SUBJECT PROFILE
The Gentlemen emerged in September 2025 following a payment dispute within the Qilin RaaS program and scaled to 478+ publicly claimed victims across 66+ countries by mid-2026 — the fastest growth trajectory of any RaaS operation on record, comparable to early LockBit 3.0. As of July 10, 2026, the group remains the #2 most active ransomware operation globally by victim count. A May 4, 2026 backend database leak exposed the group's full operator roster, toolchain, victim lists, and Bitcoin laundering chains, yet failed to interrupt operations. Microsoft tracks the encryptor as Storm-2697; it uses Go with Garble obfuscation and supports a self-propagating worm mode (--spread flag) enabling enterprise-wide encryption within minutes via Group Policy weaponization.
Financial extortion; fastest-scaling RaaS operation on record, offering 90% affiliate revenue share to dominate criminal labor market
OPERATIONAL HISTORY
FortiGate CVE-2024-55591 exploitation (T1190), RDP/SSL VPN credential abuse (T1078), SystemBC SOCKS5 proxy for C2 (T1090), Cobalt Strike post-exploitation, GPO weaponization for domain-wide ransomware deployment (T1484.001), AnyDesk/PsExec lateral movement (T1021), SharpADWS AD enumeration (T1087), Mimikatz credential dumping (T1003), NTLMv1 relay attacks (T1557), NTLM relay, double extortion, worm-mode self-propagation (T1210), EDRStartupHinder/gfreeze EDR evasion, PoisonX kernel driver (shared with Hyadina affiliates), Curve25519+XChaCha20 encryption (Go variant), AES-256-GCM (C/ESXi variant)
KNOWN INFRASTRUCTURE
Tor-based dedicated leak site, Proton66 Russian bulletproof hosting, 'Rocket' admin backend database, SystemBC botnet C2 with 1,570+ victim nodes, X/Twitter public pressure account, TOX encrypted operator comms, CVE-tracking dashboard for vulnerability prioritization