The Gentlemen ransomware operation has rapidly emerged as one of the most active and scalable cybercrime threats since its public appearance in the second half of 2025.
The Gentlemen stands out for its ability to target a wide range of enterprise systems, including Windows, Linux, NAS, BSD, and VMware ESXi environments.
This lineage suggests the group benefits from established infrastructure, experience, and affiliate networks, enabling its fast rise in 2026.
This cross-platform capability enables attackers to maximize disruption, particularly in virtualized infrastructures, where compromising ESXi servers can affect entire data centers.
Attack chains observed in incidents include exploitation of exposed remote services, credential compromise, and abuse of VPN or firewall access.
Security researchers at Levelblue, assess that the group is not entirely new, but rather a continuation of prior ransomware affiliate activity, with links to the Qilin ecosystem and a Russian-speaking actor known as “hastalamuerte.”

Once inside, attackers perform network reconnaissance, escalate privileges, turn off security tools, and deploy ransomware across the domain. Data exfiltration is a core step, reinforcing the group’s double extortion strategy.
Ransomware-as-a-Service Model
The Gentlemen operates a structured ransomware-as-a-service (RaaS) model with a dedicated affiliate panel. This backend reportedly supports payload generation, ransom note customization, victim tracking, and negotiation management.

Affiliates may also use external communication tools like Tox or Session, complicating incident tracking.
The group’s ransom note, commonly named “README-GENTLEMEN.txt,” accompanies encrypted files that use extensions such as “.7mtzhh” or other randomized variants.
The malware itself is reportedly written in Go and requires a password parameter at execution, helping affiliates control deployment and evade automated analysis.
Encryption uses a hybrid model, where smaller files are fully encrypted while larger files are partially encrypted in chunks to accelerate impact.
Before encryption, the malware terminates services tied to backups, databases, and enterprise applications to hinder recovery.
By May 2026, The Gentlemen had claimed 352 victims on its leak site, placing it among the most active ransomware groups globally.

However, incident response data suggests the real number of compromised organizations is significantly higher, with over 1,500 environments showing related activity that never appeared on public leak sites.
The group targets a broad range of industries, with the highest concentration in:
- Professional services (18.8%).
- Manufacturing (17.9%).
- Technology (11.6%).
- Healthcare (8.8%).
Geographically, activity spans over 70 countries, with the largest shares in APAC (28.7%), Europe (28.4%), and the Americas.
The United States leads at the country level, followed by Thailand, France, and Brazil. Notably, Russia and CIS countries are absent, aligning with typical ransomware targeting patterns.

Data theft plays a central role in The Gentlemen ransomware operations. Stolen data is used to pressure victims through leak sites and potential resale.
Recently, underground forums have featured claims of data allegedly linked to the group, offered for sale at around $10,000 in Bitcoin.
Some samples shared by threat actors appear to include sensitive artifacts such as credential files, internal chat logs, and victim data mappings. In one instance, references to a previously known victim organization were identified.
However, researchers caution that these claims remain unverified and should be treated as intelligence leads rather than confirmed breaches of the group’s infrastructure.
The Gentlemen’s rise reflects broader trends in ransomware operations: affiliate-driven scale, reliance on compromised credentials, and exploitation of exposed infrastructure.
The risk extends beyond encryption to include data exposure, regulatory consequences, and reputational damage.
For example, even if a manufacturing company restores its systems from backups after an attack, stolen design documents or financial records could still be leaked or sold, causing long-term business impact.
Organizations are advised to prioritize securing remote access services, enforcing multi-factor authentication, monitoring privileged accounts, and ensuring resilient, isolated backups.
Detection strategies should focus on early-stage attacker behavior such as unusual administrative activity, lateral movement, and data staging before ransomware deployment occurs.
As The Gentlemen continues to scale its operations, its combination of technical capability and affiliate-driven expansion makes it a persistent and evolving global threat.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





