The Gentlemen Ransomware Expands With Rapid Affiliate Growth
ID: 75a092e9-f58d-5b9d-af66-55759896bf4c
STIX ID: report--75a092e9-f58d-5b9d-af66-55759896bf4c
Feed Name: Infosecurity Magazine (News)
A rapidly expanding ransomware-as-a-service operation called 'The Gentlemen'—active since mid-2025—has been linked to over 320 victimizations and modular, cross-platform tooling (Go-based ransomware for Windows/Linux/NAS/BSD and a C-based ESXi encryptor). Researchers observed enterprise-targeted tactics including automated lateral movement using stolen domain credentials, Group Policy-based mass deployment, credential harvesting, disabling of endpoint protections, process termination of backups/VMs, deletion of shadow copies/logs, and use of post-exploitation frameworks such as SystemBC and Cobalt Strike; telemetry from a related C2 indicated over 1,570 infected systems globally, concentrated in the US, UK and Germany.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
