← All actors

The Gentlemen

Aliases: Gentlemen ransomware, TheGentlemen

Source profile review date: 2026-06-21

Added to the source registry: 2025-09-09 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

Locally generated translation; linguistic review is still pending.

Executive summary

The Gentlemen is a rapid-on-the-spot RaaS operation from 2025/2026 that is particularly relevant due to speed, proxy infrastructure and industrial victim claims.

The Gentlemen is part of the latest ransomware threats: a new but rapidly mature operation with affiliate behavior, SystemBC-like access, proxy infrastructure and many claims in industry, IT and consumer-oriented sectors.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Management summary

    The Gentlemen is a priority because the group in recent reporting became very quickly visible and claimed a significant share of public ransomware claims in a short time. For organisations, this is a warning that new names are not automatically immature. A group can only exist briefly and yet use experienced affiliates, existing tools, access brokers and infrastructure already proven in other ecosystems.

    The risk is mainly in speed and stealth. Reporting links The Gentlemen to proxy and tunneling infrastructure and SystemBC-like use to maintain access, conceal traffic and accelerate lateral movement, meaning that organisations with limited visibility on greres, proxy traffic, remote access and internal lateral connections will respond.

    The concrete translation for visitors is: not only look at the name of the group, but also the chain that it probably uses. If VPN, external access, management accounts, file shares and backups are insufficiently separated, a new RaaS name can cause the same damage as an older group with more historical IOC- lists.

    Grouping and development

    The Gentlemen is described as a group that became visible around July 2025 and quickly built up volume. The speed with which the brand was placed indicates experienced people, re-use of criminal infrastructure or affiliates who change from other programs.

    The group seems to be affecting organisations where operational pressure is high: industry, IT, consumer-oriented services and European targets are mentioned in reporting. Such sectors put pressure on production, customer relations, contractual obligations and reputation.

    Because the group is relatively new, each profile must remain alive. Not every claim proves the same payload or access method. Therefore, the best use of this file is defensive: which patterns are likely, what controls should be visible and how validates an organization a claim quickly?

    Operation and attack chain

    The likely attack chain starts with access via stolen credentials, access brokers, vulnerable external services or social engineering. Affiliates can buy existing access and go directly to discovery, privilege usage and data collection. New RaaS groups often grow by making affiliate influx attractive.

    SystemBC-like usage is important because traffic can proxy and give persistence without each connection looking like classic malware-C2. Detection should therefore look at unknown services, prolonged outbound connections, unusual proxy processes and hosts that will function as internal relays.

    After access, data and network exploration follows: domain structure, management accounts, fileshares, backup systems, virtualization and customer data applications. The actor tries to maximize pressure: publication value data, downtime systems and trust-destructing recovery tools.

    In the impact phase, encryption can follow, but extortion often starts earlier. Large archives, staging directories, outbound uploads and contact with victim organizations are just as important as the locker itself. Organisations must therefore run early in the chain hunts on access and data-astaging.

    Known IOCs and artifacts

    Important artifacts include SystemBC-like proxy activity, new services, unknown outbound tunnels, command-and-control via seemingly normal ports, leak-site claims, ransom notes, data-astaging and archives with sensitive data.

    Because The Gentlemen is new, hard hashes and infrastructure are quickly outdated. Label IOC disregarded always with source, date and confidence. Use them for retro-hunting but build structural detection on behavior: proxying, remote access, discovery, credential usage, archiving and exfiltration.

    Note combinations. A single unknown process is not enough, but unknown proxy activity on a server followed by domain discovery, new admin permissions and file-share bulk access is a strong ransomware preparation signal.

    Victim pattern and lessons

    Public reporting mentions The Gentlemen as a fast growing group with focus on industry, IT and consumer sectors, with European emphasis in some datasets. For Dutch and European organisations it is especially relevant that production and supplier chains remain attractive.

    The lesson is that current threats are not just from established names. New brands can grow up faster because tools, access brokers, affiliate knowledge and extortion processes are available as criminal building blocks.

    Use a claim of The Gentlemen as a reason to control remote access, proxy traffic, data access and recovery at the same time. If you look at one of those layers, you miss the point of a modern RaaS attack.

    How to arm yourself

    Monitor greress and proxy behavior. Servers should not just maintain long-lasting unknown outbound tunnels. Make DNS, proxy, firewall and EDR-data compatible in a timeline.

