DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // THE-GENTLEMEN-RAASFIRST SEEN: SEP 2025

THE GENTLEMEN (Phantom Mantis / LARVA-368)

ALSO KNOWN AS: Storm-2697 (Microsoft), Phantom Mantis (PRODAFT), LARVA-368, ArmCorp
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia (operator Alexander Andreevich Yapaev of Izhevsk, Russia, deanonymized by Krebs on Security Jun 10 2026)
ATTRIBUTION:ORGANIZED CRIME
STATUS:● ACTIVE
FIRST OBSERVED:SEP 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL77/100
RESOURCES77/100
PERSISTENCE80/100
STEALTH72/100
IMPACT86/100

The Gentlemen emerged in September 2025 following a payment dispute within the Qilin RaaS program and scaled to 478+ publicly claimed victims across 66+ countries by mid-2026 — the fastest growth trajectory of any RaaS operation on record, comparable to early LockBit 3.0. As of July 10, 2026, the group remains the #2 most active ransomware operation globally by victim count. A May 4, 2026 backend database leak exposed the group's full operator roster, toolchain, victim lists, and Bitcoin laundering chains, yet failed to interrupt operations. Microsoft tracks the encryptor as Storm-2697; it uses Go with Garble obfuscation and supports a self-propagating worm mode (--spread flag) enabling enterprise-wide encryption within minutes via Group Policy weaponization.

Financial extortion; fastest-scaling RaaS operation on record, offering 90% affiliate revenue share to dominate criminal labor market

FortiGate CVE-2024-55591 exploitation (T1190), RDP/SSL VPN credential abuse (T1078), SystemBC SOCKS5 proxy for C2 (T1090), Cobalt Strike post-exploitation, GPO weaponization for domain-wide ransomware deployment (T1484.001), AnyDesk/PsExec lateral movement (T1021), SharpADWS AD enumeration (T1087), Mimikatz credential dumping (T1003), NTLMv1 relay attacks (T1557), NTLM relay, double extortion, worm-mode self-propagation (T1210), EDRStartupHinder/gfreeze EDR evasion, PoisonX kernel driver (shared with Hyadina affiliates), Curve25519+XChaCha20 encryption (Go variant), AES-256-GCM (C/ESXi variant)

MANUFACTURING
HEALTHCARE
FINANCIAL SERVICES
TECHNOLOGY
GOVERNMENT
ENERGY
EDUCATION
RETAIL
TRANSPORTATION
LOGISTICS

Tor-based dedicated leak site, Proton66 Russian bulletproof hosting, 'Rocket' admin backend database, SystemBC botnet C2 with 1,570+ victim nodes, X/Twitter public pressure account, TOX encrypted operator comms, CVE-tracking dashboard for vulnerability prioritization

FILE DATE: JUL 2026
Ongoing Global RaaS Campaign — 478+ Victims
As of July 10, 2026, The Gentlemen has claimed 478+ victims across 66 countries; the PoisonX EDR-kill driver is now distributed in the GentleKiller toolkit to affiliates, escalating defensive evasion capability enterprise-wide.
FILE DATE: MAY 2026
Backend 'Rocket' Database Compromise and Leak
The group's internal backend database was leaked on May 4, 2026, ████████████████ operators, affiliate identities, live ransom negotiation transcripts, Bitcoin laundering chains, and the complete toolchain — yet operations continued uninterrupted.
FILE DATE: APR 2026
UK Software Consultancy High-Profile Breach
A named UK software consultancy publicly disclosed a breach by The Gentlemen in April 2026, with the group claiming exfiltration of customer infrastructure data, secrets, and NDAs.
FILE DATE: JAN 2026
Q1 2026 Surge — 182 Victims in Single Quarter
The Gentlemen jumped from 16th place (35 victims) in Q4 2025 to 2nd most active globally (182 victims) in Q1 2026, a 315% quarter-over-quarter increase ██████████████████████ affiliate talent away from rival RaaS programs.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn