logo

Gentlemen RaaS Hits Windows, Linux, and ESXi With New C-Based Locker

ID: 8d2236ed-fc5a-5665-a838-944ca4dff465

STIX ID: report--8d2236ed-fc5a-5665-a838-944ca4dff465

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-21

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

Gentlemen is a rapidly expanding ransomware-as-a-service operation active in early 2026 that provides cross-platform lockers (Go for general OSes and a C-based ESXi locker) to affiliates, enabling large-scale domain compromises and double‑extortion through a Tor leak site; observed TTPs include Cobalt Strike, SystemBC, AnyDesk, Mimikatz, GPO/PowerShell propagation, Defender suppression, and hypervisor-aware encryption targeting VM datastores.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.