CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

The Gentlemen

actor · actor:thegentlemen single-source

Ransomware-as-a-service operation (also tracked as Storm-2697 / Phantom Mantis) that surged in Q1 2026, 192 attacks, +588% QoQ, 32% of victims European, with FortiGate CVE-2024-55591 as the initial-access funnel. ESET (2026-06-18) documents the operators centrally building and maintaining the GentleKiller EDR-killer framework (BYOVD, 48 vendors) for their affiliates.

Aliases: Gentlemen RaaS, Storm-2697, Phantom Mantis

Coverage
9
first 2026-05-10 → last 2026-09-21
Latest activity
2026-09-21
Cisco Talos maps The Gentlemen's AD attack chain, including credential theft from a mounted backup image…
Peak priority
high
4 high · 5 notable
Targets
public-sector
sectors: public-sector, manufacturing, transport · regions: europe, switzerland, dach
Sources cited
21
19 hosts
2026-05-149 appearances2026-09-21

Defender insights

What each entry about The Gentlemen tells a defender to do, newest first.

2026-09-21HIGHCisco Talos maps The Gentlemen's AD attack chain, including credential theft from a mounted backup image rather than the live domain controller

Triage

2026-07-18NOTABLEMetro Mondego confirms a 6 July ransomware attack on internal systems, transport operation unaffected; TheGentlemen claims data theft

Triage

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

documented in

attributed activity

Story timeline

  1. 2026-09-21The Gentlemen's open-directory attack toolchain: mounting a victim's own VHDX backup files to pull ntds.dit and SAM offline, then chunked-rclone exfil to Wasabi
    active-threatsCisco Talos maps The Gentlemen's AD attack chain, including credential theft from a mounted backup image rather than the live domain controller
  2. 2026-07-18TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD
    active-threatsMetro Mondego confirms a 6 July ransomware attack on internal systems, transport operation unaffected; TheGentlemen claims data theft
  3. 2026-06-27"The Gentlemen" ransomware claims 478 victims and adds worm propagation, Switzerland the second-most-targeted European country
    active-threats
  4. 2026-06-20The Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian national
    active-threats
  5. 2026-06-19ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework
    research
  6. 2026-06-12The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named
    active-threats
  7. 2026-05-29The Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor
    active-threats
  8. 2026-05-23Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days
    research
  9. 2026-05-14The Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub
    active-threatsThe Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims
ATT&CK techniques (23 across 13 tactics)

23 techniques observed across 4 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ReconnaissanceActive Scanning
  • Initial AccessExploit Public-Facing Application
  • ExecutionScheduled Task/Job · Scheduled Task/Job: Scheduled Task
  • PersistenceScheduled Task/Job · Scheduled Task/Job: Scheduled Task · Create or Modify System Process: Windows Service
  • Privilege EscalationScheduled Task/Job · Scheduled Task/Job: Scheduled Task · Create or Modify System Process: Windows Service
  • Defense ImpairmentDisable or Modify Tools
  • Credential AccessOS Credential Dumping: Security Account Manager · OS Credential Dumping: NTDS · Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay
  • DiscoveryRemote System Discovery · Permission Groups Discovery: Domain Groups · Account Discovery: Domain Account · Domain Trust Discovery
  • Lateral MovementRemote Services · Remote Services: Remote Desktop Protocol · Remote Services: SMB/Windows Admin Shares · Remote Services: Windows Remote Management · Exploitation of Remote Services
  • CollectionData from Network Shared Drive · Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay
  • Command and ControlProtocol Tunneling
  • ExfiltrationExfiltration Over Web Service · Exfiltration Over Web Service: Exfiltration to Cloud Storage
  • ImpactData Encrypted for Impact

Reconnaissance TA0043

T1595Active Scanning×1

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

Execution TA0002

T1053Scheduled Task/Job×1

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

Persistence TA0003

T1053Scheduled Task/Job×1

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-06-19/eset-the-gentlemen-raas-gang-centrally-builds-and-maintains · ATT&CK page ↗

Privilege Escalation TA0004

T1053Scheduled Task/Job×1

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-06-19/eset-the-gentlemen-raas-gang-centrally-builds-and-maintains · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

Credential Access TA0006

T1003.002OS Credential Dumping: Security Account Manager×1

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

T1003.003OS Credential Dumping: NTDS×1

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

T1557.001Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay×1

By responding to LLMNR/NBT-NS/mDNS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system. This activity may be used to collect or relay authentication materials.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

Discovery TA0007

T1018Remote System Discovery×1

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <code>net view</code> using Net, or, on ESXi servers, `esxcli network diag ping`.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

T1069.002Permission Groups Discovery: Domain Groups×1

Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

T1087.002Account Discovery: Domain Account×1

Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

T1482Domain Trust Discovery×1

Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

Lateral Movement TA0008

T1021Remote Services×1

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

T1021.002Remote Services: SMB/Windows Admin Shares×2

Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1021.006Remote Services: Windows Remote Management×1

Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

T1210Exploitation of Remote Services×1

Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

Collection TA0009

T1039Data from Network Shared Drive×1

Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

T1557.001Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay×1

By responding to LLMNR/NBT-NS/mDNS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system. This activity may be used to collect or relay authentication materials.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

Command and Control TA0011

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit · ATT&CK page ↗

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-09-21/the-gentlemen-open-directory-vhdx-backup-ntds-theft · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit · ATT&CK page ↗

Entries about The Gentlemen (9)

2026-09-21 · view entry permalink →

HIGHCVE-2025-24799NATOB2

The Gentlemen's open-directory attack toolchain: mounting a victim's own VHDX backup files to pull ntds.dit and SAM offline, then chunked-rclone exfil to Wasabi

Cisco Talos recovered an exposed open directory believed to belong to an operator associated with the ransomware-as-a-service brand The Gentlemen, and reconstructed a six-phase attack chain from the directory's own shell command history (Cisco Talos, 2026-09-17). The operator first built a pivot platform using Chisel, Ligolo-ng and SSH tunnels, then ran nmap and masscan against externally exposed hosts and internal services once inside, then used NetExec to enumerate SMB shares, host information, LDAP and computer information in Active Directory; Talos assesses the operator may also have used RustHound/BloodHound-related tools (a Rust BloodHound collector) to collect domain users, groups, computers, administrative privileges and trust relationships for attack-path analysis. For initial footholds against public-facing applications, the actor ran a PoC and sqlmap against CVE-2025-24799, an unauthenticated SQL injection in GLPI's inventory endpoint (fixed in GLPI 10.0.18), and separately downloaded and ran a cPanel/WHM authentication-bypass PoC. Toward the domain controller, the command history shows attempted exploitation of CVE-2020-1472 (Zerologon) and the MS17-010 vulnerabilities alongside NTLM-relay tooling via Responder. Separately, for lateral movement once inside the network, the operator used NetExec and Impacket to attempt authentication against SMB, LDAP, RDP and WinRM across multiple hosts.

The credential-theft step is the chain's most distinctive detail: rather than dumping credentials from a live, monitored domain controller, the operator mounted a backup share over CIFS, installed libguestfs-tools, qemu-utils and nbd-client to inspect the Windows filesystem inside VHDX backup images, copied out ntds.dit, SAM and SYSTEM, and ran Impacket's secretsdump.py offline against the extracted files (Cisco Talos, 2026-09-17). The VHDX backup files themselves (not just the small credential-dump output) were compressed with zstd, split into 256MiB chunks and uploaded concurrently (up to 16 files at a time) to Wasabi cloud storage via rclone, with the operator visibly reconfiguring transfer settings mid-exfiltration to improve speed and reliability. Command and control ran on the open-source AdaptixC2 post-exploitation framework, and Russian-language script comments plus Cyrillic-keymap mistyping in the operator's own bash history (whoami, ls, ip a, clear, exit typed on a Russian keyboard layout) support Talos's existing assessment that The Gentlemen is Russian-speaking-operator-led.

Triage: legitimate backup-verification and disaster-recovery testing also mount VHDX images and inspect their contents, so the mount event alone is not the signal; the discriminator is the immediate follow-on: secretsdump.py or an equivalent credential-extraction tool run against files copied from that mount, on a host or account that has no operational reason to be doing backup verification.

Talos identified open directory infrastructure believed to have been used by a threat actor associated with The Gentlemen. During our investigation, we observed numerous tools used to support ransomware operations.

In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups. The command history records the installation of libguestfs-tools, qemu-utils, and nbd-client, the creation of directories such as /mnt/vhdx, and the copying of ntds.dit, SAM, and SYSTEM. The actor then used Impacket's secretsdump.py to extract credentials and password hashes from the collected ntds.dit and SAM files, saving the results as "ntds.txt" and "SAM.txt".

Cisco Talos 2026-09-17
threat21 Sep 04:40Zsingle-sourceOpen finding →
Sources: Cisco Talos

2026-07-18 · view entry permalink →

NOTABLENATOB2

TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD

Metro Mondego (the public operator of the Metrobus light-rail line between Lousã and Coimbra, Portugal) announced on 2026-07-17 that it was hit by a ransomware attack on 6 July that affected "part of its internal systems" without compromising the transport service ("um ataque informático a 6 de Julho que afectou 'parte dos seus sistemas internos', mas sem comprometer a operação do serviço de transporte") (Campeão das Províncias, 2026-07-17). The operator confirms it activated incident-response procedures with external cybersecurity experts and notified the competent authorities, Portugal's National Cybersecurity Centre (CNCS), the National Data Protection Commission (CNPD) and criminal-investigation authorities, and that its investigation is examining whether the attackers copied data from the affected internal systems; it cannot yet determine whether any personal data of passengers, employees or suppliers is involved, but states passenger payment data was not affected (Campeão das Províncias, 2026-07-17). The attack was claimed by the ransomware-and-extortion group TheGentlemen (Microsoft: Storm-2697; registry-tracked), which posted that it extracted confidential documentation and threatened to publish absent payment (TugaTech, 2026-07-16).

