The Gentlemen (Storm-2697) status: ReliaQuest's Q2 2026 numbers put it ahead of Qilin on the ransomware leaderboard, and a European public-transport victim (Metro Mondego) landed this week
UPDATE · originally covered The Gentlemen (Storm-2697) status update — Unit 42's full profile: 580 victims, a Qilin-affiliate lineage, and a suspected EDR-disable zero-day (2026-07-12)
The prior weekly carried Unit 42's full profile of The Gentlemen (Storm-2697) — 580 claimed victims, a Qilin-affiliate lineage, a 90% affiliate payout and a suspected EDR-disable zero-day. This week the status change is quantitative and reaches the constituency. ReliaQuest's Q2 2026 threat-spotlight reports The Gentlemen "became the most-active group, powered by aggressive affiliate recruitment and a well-packaged intrusion kit" — 300 victims in Q2 against Qilin's 289 — with affiliates receiving pre-compromised victim lists, custom EDR killers and GPO-based deployment tooling, and a "likely AI-accelerated iteration layer" letting the operators refresh tooling faster than human-developer rivals (ReliaQuest, 2026-07-16); Infosecurity Magazine independently corroborates the 300-vs-289 figures (Infosecurity Magazine, 2026-07-17). GuidePoint GRIT's pre-window Q2 review sets the same concentration in context — its "four-headed monster" is Qilin, The Gentlemen, Akira and DragonForce, and it reports the five most prolific groups collectively claimed over 40% of recorded Q2 attacks (Cybersecurity Dive on GuidePoint GRIT, 2026-07-09). Operationally, the group's claimed 6 July attack on Portugal's Metro Mondego — contained to internal systems, transport unaffected — is the fresh European public-sector datapoint. The initial-access funnel (the tracked FortiOS path and opportunistic edge exploitation) is unchanged; the practical takeaway for the constituency is that the most-active RaaS operator of the quarter is one already on its radar, now recruiting and tooling harder, so the FortiOS/edge and EDR-killer hunt posture the earlier coverage set remains the right one.
The Gentlemen became the most-active group, powered by aggressive affiliate recruitment and a well-packaged intrusion kit
ATT&CK mapping
3 techniques mapped from the cited reporting · MITRE ATT&CK v19.1
Resource Development TA0042
T1587.001Develop Capabilities: Malware
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Impact TA0040
T1486Data Encrypted for Impact
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Sources
Update chain
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.