# The Gentlemen

> As of 2026-09-17, The Gentlemen is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 10 threats spanning ransomware, malware. Also known as Qilin, Gentlemen RaaS, Gentlemen Ransomware, The Gentlemen Group. ATT&CK coverage spans 127 techniques across 15 tactics in 10 of 10 tracked threats. Most-observed techniques: T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery), T1685 (Disable or Modify Tools).

- **Nation:** Russia
- **Tracked threats:** 10
- **Categories:** RANSOMWARE, MALWARE
- **Also known as:** Qilin, Gentlemen RaaS, Gentlemen Ransomware, The Gentlemen Group, The Gentlemen RaaS, Gentlemen-Locker, Gntlm, Thegentlemen, The Gentlemen Ransomware
- **As of:** 2026-09-17

## ATT&CK techniques observed

127 techniques observed across 10 of 10 tracked threats. Tactics: Credential Access (15), Discovery (14), Execution (14), Stealth (formerly Defense Evasion) (14), Persistence (12), Command and Control (9).

- [T1486](https://attack.mitre.org/techniques/T1486/) Data Encrypted for Impact — Impact — observed in 9 of 10 tracked threats
- [T1490](https://attack.mitre.org/techniques/T1490/) Inhibit System Recovery — Impact — observed in 9 of 10 tracked threats
- [T1685](https://attack.mitre.org/techniques/T1685/) Disable or Modify Tools — Defense Impairment — observed in 9 of 10 tracked threats
- [T1078](https://attack.mitre.org/techniques/T1078/) Valid Accounts — Initial Access — observed in 8 of 10 tracked threats
- [T1190](https://attack.mitre.org/techniques/T1190/) Exploit Public-Facing Application — Initial Access — observed in 8 of 10 tracked threats
- [T1489](https://attack.mitre.org/techniques/T1489/) Service Stop — Impact — observed in 7 of 10 tracked threats
- [T1005](https://attack.mitre.org/techniques/T1005/) Data from Local System — Collection — observed in 6 of 10 tracked threats
- [T1046](https://attack.mitre.org/techniques/T1046/) Network Service Discovery — Discovery — observed in 6 of 10 tracked threats
- [T1068](https://attack.mitre.org/techniques/T1068/) Exploitation for Privilege Escalation — Privilege Escalation — observed in 6 of 10 tracked threats
- [T1090](https://attack.mitre.org/techniques/T1090/) Proxy — Command and Control — observed in 6 of 10 tracked threats
- [T1133](https://attack.mitre.org/techniques/T1133/) External Remote Services — Initial Access — observed in 6 of 10 tracked threats
- [T1021](https://attack.mitre.org/techniques/T1021/) Remote Services — Lateral Movement — observed in 5 of 10 tracked threats
- [T1027](https://attack.mitre.org/techniques/T1027/) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 5 of 10 tracked threats
- [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration Over Web Service — Exfiltration — observed in 5 of 10 tracked threats
- [T1018](https://attack.mitre.org/techniques/T1018/) Remote System Discovery — Discovery — observed in 4 of 10 tracked threats

## Tracked threats

- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — HIGH
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts](https://intel.threadlinqs.com/threat/TL-2026-1332) — HIGH
- [The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go Encryptor](https://intel.threadlinqs.com/threat/TL-2026-1220) — HIGH
- [Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1086) — CRITICAL
- [GentleKiller BYOVD EDR-Killing Framework Operated by The Gentlemen RaaS (hastalamuerte / Qilin lineage)](https://intel.threadlinqs.com/threat/TL-2026-0893) — HIGH
- [Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0758) — CRITICAL
- [The Gentlemen Ransomware — FortiOS CVE-2024-55591 Authentication Bypass + Custom G-BOT C2 Framework](https://intel.threadlinqs.com/threat/TL-2026-0685) — CRITICAL
- [The Gentlemen Ransomware (RaaS) — Defense Evasion TTPs: Event Log Clearing, Defender Disable & AV Exclusions via PowerShell + Scheduled Tasks (Huntress April/May 2026 IRs)](https://intel.threadlinqs.com/threat/TL-2026-0555) — HIGH
- [The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion Operations](https://intel.threadlinqs.com/threat/TL-2026-0399) — HIGH
- [The Gentlemen Ransomware: Emerging Multi-Region Enterprise Threat — 80+ Victims Across 30+ Countries Since September 2025](https://intel.threadlinqs.com/threat/TL-2026-0076) — HIGH

## Related CVEs

14 CVEs referenced by tracked The Gentlemen activity.

- [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-24799](https://intel.threadlinqs.com/cve/CVE-2025-24799)
- [CVE-2025-2479](https://intel.threadlinqs.com/cve/CVE-2025-2479)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/The%20Gentlemen
