The Gentlemen
actor · actor:thegentlemen single-source
Ransomware-as-a-service operation (also tracked as Storm-2697 / Phantom Mantis) that surged in Q1 2026, 192 attacks, +588% QoQ, 32% of victims European, with FortiGate CVE-2024-55591 as the initial-access funnel. ESET (2026-06-18) documents the operators centrally building and maintaining the GentleKiller EDR-killer framework (BYOVD, 48 vendors) for their affiliates.
Aliases: Gentlemen RaaS, Storm-2697, Phantom Mantis
Coverage
9
first 2026-05-10 → last 2026-09-21
Latest activity
2026-09-21
Cisco Talos maps The Gentlemen's AD attack chain, including credential theft from a mounted backup image…
Peak priority
high
4 high · 5 notable
Targets
public-sector
sectors: public-sector, manufacturing, transport · regions: europe, switzerland, dach
Sources cited
21
19 hosts
2026-05-149 appearances2026-09-21
Defender insights
What each entry about The Gentlemen tells a defender to do, newest first.
Triage
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
documented in
attributed activity
Story timeline
- 2026-09-21The Gentlemen's open-directory attack toolchain: mounting a victim's own VHDX backup files to pull ntds.dit and SAM offline, then chunked-rclone exfil to Wasabi
- 2026-07-18TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD
- 2026-06-27"The Gentlemen" ransomware claims 478 victims and adds worm propagation, Switzerland the second-most-targeted European country
- 2026-06-20The Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian national
- 2026-06-19ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework
- 2026-06-12The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named
- 2026-05-29The Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor
- 2026-05-23Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days
- 2026-05-14The Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub
Hunting pivots
CVEs
Affected products
ATT&CK techniques (23 across 13 tactics)
23 techniques observed across 4 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissanceActive Scanning
- Initial AccessExploit Public-Facing Application
- ExecutionScheduled Task/Job · Scheduled Task/Job: Scheduled Task
- PersistenceScheduled Task/Job · Scheduled Task/Job: Scheduled Task · Create or Modify System Process: Windows Service
- Privilege EscalationScheduled Task/Job · Scheduled Task/Job: Scheduled Task · Create or Modify System Process: Windows Service
- Defense ImpairmentDisable or Modify Tools
- Credential AccessOS Credential Dumping: Security Account Manager · OS Credential Dumping: NTDS · Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay
- DiscoveryRemote System Discovery · Permission Groups Discovery: Domain Groups · Account Discovery: Domain Account · Domain Trust Discovery
- Lateral MovementRemote Services · Remote Services: Remote Desktop Protocol · Remote Services: SMB/Windows Admin Shares · Remote Services: Windows Remote Management · Exploitation of Remote Services
- CollectionData from Network Shared Drive · Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay
- Command and ControlProtocol Tunneling
- ExfiltrationExfiltration Over Web Service · Exfiltration Over Web Service: Exfiltration to Cloud Storage
- ImpactData Encrypted for Impact
Reconnaissance TA0043
T1595Active Scanning×1
Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
Execution TA0002
T1053Scheduled Task/Job×1
Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.
Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗
Persistence TA0003
T1053Scheduled Task/Job×1
Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.
Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-06-19/eset-the-gentlemen-raas-gang-centrally-builds-and-maintains · ATT&CK page ↗
Privilege Escalation TA0004
T1053Scheduled Task/Job×1
Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.
Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-06-19/eset-the-gentlemen-raas-gang-centrally-builds-and-maintains · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗
Credential Access TA0006
T1003.002OS Credential Dumping: Security Account Manager×1
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
T1003.003OS Credential Dumping: NTDS×1
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
T1557.001Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay×1
By responding to LLMNR/NBT-NS/mDNS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system. This activity may be used to collect or relay authentication materials.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
Discovery TA0007
T1018Remote System Discovery×1
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <code>net view</code> using Net, or, on ESXi servers, `esxcli network diag ping`.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
T1069.002Permission Groups Discovery: Domain Groups×1
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
T1087.002Account Discovery: Domain Account×1
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
T1482Domain Trust Discovery×1
Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
Lateral Movement TA0008
T1021Remote Services×1
Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.
Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗
T1021.001Remote Services: Remote Desktop Protocol×1
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
T1021.002Remote Services: SMB/Windows Admin Shares×2
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗
T1021.006Remote Services: Windows Remote Management×1
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
T1210Exploitation of Remote Services×1
Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
Collection TA0009
T1039Data from Network Shared Drive×1
Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
T1557.001Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay×1
By responding to LLMNR/NBT-NS/mDNS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system. This activity may be used to collect or relay authentication materials.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
Command and Control TA0011
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
Exfiltration TA0010
T1567Exfiltration Over Web Service×1
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.
