Threats · 66 days ago
The Gentlemen has moved past being a single ransomware crew. It is now built to recruit affiliates, hand out working encryptors, and take only a small cut, which lowers the barrier to entry and raises attack volume at the same time. The standard read — a new gang with a new name — misses that this is now a scale model for monetizing intrusions.
Unit 42 says the operation has been active since at least July 2025 and shifted into a full RaaS model around September 2025, with roughly 20 operators and a 90% payout for affiliates. Its ransomware is written in C and Go, which lets the group push encryptors across Windows, Linux, and virtual infrastructure. The same report also ties the group to broad initial access methods, including edge devices, VPNs, stolen credentials, and access brokers.
For defenders, the change is not just more victims. A larger affiliate pool means more hands on keyboard, more varied intrusion paths, and more chances that mixed OS and virtualization estates get hit in one campaign.
3 sources covering this story
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth.
Why The Gentlemen ransomware is a test of identity and recovery controls
The ransomware’s use of trusted administrative tools and recovery-disruption tactics shows why containment, not just endpoint detection, is becoming central to enterprise defense.
The Gentlemen Ransomware: What You Need to Know | Fortra
Learn how The Gentlemen ransomware group rose to prominence, targets organizations worldwide, and uses stolen credentials to launch attacks.
Part of the PlainSec briefing for 2026-07-10