    Limit affiliate speed. MFA on remote access, device compliance, privilege separation and jump hosts ensure that purchased credentials do not directly lead to domain-wide access.

    Hunt on preparation: new services, SystemBC-like behaviour, RDP-hopping, PowerShell discovery, archive formation, cloud sync and access to backup or virtualization management. These are the points where you avoid damage before the name appears on a leak site.

    Specific Hunts

    Hunt at The Gentlemen first for proxy and tunnel behaviour. Search for servers or workstations that maintain long-term outbound connections to unknown VPS, hosting or residential-proxy infrastructure. Combine this with new services, scheduled tasks, registry run keys and processes that do not match the role of the system.

    Check identity around the first suspicious connection. A SystemBC-like channel becomes dangerous only when it coincides with valid logins, privilege escalation or lateral movement. Search for VPN-logins from new countries, MFA-pushes off-work time, new local admins, domain group changes and RDP- sessions that hit multiple servers shortly after each other.

    Hunt on datastaging before encryption. Search for 7z, rar, zip, tar, robocopy, rclone, cloud sync, temporary folders with large files and file-share access by accounts that normally read little data. The Gentlemen is especially dangerous when fast access is directly converted to data and recovery impact.

    Exposure and prevention

    Exposure scans should focus on remote access, edge systems and management interfaces for this actor. An open VPN without strong MFA, an outdated application or a management portal accessible from the internet, gives affiliates a quick start position.

    In addition, check equres policy. Many organizations filter incoming traffic but let servers talk freely out. For a group using proxy or tunnel behavior, that is ideal. Capture which server rolls need outbound internet and block the rest or send it via inspectable proxy .

    Make it detectable. Test whether backup servers, storage control and hypervisors are accessible from ordinary server segments. If so, an actor who is inside can understand or disrupt the recovery chain once.

    Sources and uncertainty

    Because The Gentlemen is relatively new, every technical conclusion must be carefully tagged. Public reporting indicates direction, but incident telemetry determines whether a specific organization has really been affected by this actor.

    Use feed claims as triage, not evidence. A victim name on a leak site is enough to assess sector risk and supplier relationships, but not enough to establish initial access, tooling or data diode.

    The profile should therefore distinguish between claim information, technical IOC disregardeds, behavioral observations and own telemetry at each update. This separation prevents an actual but young group from getting too much certainty.

    Executive Scenario and SOC

    A realistic scenario is an industrial company where a VPN- account is abused, after which an internal server will function as a proxy node. The SOC may only see a new service and outbound traffic. The administrative impact comes later when data from customers, suppliers or production processes is mentioned in a claim.

    The correct first question is not whether all files are already encrypted, but if the actor still has access. Check active sessions, new accounts, persistence, proxy processes, scheduled tasks and connections from systems that normally do not need an internet route.

    For management, the decisive question is whether recovery can safely begin. If domain controllers, backup servers, hypervisors or storage control have not been checked, recovery is possible too early. The Gentlemen-like speed makes half containment dangerous.

    What the visitor needs to check out in concrete terms

    Check that all remote access has MFA and that MFA also applies to vendors, break-glass accounts and legacy protocols. Then check if VPN- and SSO-logs are available for at least 90 days.

    Check whether servers are allowed to connect freely to the Internet. A file server, domain controller or backup server with unlimited outbound access is a perfect tunnel host. Make exceptions explicit and log them.

    Check if data exfil is visible. Who can create large archives, which cloud storage is allowed and which alerts arise in sudden upload volumes? Without this answer double extortion remains largely blind.

    Relationship with Amuneth Exposure

    The exposure scans should be performed atThe Gentlemen help to make the attack surfaces visible before an actor uses them: external services,DNS , web portals,VPN ,TLS- configuration,CMS .

    A technical scan alone is not enough. Link the result to management: who owns the service found, when is it last patched, what logs exist and which accounts can log in?

    When a scan shows a public management interface or outdated platform, this should not be seen as loose vulnerability but as a possible first step towards proxy access, data diode and ransomware impact.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    behaviorSystemBC-like proxy and covert access behaviorNTT / public reporting 2026Detect proxy behaviour and long-term outbound tunnels.
    behaviorRaaS affiliate model with fast intrusion lifecyclepublic ransomware activity reporting 2026Focus on access, lateral movement and data-processing.
    targetingindustrial, IT and consumer-facing sectorspublic reporting 2026Victimology; not read as exclusive targeting.

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.