Ransomware Crew Arms Affiliates for Cross-Platform Datacenter Hits

The Gentlemen is built for broad disruption, not just file encryption. Its affiliates get lockers for Windows, Linux, NAS, BSD, and ESXi, plus EDR-killing tools and pivot infrastructure that can move inside a victim network and reach virtualized systems that hold many workloads at once. Check Point says the group emerged around mid-2025 and has already publicly claimed a little over 320 victims, with most infections in 2026. It recruits affiliates on underground forums, uses Tox for negotiations, and runs an onion leak site and public social account to pressure victims who refuse to pay. The practical risk is a ransomware operation that can hit mixed estates and hypervisors from one affiliate playbook. That makes datacenter availability the target, not just endpoint recovery, and it raises the odds that a single intrusion can spread across Windows hosts, NAS devices, and ESXi infrastructure.

Part of the PlainSec briefing for 2026-04-21

Every edition of this story: Ransomware Crew Arms Affiliates for Cross-Platform Datacenter Hits

Sources