A Metro Mondego anunciou esta sexta-feira que foi alvo de um ataque informático a 6 de Julho que afectou “parte dos seus sistemas internos”, mas sem comprometer a operação do serviço de transporte.

Campeão das Províncias

A ação foi reivindicada pelo grupo de cibercriminosos Thegentlemen, que afirma ter conseguido extrair documentação confidencial

TugaTech 2026-07-16
incident18 Jul 04:35Zmulti-sourceOpen finding →

2026-06-27 · view entry permalink →

HIGH

"The Gentlemen" ransomware claims 478 victims and adds worm propagation, Switzerland the second-most-targeted European country

UPDATE (originally covered in the 2026-W25 weekly): The fresh in-window signal on The Gentlemen ransomware operation is geographic: Swiss tech press, citing Check Point Research, reports Switzerland as the second-most-targeted European country (after Germany) for the group (inside-it.ch, 2026-06-26).

The group's established profile (detailed earlier this month) is 478 claimed victims and a --spread command-line argument enabling self-propagation across Windows networks via SMB share enumeration and credential reuse (The Hacker News, 2026-06-11). Combined with the previously reported GentleKiller BYOVD EDR-killer, the Swiss-targeting signal means a foothold in one Swiss organisation can spread laterally without further operator action; defenders should enforce SMB signing, restrict admin shares, apply the Microsoft vulnerable-driver blocklist, and alert on a --spread argument in ransomware process trees.

threat27 Jun 05:17Zmulti-sourceOpen finding →

Earlier coverage (6)

2026-06-20NOTABLEThe Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian nationalUPDATE (originally covered 2026-06-19): Following ESET's 2026-06-19 documentation of the group's GentleKiller EDR-killer framework, The Gentlemen ransomware group has claimed an OT-adjacent attack on Mackay Sugar (Australia's second-largest sugar producer), which confirmed on 2026-06-18 that an external party …2026-06-19NOTABLEESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer frameworkESET's months-long investigation into the Gentlemen ransomware-as-a-service operation reveals a structural departure from the affiliate norm: rather than each affiliate sourcing its own evasion tooling, the operators build, maintain and distribute a modular EDR-killing framework (GentleKiller) centrally (ESET …2026-06-12HIGHThe Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly namedThe Gentlemen RaaS claims 478 leak-site victims (concentrated in Thailand, the UK, Brazil, Germany and India per THN); Krebs publishes an operator deanonymisation, and Microsoft's dissection details the encryptor's --spread worm mode (KrebsOnSecurity, 2026-06-10).2026-05-29NOTABLEexploitedThe Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptorUPDATE (originally covered 2026-05-20; consolidated in weekly W21): Microsoft Threat Intelligence published a full dissection of The Gentlemen ransomware on 2026-05-28, giving Storm-2697 a much sharper technical profile than the victim-list reporting available in week 21.2026-05-23NOTABLERapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 daysRapid7 Labs published its Q1 2026 Threat Landscape Report on 2026-05-21 covering January–March 2026 IR data; the GlobeNewswire release accompanied the post the same day. The findings that change what a Swiss/EU public-sector SOC should prioritise:2026-05-14HIGHThe Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHubThe Gentlemen RaaS backend dumped, Check Point exposes operator handles and tooling; SystemBC C&C reveals 1,570+ victims vs. 332 on the public leak site; decryptor on GitHub. Check Point Research's 2026-05-13 analysis of a 44.4 MB extract from the group's leaked "Rocket" backend (16.22 GB total, posted to the cybercrime forum Breached on 4 May after the group's infrastructure was compromised) maps nine operator handles, the EDR-suppression toolchain (EDRStartupHinder, gfreeze, glinker), the ZeroPulse C2 framework, and a separately-exposed SystemBC C&C server holding 1,570+ victim entries against 332 publicly listed in the first five months of 2026, large under-reporting of true scope. The decryptor is public on GitHub per BankInfoSecurity, making decryption the first action for any in-flight Gentlemen incident (Check Point Research, 2026-05-13; BankInfoSecurity, 2026-05-11).

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats7
  • Research2

Source distribution

  • attack.mitre.org3 (14%)
  • bankinfosecurity.com1 (5%)
  • blog.talosintelligence.com1 (5%)
  • campeaoprovincias.pt1 (5%)
  • github.com1 (5%)
  • globenewswire.com1 (5%)
  • helpnetsecurity.com1 (5%)
  • huntress.com1 (5%)
  • other11 (52%)
All cited sources (21)