Gentlemen RaaS Hits Windows, Linux, and ESXi With New C-Based Locker
ID: 8d2236ed-fc5a-5665-a838-944ca4dff465
STIX ID: report--8d2236ed-fc5a-5665-a838-944ca4dff465
Feed Name: GBHackers
Threat Score
Gentlemen is a rapidly expanding ransomware-as-a-service operation active in early 2026 that provides cross-platform lockers (Go for general OSes and a C-based ESXi locker) to affiliates, enabling large-scale domain compromises and double‑extortion through a Tor leak site; observed TTPs include Cobalt Strike, SystemBC, AnyDesk, Mimikatz, GPO/PowerShell propagation, Defender suppression, and hypervisor-aware encryption targeting VM datastores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
