logo

The Gentlemen Ransomware Expands With Rapid Affiliate Growth

ID: 75a092e9-f58d-5b9d-af66-55759896bf4c

STIX ID: report--75a092e9-f58d-5b9d-af66-55759896bf4c

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-04-21

Date Updated: 2026-04-22

...
...

A rapidly expanding ransomware-as-a-service operation called 'The Gentlemen'—active since mid-2025—has been linked to over 320 victimizations and modular, cross-platform tooling (Go-based ransomware for Windows/Linux/NAS/BSD and a C-based ESXi encryptor). Researchers observed enterprise-targeted tactics including automated lateral movement using stolen domain credentials, Group Policy-based mass deployment, credential harvesting, disabling of endpoint protections, process termination of backups/VMs, deletion of shadow copies/logs, and use of post-exploitation frameworks such as SystemBC and Cobalt Strike; telemetry from a related C2 indicated over 1,570 infected systems globally, concentrated in the US, UK and Germany.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.