The Gentlemen
As of 2026-09-17, The Gentlemen is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 10 threats spanning ransomware, malware. Also known as Qilin, Gentlemen RaaS, Gentlemen Ransomware, The Gentlemen Group. ATT&CK coverage spans 127 techniques across 15 tactics in 10 of 10 tracked threats. Most-observed techniques: T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery), T1685 (Disable or Modify Tools).
Also known as: Qilin, Gentlemen RaaS, Gentlemen Ransomware, The Gentlemen Group, The Gentlemen RaaS, Gentlemen-Locker, Gntlm, Thegentlemen, The Gentlemen Ransomware
ATT&CK techniques observed
- T1486 Data Encrypted for Impact — Impact — observed in 9 of 10 tracked threats
- T1490 Inhibit System Recovery — Impact — observed in 9 of 10 tracked threats
- T1685 Disable or Modify Tools — Defense Impairment — observed in 9 of 10 tracked threats
- T1078 Valid Accounts — Initial Access — observed in 8 of 10 tracked threats
- T1190 Exploit Public-Facing Application — Initial Access — observed in 8 of 10 tracked threats
- T1489 Service Stop — Impact — observed in 7 of 10 tracked threats
- T1005 Data from Local System — Collection — observed in 6 of 10 tracked threats
- T1046 Network Service Discovery — Discovery — observed in 6 of 10 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalation — observed in 6 of 10 tracked threats
- T1090 Proxy — Command and Control — observed in 6 of 10 tracked threats
- T1133 External Remote Services — Initial Access — observed in 6 of 10 tracked threats
- T1021 Remote Services — Lateral Movement — observed in 5 of 10 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 5 of 10 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltration — observed in 5 of 10 tracked threats
- T1018 Remote System Discovery — Discovery — observed in 4 of 10 tracked threats
Tracked threats
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed — HIGH
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts — HIGH
- The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go Encryptor — HIGH
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation — CRITICAL
- GentleKiller BYOVD EDR-Killing Framework Operated by The Gentlemen RaaS (hastalamuerte / Qilin lineage) — HIGH
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation — CRITICAL
- The Gentlemen Ransomware — FortiOS CVE-2024-55591 Authentication Bypass + Custom G-BOT C2 Framework — CRITICAL
- The Gentlemen Ransomware (RaaS) — Defense Evasion TTPs: Event Log Clearing, Defender Disable & AV Exclusions via PowerShell + Scheduled Tasks (Huntress April/May 2026 IRs) — HIGH
- The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion Operations — HIGH
- The Gentlemen Ransomware: Emerging Multi-Region Enterprise Threat — 80+ Victims Across 30+ Countries Since September 2025 — HIGH
Related CVEs
CVE-2025-61884, CVE-2025-61882, CVE-2025-5777, CVE-2025-55182, CVE-2025-33073, CVE-2025-32463, CVE-2025-32433, CVE-2025-26125, CVE-2025-24799, CVE-2025-2479, CVE-2024-55591, CVE-2024-37085, CVE-2022-42045, CVE-2020-1472