The Gentlemen is a Ransomware-as-a-Service (RaaS) operation that emerged in mid-2025 and quickly established itself as one of the fastest-growing ransomware groups currently active. The operation is reportedly led by a Russian-speaking threat actor using the aliases hastalamuerte and zeta88. Before launching The Gentlemen, the group operated as ArmCorp, a former affiliate of the Qilin Ransomware operation.
The relationship with Qilin ended publicly when hastalamuerte claimed Qilin owed roughly $48,000 in unpaid commissions. However, while the public claim was made on July 22; the first known Gentlemen sample appeared on VirusTotal on July 17, indicating development of the malware had already begun. The speed at which The Gentlemen started a fully functional RaaS platform suggests this was an experienced team branching out rather than a newly formed ransomware group.
Unlike many other RaaS operations, The Gentlemen maintains a relatively structured organization. Leaked internal communications indicate a core team of approximately nine operators. The core administrators develop and maintain the ransomware locker and affiliate infrastructure, assign intrusion opportunities to affiliates, manage negotiations and revenue sharing, and coordinate overall operations. Individual operators specialize in areas such as FortiGate exploitation, credential harvesting, NTLM relay attacks, browser credential theft, and post-exploitation activities, creating a repeatable intrusion workflow that affiliates can follow.
The Gentlemen operates a double extortion model, encrypting systems while threatening to publish stolen data. More recently, the group expanded its data leak site by publishing breach summary reports alongside victim listings. These reports summarize the intrusion, identify affected systems, estimate the amount of stolen data, and often include screenshots or other evidence of the compromise. The reports increase pressure on victims by documenting the attack publicly while also demonstrating the group’s knowledge of the victim environment.
The affiliate program offers a 90/10 revenue split, one of the more competitive models currently advertised on underground forums. Affiliates receive access to custom ransomware, supporting infrastructure, and operational tooling rather than just an encryptor. The ransomware supports Windows, Linux, BSD, NAS, and ESXi environments, with a dedicated encryptor for ESXi hypervisors. It uses hybrid encryption with a unique key generated for every file and requires a build-specific password during execution, making automated analysis more difficult. Internal discussions also indicate the developers regularly study ransomware families such as Babuk, Qilin, LockBit, and Medusa, incorporating techniques and functionality they view as effective into their own codebase rather than relying on a direct fork of any one family.
Initial access is heavily focused on internet-facing infrastructure. The group’s primary intrusion method has been exploitation of CVE-2024-55591 affecting FortiOS and FortiProxy devices, and researchers have reported that the group maintains access to approximately 14,700 compromised FortiGate devices. Affiliates have also been observed using exposed RDP services, SSL VPN appliances, brute-forced credentials, Cisco edge devices, and NTLM relay attacks. Internal communications further show the group actively tracking newly disclosed vulnerabilities that could expand future access opportunities.
Once inside a network, operators conduct extensive reconnaissance before deploying ransomware. Tooling and techniques are often adjusted based on the security products identified in the victim environment. Defense evasion includes the use of a Bring Your Own Vulnerable Driver (BYOVD) technique that abuses the ThrottleStop.sys drive to terminate protected security software at the kernel level. The group also maintains multiple EDR killer variants, stages stolen data locally before exfiltrating it with tools such as WinSCP or Rclone, and commonly deploys ransomware through Group Policy using the NETLOGON share to encrypt domain-joined systems simultaneously. Before ransom demands are made, operators also review publicly available business intelligence to estimate an organization’s financial position and have been observed tailoring ransom amounts based on that information.
In May 2026, The Gentlemen suffered a breach of its own backend infrastructure that exposed internal chat logs, affiliate information, negotiation transcripts, tooling discussions, and server credentials. The leak provided rare insight into the group’s operations, but it did little to slow the operation. The administrators rebuilt their infrastructure, hardened the ransomware, and resumed normal operations, reinforcing that The Gentlemen remains an active and resilient ransomware threat despite significant operational setbacks.
Organizations with internet-facing edge devices, particularly Fortinet and Cisco infrastructure, should consider The Gentlemen a high-priority threat. The group’s ability to rapidly adopt new exploitation opportunities, support experienced affiliates, and continually evolve its tooling has made it one of the more active ransomware operations currently targeting organizations worldwide.