin’s operators on the RAMP underground forum of withholding approximately $48,000 in unpaid commissions. Within days, the first Gentlemen-branded ransomware sample appeared on VirusTotal, and by September 2025, the group had transitioned into a full RaaS platform complete with an affiliate panel, a dedicated leak site, and a uniquely generous revenue-sharing model.
The 90/10 Revenue Split That Changed the Game
What set The Gentlemen apart from the outset was an unusually generous affiliate revenue split: affiliates retain 90 percent of ransom proceeds, with operators keeping only 10 percent. The industry standard for most RaaS programs ranges from 70 to 80 percent for affiliates. Only RansomHub had previously matched the 90/10 split. This single business decision became the group’s biggest growth lever, pulling experienced operators away from competing programs almost overnight.
By early 2026, The Gentlemen had struck an official recruitment partnership with BreachForums, opening the affiliate program to a much wider pool of penetration testers and initial access brokers. The group also enforced a disciplined requirement: affiliates must exfiltrate victim data before requesting a ransomware binary. Operators verify the exfiltration before providing the customized encryptor, ensuring that every attack has maximum extortion leverage.
How the Attacks Unfold
The Gentlemen does not rely on phishing for initial access. Instead, affiliates systematically target internet-facing edge infrastructure, primarily FortiGate VPN appliances, Cisco ASA devices, and SonicWall appliances. The group’s primary entry vector exploits CVE-2024-55591, a critical authentication bypass in FortiOS and FortiProxy that allows an unauthenticated attacker to bypass login controls. Researchers revealed that the operators maintained an inventory of approximately 14,700 compromised FortiGate devices worldwide, supplemented by nearly a thousand brute-forced FortiGate VPN credentials ready for affiliate use.
Once inside, attackers escalate privileges, create administrator accounts, and establish persistent access. Lateral movement relies on legitimate administrative utilities such as AnyDesk and PsExec, allowing malicious activity to blend into normal network operations. The group uses SharpADWS to enumerate Active Directory objects while bypassing conventional LDAP logging, and relies on tools like NetScan and Advanced IP Scanner for network discovery.
The NETLOGON Distribution Mechanism
One of The Gentlemen’s most distinctive tactics is pushing the ransomware binary through the NETLOGON share, allowing simultaneous execution across every machine that authenticates to the domain. This is paired with a custom PowerShell script, deploy_gpo.ps1, that leverages Group Policy Objects to distribute and trigger the payload domain-wide. Where GPO-based delivery is not feasible, the group falls back on PsExec for remote execution. The self-propagating encryptor attempts 21 independent remote execution techniques per target host, making it effectively worm-like in behavior.
The GentleKiller EDR Evasion Suite
The group’s defense evasion is layered and deliberate. Operators deploy a centralized EDR-killing framework named GentleKiller before encryption begins. This suite comprises at least eight distinct BYOVD (Bring Your Own Vulnerable Driver) variants capable of terminating over 400 security processes across 48 vendors. The kernel access is paired with user-mode executables that dynamically detect and stop whichever EDR or antivirus product is running on the victim system, rather than relying on a static kill-list.
One particularly notable tool in the arsenal is ThrottleBlood.sys, a renamed and weaponized version of ThrottleStop.sys, a legitimate CPU thermal-monitoring driver. This driver is exploited via CVE-2025-7771, a high-severity vulnerability enabling kernel-level code execution. Once loaded, it grants privileges sufficient to terminate protected security software. ESET researchers assessed with high confidence that The Gentlemen did not develop ThrottleBlood in-house; it has also been observed in unrelated MedusaLocker and DragonForce intrusions.
A Global Victim Profile
The Gentlemen’s targeting profile deviates significantly from the North America-Europe axis that dominates most major ransomware group data. Asia accounts for nearly 46 percent of all known victims, an unprecedented concentration for a group of this size. Thailand is the most targeted country with 27 victims, followed by the United States, France, and Brazil. Only 7 percent of victims are US-based, a significant deviation from the broader ransomware ecosystem where roughly half of all victims are American organizations.
The top targeted sectors include:
- IT services
- Construction
- Manufacturing
- Financial services
- Healthcare
The group operates under a strict CIS exclusion policy, programmatically excluding victims in Commonwealth of Independent States countries, consistent with Russian-speaking threat actor norms. In June 2026, The Gentlemen claimed responsibility for a ransomware attack on Mackay Sugar, Australia’s second-largest raw sugar producer, shutting down operations at two mills for over a week and disrupting 1,300 family-owned farms.
The Internal Leak That Exposed Everything
On May 4, 2026, The Gentlemen’s administrator publicly acknowledged that an internal backend database known as “Rocket” had been compromised and leaked. The data, sold for $10,000 in Bitcoin, contained approximately 16.22 GB of operational data, including:
- 3,366 internal Rocket.Chat messages across operational channels
- 9 named operator accounts and their roles within the organization
- 1,570 victims on a single affiliate’s C2 botnet
- Bitcoin laundering chains and payout records
- A live FortiGate tracking dashboard showing active targets
- The full toolchain, including EDR killer collections
- Ransom negotiation transcripts revealing initial demands of $250,000 settling at $190,000
The leaked material offered an unprecedented window into the group’s daily operations, revealing how affiliates and operators shared compromised VPN and Synology accounts, coordinated intrusions in progress, and tracked payouts across campaigns.
Defensive Recommendations for Organizations
Security researchers emphasize several critical steps to defend against The Gentlemen and similar threats:
- Patch FortiGate appliances immediately against CVE-2024-55591. Any unpatched device should be treated as potentially breached given the group’s inventory of 14,700 compromised devices.
- Enforce phishing-resistant MFA on all VPN, RDP, and OWA endpoints. The group actively brute-forces and credential-stuffs these services.
- Block all GentleKiller drivers using Microsoft’s Vulnerable Driver Blocklist and enable HVCI to prevent unsigned kernel drivers from loading.
- Implement strict network segmentation to contain worm-like propagation and protect critical operational technology environments.
- Secure backups with immutability and maintain offline, air-gapped copies. The group actively targets Veeam, backup services, and NAS devices.
- Monitor for NETLOGON and SYSVOL modifications, as GPO-based deployment uses this vector for domain-wide ransomware distribution.
The Bigger Picture: Data Theft Over Encryption
The rise of The Gentlemen coincides with a broader shift in the ransomware landscape. According to the Zscaler ThreatLabz 2026 Ransomware Report, ransomware data theft surged 275 percent year over year, reaching 896.2 terabytes of exfiltrated data. That is more than seven times the volume recorded during the 2023 to 2024 reporting period. Ransom payments, meanwhile, fell 15.8 percent to $327.8 million, suggesting that while organizations are increasingly refusing to pay, attackers are stealing far more data to maintain extortion pressure.
The Gentlemen exemplify this trend. Their double-extortion model, requiring data exfiltration before encryption, ensures that even organizations with robust backup strategies face significant leverage from the threat of public data exposure. As AI-assisted attackers accelerate operations and the volume of stolen data continues to climb, organizations must treat data exfiltration, not just encryption, as the primary threat.
The ransomware ecosystem has historically been a slow churn of established brands. The Gentlemen have shattered that pattern, proving that a well-funded RaaS operation with the right economic incentives can achieve in months what previously took years. For security teams worldwide, the message is clear: the threat landscape is evolving faster than ever, and defensive postures must evolve with it.
Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous
Discover more from QUE.com
Subscribe to get the latest posts sent to your email.
