DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // THE-GENTLEMEN-RAASFIRST SEEN: SEP 2025

THE GENTLEMEN (Phantom Mantis / LARVA-368)

ALSO KNOWN AS: Storm-2697 (Microsoft), Phantom Mantis (PRODAFT), LARVA-368, ArmCorp
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia (operator Alexander Andreevich Yapaev of Izhevsk, Russia, deanonymized by Krebs on Security Jun 10 2026)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:SEP 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL77/100
RESOURCES77/100
PERSISTENCE80/100
STEALTH72/100
IMPACT86/100

The Gentlemen emerged in September 2025 following a payment dispute within the Qilin RaaS program and scaled to 478+ publicly claimed victims across 66+ countries by mid-2026 — the fastest growth trajectory of any RaaS operation on record, comparable to early LockBit 3.0. As of July 10, 2026, the group remains the #2 most active ransomware operation globally by victim count. A May 4, 2026 backend database leak exposed the group's full operator roster, toolchain, victim lists, and Bitcoin laundering chains, yet failed to interrupt operations. Microsoft tracks the encryptor as Storm-2697; it uses Go with Garble obfuscation and supports a self-propagating worm mode (--spread flag) enabling enterprise-wide encryption within minutes via Group Policy weaponization.

Financial extortion; fastest-scaling RaaS operation on record, offering 90% affiliate revenue share to dominate criminal labor market

FortiGate CVE-2024-55591 exploitation (T1190), RDP/SSL VPN credential abuse (T1078), SystemBC SOCKS5 proxy for C2 (T1090), Cobalt Strike post-exploitation, GPO weaponization for domain-wide ransomware deployment (T1484.001), AnyDesk/PsExec lateral movement (T1021), SharpADWS AD enumeration (T1087), Mimikatz credential dumping (T1003), NTLMv1 relay attacks (T1557), NTLM relay, double extortion, worm-mode self-propagation (T1210), EDRStartupHinder/gfreeze EDR evasion, PoisonX kernel driver (shared with Hyadina affiliates), Curve25519+XChaCha20 encryption (Go variant), AES-256-GCM (C/ESXi variant)

MANUFACTURING
HEALTHCARE
FINANCIAL SERVICES
TECHNOLOGY
GOVERNMENT
ENERGY
EDUCATION
RETAIL
TRANSPORTATION
LOGISTICS

Tor-based dedicated leak site, Proton66 Russian bulletproof hosting, 'Rocket' admin backend database, SystemBC botnet C2 with 1,570+ victim nodes, X/Twitter public pressure account, TOX encrypted operator comms, CVE-tracking dashboard for vulnerability prioritization

FILE DATE: JUL 2026
Ongoing Global RaaS Campaign — 478+ Victims
As of July 10, 2026, The Gentlemen has claimed 478+ victims across 66 countries; the PoisonX EDR-kill driver is now distributed in the GentleKiller toolkit to affiliates, escalating defensive evasion capability enterprise-wide.
FILE DATE: MAY 2026
Backend 'Rocket' Database Compromise and Leak
The group's internal backend database was leaked on May 4, 2026, ████████████████ operators, affiliate identities, live ransom negotiation transcripts, Bitcoin laundering chains, and the complete toolchain — yet operations continued uninterrupted.
FILE DATE: APR 2026
UK Software Consultancy High-Profile Breach
A named UK software consultancy publicly disclosed a breach by The Gentlemen in April 2026, with the group claiming exfiltration of customer infrastructure data, secrets, and NDAs.
FILE DATE: JAN 2026
Q1 2026 Surge — 182 Victims in Single Quarter
The Gentlemen jumped from 16th place (35 victims) in Q4 2025 to 2nd most active globally (182 victims) in Q1 2026, a 315% quarter-over-quarter increase ██████████████████████ affiliate talent away from rival RaaS programs.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn