The Gentlemen Ransomware: Emerging Multi-Region Enterprise Threat — 80+ Victims Across 30+ Countries Since September 2025

The Gentlemen Ransomware (TL-2026-0076) is a high-severity ransomware operation scored CVSS 7.5, first published 2026-02-12. It is attributed to The Gentlemen with low confidence, maps to 32 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 12 detection rules and 30 indicators of compromise.

Key facts for TL-2026-0076

Threat ID
TL-2026-0076
Severity
HIGH
CVSS
7.5
Status
ACTIVE
Category
RANSOMWARE
First published
2026-02-12
Last reviewed
2026-02-12
Attribution
The Gentlemen
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
Manufacturing, Financial Services, Construction, Education, Healthcare, Technology, Transportation, Energy, Public Sector, Consumer Services, Automotive
Target regions
Southeast Asia, Latin America, Europe, Middle East, Africa, North America, East Asia
Detection rules
12
Indicators of compromise
30

Malware and tooling in The Gentlemen Ransomware

Malware and tooling: the gentlemen

The Gentlemen is an emerging ransomware group first observed in September 2025 that has rapidly established itself as a prolific, multi-region enterprise threat with 80+ confirmed victims across 30+ countries. Profiled by SOCRadar's Dark Web intelligence team, The Gentlemen operates a dedicated leak site on Tor and targets a diverse range of sectors including manufacturing, financial services, construction, education, technology, healthcare, and transportation/logistics. Notable for geographic breadth spanning Asia-Pacific, Latin America, Europe, Middle East, and Africa — with particularly heavy targeting of Southeast Asian, Latin American, and Turkish organizations. Victim organizations range from mid-market companies to major enterprises including Colliers International ($5.2B revenue), Silverlake Axis (publicly traded fintech), 2GO Group (Philippine logistics, publicly traded), and PLUS Malaysia Berhad (national highway operator). The group demonstrates rapid operational tempo with 15+ new victims posted in a single week (Feb 6-11, 2026) and multi-terabyte data exfiltration (3TB from KlearNow.AI, 1.5TB from an unnamed Asian investment firm). Attack dating suggests some victims were compromised months before public disclosure, indicating patient network persistence.

How The Gentlemen Ransomware works

The Gentlemen ransomware group represents a new entrant in the Ransomware-as-a-Service (RaaS) ecosystem that has achieved remarkable scale in under 6 months of observed operations. First tracked in September 2025 with initial victims (JN Aceros, Flexofast Indonesia, Cremona Inoxidable), the group has grown to 80+ confirmed victims by February 2026.

OPERATIONAL CHARACTERISTICS:

1. GEOGRAPHIC TARGETING — Unusually broad geographic spread across 30+ countries: - Southeast Asia: Thailand (multiple — USTAR, BioNet-Asia, Lotus Bedding, JIEI, Thai Future Inc.), Vietnam (SASI JSC, AiHealth, KIM Dental, Donacoop), Taiwan (NFT Technology, PAO HWA, Wieson Technologies), Philippines (Personal Collection, 2GO Group), Indonesia (Flexofast, PT Pupuk Iskandar Muda), Malaysia (WCT Holdings, PLUS Malaysia, BIB Insurance) - Latin America: Brazil (UniFil, Stewart Engenharia, Santa Casa de Assis, Unimed Anápolis), Colombia (Área Limpia, Autofinanciera), Peru (JN Aceros, AUSA), Mexico (Cadisa, Del Campo Supreme), Chile (Seguros la Cámara), Ecuador (Ecuacorriente) - Europe: Spain (CPQ Ingenieros, Sansala, L'Aeroclub, Grupo Halcon), Italy (Silvi SRL, ICET Studios, Talarico, Sita Sud), Portugal (Museu do Caramulo), France (Hafa), Germany (Röben, BAM), Ireland (Smartply Europe), Poland (MBM, Wamtechnik, Systherm, Hart), Czech Republic (Garko, Orlík), Sweden (Hafa), Austria (Gady Family), Luxembourg (BAM) - Middle East/Africa: UAE (Marina Home Interiors), Israel (Magen Eco Energy, Shtainmetz Aminoach), Turkey (Erg Otoyol, Ankara-İzmir, Pos Bilişim, Dekoyap), South Africa (Rola Motor Group, Paltrack), Kenya (Wells Fargo Ltd, CPF Financial), Ghana (energy sector), Madagascar (Madagascar Airlines), Mauritius (Rogers Capital) - North America: USA (Clark Foam Products, KlearNow.AI, Hog Slat, Abatix, Infinite Tiers, Dome Partners, Torus), Canada (All Rush) - Other: Hong Kong (Novetex Textiles), Japan (Nishiyama Seisakusho, Sincere Corp), India (Nobel Hygiene, DRD Communications), Dominican Republic (Casa de España), Zimbabwe (Proplastics)

2. SECTOR DIVERSITY — Targeting across all major industries: - Manufacturing: Clark Foam, Smartply, Novetex Textiles, Nishiyama, Röben, Silvi SRL, Wieson Technologies, Nobel Hygiene, Flexofast, Cremona Inoxidable - Financial Services: Wells Fargo Ltd (Kenya), EXIM Bank (Jamaica), CPF Financial, Rogers Capital, Kandeo Fund, Silverlake Axis - Construction/Infrastructure: WCT Holdings, Erg Otoyol, PLUS Malaysia, Ankara-İzmir Railway, CPQ Ingenieros - Education: Thammasat University, British School of Brasilia, UniFil, MBM, Cervantes - Healthcare: Unimed Anápolis, KIM Dental, AiHealth, BioNet-Asia (vaccine manufacturer), Santa Casa de Assis - Technology: KlearNow.AI, NFT Technology, Silverlake Axis, Infinite Tiers, Pos Bilişim - Transportation/Logistics: PLUS Malaysia, 2GO Group, Madagascar Airlines, AUSA, L'Aeroclub, Sita Sud

3. OPERATIONAL TEMPO — Rapid escalation: - Sep 2025: ~10 initial victims (first observed) - Oct 2025: ~10 additional victims including publicly traded companies - Nov 2025: ~8 victims including Colliers International ($5.2B) - Dec 2025: ~8 victims across 5 countries - Jan 2026: ~20+ victims — dramatic acceleration - Feb 2026 (first 11 days): 15+ new victims — sustained high tempo

4. DATA EXFILTRATION SCALE: - KlearNow.AI: 3 TB of data including 'all correspondence' - Unnamed Asian investment firm: 1.5 TB (company with >$10B AUM) - Regional grocery network: 'entire infrastructure' of ~80 stores - Multi-terabyte theft indicates dwell time for staging and exfiltration

5. ATTACK TIMING DISCREPANCIES: - Several victims show attack dates MONTHS before discovery (Thin Red Line: attacked Sep 2025, discovered Feb 2026 — 5 months) - Multiple victims listed with 'Estimated Attack Date: 2025-02-19' suggesting possible bulk data from early 2025 operations or a different dating methodology - Rapid posting of 15+ victims in a single week (Feb 6-11) suggests batch disclosure or multiple simultaneous operations

ATTRIBUTION & INFRASTRUCTURE: The Gentlemen operates a Tor-based leak site for victim naming and shaming. The group's name suggests a 'professional' or 'gentleman thief' branding — positioning themselves as sophisticated operators rather than crude extortionists. No confirmed attribution to a nation-state or known threat actor group. The geographic and sector diversity suggests either a large affiliate network or an efficient small team with broad access to initial access brokers (IABs).

RaaS ECOSYSTEM POSITION: The Gentlemen fills a gap as a mid-tier ransomware operation targeting the underserved mid-market and emerging market segments. Unlike LockBit or DragonForce which focus on large Western enterprises, The Gentlemen appear to target organizations in Southeast Asia, Latin America, and emerging markets where cybersecurity maturity may be lower and response capabilities limited.

MITRE ATT&CK techniques used in TL-2026-0076

credential-access

T1003 OS Credential Dumping; T1558 Steal or Forge Kerberos Tickets

collection

T1005 Data from Local System; T1039 Data from Network Shared Drive; T1074 Data Staged; T1560 Archive Collected Data

lateral-movement

T1021 Remote Services

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

discovery

T1046 Network Service Discovery; T1082 System Information Discovery; T1135 Network Share Discovery

execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1569 System Services

privilege-escalation

T1068 Exploitation for Privilege Escalation

defense-evasion

T1070 Indicator Removal; T1078 Valid Accounts

persistence

T1136 Create Account; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

initial-access

T1190 Exploit Public-Facing Application; T1566 Phishing

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

resource-development

T1585 Establish Accounts; T1588 Obtain Capabilities

reconnaissance

T1591 Gather Victim Org Information; T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Remediation for The Gentlemen Ransomware

