logo

Emulating the Gentlemen Ransomware

ID: 293f289c-ea6c-5186-b181-475cfd067765

STIX ID: report--293f289c-ea6c-5186-b181-475cfd067765

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Ayelen Torello

...
...

**Executive summary:** This AttackIQ emulation details The Gentlemen ransomware (active since July 2025), its double-extortion model, cross-platform malware (Windows/Linux/ESXi), tradecraft (reconnaissance, GPO abuse, living-off-the-land), defense-evasion and encryption techniques (XChaCha20/Curve25519), example SHA256 samples, and comprehensive TTP-based scenarios to validate security controls against this threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.