Evidence: 2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit · ATT&CK page ↗
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit · ATT&CK page ↗
Entries about The Gentlemen (9)
Earlier coverage (6)
The Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian nationalUPDATE (originally covered 2026-06-19): Following ESET's 2026-06-19 documentation of the group's GentleKiller EDR-killer framework, The Gentlemen ransomware group has claimed an OT-adjacent attack on Mackay Sugar (Australia's second-largest sugar producer), which confirmed on 2026-06-18 that an external party …ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer frameworkESET's months-long investigation into the Gentlemen ransomware-as-a-service operation reveals a structural departure from the affiliate norm: rather than each affiliate sourcing its own evasion tooling, the operators build, maintain and distribute a modular EDR-killing framework (GentleKiller) centrally (ESET …The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly namedThe Gentlemen RaaS claims 478 leak-site victims (concentrated in Thailand, the UK, Brazil, Germany and India per THN); Krebs publishes an operator deanonymisation, and Microsoft's dissection details the encryptor's --spread worm mode (KrebsOnSecurity, 2026-06-10).The Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptorUPDATE (originally covered 2026-05-20; consolidated in weekly W21): Microsoft Threat Intelligence published a full dissection of The Gentlemen ransomware on 2026-05-28, giving Storm-2697 a much sharper technical profile than the victim-list reporting available in week 21.Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 daysRapid7 Labs published its Q1 2026 Threat Landscape Report on 2026-05-21 covering January–March 2026 IR data; the GlobeNewswire release accompanied the post the same day. The findings that change what a Swiss/EU public-sector SOC should prioritise:The Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHubThe Gentlemen RaaS backend dumped, Check Point exposes operator handles and tooling; SystemBC C&C reveals 1,570+ victims vs. 332 on the public leak site; decryptor on GitHub. Check Point Research's 2026-05-13 analysis of a 44.4 MB extract from the group's leaked "Rocket" backend (16.22 GB total, posted to the cybercrime forum Breached on 4 May after the group's infrastructure was compromised) maps nine operator handles, the EDR-suppression toolchain (EDRStartupHinder, gfreeze, glinker), the ZeroPulse C2 framework, and a separately-exposed SystemBC C&C server holding 1,570+ victim entries against 332 publicly listed in the first five months of 2026, large under-reporting of true scope. The decryptor is public on GitHub per BankInfoSecurity, making decryption the first action for any in-flight Gentlemen incident (Check Point Research, 2026-05-13; BankInfoSecurity, 2026-05-11).
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- EtherRAT×1
- GLPI×1
- GLPI unauthenticated SQL injection via the inventory endpoint, exploited by an operator associated with The Gentlemen RaaS for initial access×1
- Q1 2026 ransomware quarterly synthesis×1
Where this entity is cited
Source distribution
- attack.mitre.org3 (14%)
- bankinfosecurity.com1 (5%)
- blog.talosintelligence.com1 (5%)
- campeaoprovincias.pt1 (5%)
- github.com1 (5%)
- globenewswire.com1 (5%)
- helpnetsecurity.com1 (5%)
- huntress.com1 (5%)
- other11 (52%)
All cited sources (21)
- attack.mitre.orgT1021.002https://attack.mitre.org/techniques/T1021/002/
- attack.mitre.orgT1053.005https://attack.mitre.org/techniques/T1053/005/
- attack.mitre.orgT1562.001https://attack.mitre.org/techniques/T1562/001/
- bankinfosecurity.comBankInfoSecurity, 2026-05-11https://www.bankinfosecurity.com/tables-turned-gentlemen-ransomware-group-suffers-data-leak-a-31654
- blog.talosintelligence.comCisco Taloshttps://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/
- campeaoprovincias.ptCampeão das Províncias (relaying Metro Mondego's statement)https://www.campeaoprovincias.pt/2026/07/17/metro-mondego-foi-alvo-de-ataque-informatico-que-afectou-sistemas-internos/
- github.comGitHub `Bedrock-Safeguard/gentlemen-decryptor`https://github.com/Bedrock-Safeguard/gentlemen-decryptor
- globenewswire.comGlobeNewswire press releasehttps://www.globenewswire.com/news-release/2026/05/21/3299378/36514/en/Rapid7-Q1-2026-Threat-Landscape-Report-Finds-Vulnerability-Exploitation-Overtakes-Social-Engineering-as-the-Top-Initial-Access-Vector.html
- helpnetsecurity.comHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/18/eset-gentlemen-edr-killers/
- huntress.comHuntress Labshttps://www.huntress.com/blog/the-gentlemen-ransomware-defense-evasion-ttps
- inside-it.chinside-it.chhttps://www.inside-it.ch/aufstrebende-ransomware-bande-findet-mehr-schweizer-opfer-20260626
- krebsonsecurity.comKrebsOnSecurityhttps://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/
- learn.microsoft.comASR rules referencehttps://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference
- microsoft.comMicrosoft Threat Intelligence, The Gentlemen dissectionhttps://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/
- rapid7.comRapid7 Q1 2026 Threat Landscape Reporthttps://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/
- research.checkpoint.comCheck Point Research, 2026-05-13https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/
- thedfirreport.comThe DFIR Report, flash alerthttps://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html
- therecord.mediaThe Recordhttps://therecord.media/mackay-sugar-cyberattack-claimed-gentlemen
- tugatech.com.ptTugaTechhttps://tugatech.com.pt/t87569-metro-mondego-e-alvo-de-alegado-ataque-informatico-com-roubo-de-dados
- welivesecurity.comESET WeLiveSecurityhttps://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/