Patches

  • No specific CVEs — The Gentlemen likely use initial access brokers, phishing, and exposed services for entry
  • Ensure all internet-facing services are fully patched (VPN, RDP, web applications)
  • Apply all available OS and application patches — unpatched systems are primary ransomware entry points

Immediate actions

  • Review network segmentation to limit lateral movement — The Gentlemen achieve multi-terabyte exfiltration indicating prolonged dwell time
  • Implement robust data loss prevention (DLP) monitoring — 1.5-3 TB data exfiltration should trigger alerts before completion
  • Verify backup integrity and test restoration procedures — ransomware recovery depends on clean, isolated backups
  • Deploy EDR across all endpoints with behavioral detection enabled — detect ransomware deployment and lateral movement
  • Monitor dark web leak sites (ransomware.live, Tor) for organizational mentions — early warning of potential compromise

Workarounds

  • Disable unnecessary RDP and remote access services — common ransomware initial access vector
  • Implement MFA on all remote access and privileged accounts
  • Deploy application whitelisting to prevent unauthorized executable execution
  • Segment OT/ICS networks from IT networks for manufacturing sector targets
  • Implement canary files and honeypots to detect ransomware encryption activity early

Longer-term hardening

  • Implement zero-trust network architecture to limit initial access broker exploitation
  • Deploy network detection and response (NDR) to identify large-scale data staging and exfiltration
  • Establish incident response retainer with a firm experienced in ransomware negotiations
  • Conduct regular tabletop exercises specifically for ransomware scenarios
  • Implement privileged access management (PAM) to restrict domain admin capabilities
  • Organizations in Southeast Asia, Latin America, and emerging markets should prioritize cybersecurity investment — The Gentlemen specifically target regions with lower security maturity

Timeline of The Gentlemen Ransomware

  • The Gentlemen ransomware group posts initial batch of victims on their Tor leak site. First confirmed victims include JN Aceros (Peru), Flexofast Indonesia, Cremona Inoxidable (Argentina), Grupo Halcon (Spain), and others. Estimated attack dates suggest some compromises occurred as early as June 2025. Source: ransomware.live
  • Silverlake Axis (publicly traded fintech, stock symbol 5CP) posted as victim — marks escalation to enterprise-class targets. 2GO Group (Philippine logistics, publicly traded) and PT Pupuk Iskandar Muda (Indonesian state-owned fertilizer) also compromised around this period. Source: ransomware.live
  • Colliers International ($5.2B revenue global commercial real estate) posted as victim. An unnamed Asian investment firm with >$10B AUM also breached with 1.5TB data stolen. Marks The Gentlemen as capable of targeting major enterprises. Source: ransomware.live
  • Massive batch of victims posted: 15+ organizations across 10+ countries in a single disclosure event. Targets include banks (CPF Financial, EXIM Bank), energy (Magen Eco Energy), transportation (Sita Sud, PLUS Malaysia), and manufacturing across Asia, Latin America, Europe, and Africa. Source: ransomware.live
  • Another major victim posting: 15+ organizations including Ankara-İzmir High-Speed Railway (Turkish government project), Marina Home Interiors (UAE), Novetex Textiles (Hong Kong), multiple European targets. Data theft includes 3TB from KlearNow.AI. Source: ransomware.live
  • SOCRadar publishes Dark Web Profile of The Gentlemen ransomware, noting rapid deployment speed, multi-region enterprise operations, and coordinated targeting. Threadlinqs catalogs as TL-2026-0076. 80+ confirmed victims across 30+ countries in under 6 months. Source: SOCRadar/Threadlinqs
  • As of 2026-05-29, The Gentlemen RaaS group remains highly ACTIVE and escalating: ransomware.live shows 442 victims with new posts on May 28 2026, and Check Point ranks it 2026's #2 group (320+ claims, 1,570+ SystemBC botnet victims). A May 2026 internal-chat leak embarrassed but did not disrupt it; no CVE, no KEV, no takedown, no successor.

Sources cited for The Gentlemen Ransomware

Threats related to The Gentlemen Ransomware

Detection coverage for TL-2026-0076

As of 2026-02-12, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0076 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats