The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts — Threadlinqs Intelligence
As of 2026-07-14, The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts is a high-severity ransomware threat attributed to The Gentlemen (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-1332 · Severity: HIGH · CVSS: 9.6 · Status: ACTIVE · Category: RANSOMWARE
Attribution: The Gentlemen · Russia · FINANCIAL
The Gentlemen, a ransomware-as-a-service operation founded by former Qilin affiliate hastalamuerte after a 2025 payment dispute, displaced Qilin as the #1 ransomware group in June 2026 with 121
The Gentlemen (RaaS admin/founder alias 'hastalamuerte', identified by Krebs/PRODAFT as Russian national Alexander Andreevich Yapaev) emerged from the Qilin affiliate ecosystem in mid-2025. hastalamuerte previously ran a ~20-member Qilin-affiliated crew called ArmCorp and, after a public $48,000 payment-dispute arbitration against Qilin operators on the RAMP forum on 22 July 2025, spun up an independent RaaS brand. First Windows ransomware sample surfaced on VirusTotal 17 July 2025; the group's own leak site went live by early September 2025, alongside an official RaaS launch offering affiliates a 90% profit share (an unusually aggressive split versus the industry-standard 70-80%). PRODAFT has also linked Gentlemen operators to prior affiliate work with Qilin, Embargo, LockBit, Medusa, and BlackLock.
Initial access is edge-infrastructure-centric: mass exploitation of CVE-2024-55591 (FortiOS/FortiProxy authentication bypass via crafted Node.js WebSocket requests achieving super_admin), CVE-2025-32433 (unauthenticated Erlang/OTP SSH daemon RCE, CVSS 10.0), CVE-2025-33073 (Windows SMB Client), and CVE-2025-55182 (React2Shell), plus credential brute-forcing against ~1,000 additional FortiGate VPNs using an 80+ entry dictionary (including honeypot-detection garbage strings) and purchases from initial access brokers. The group maintains an internal database of ~14,700 internet-facing FortiGate devices, built via Shodan/ZoomEye reconnaissance and a cracked SoftPerfect Network Scanner.
Once inside, affiliates use NetExec for host discovery/brute force/lateral movement, DonPAPI and Impacket's dpapi.py for automated DPAPI/LSA secret extraction, a custom Python tool (userpassfort.py) to harvest Fortinet credentials, and custom PowerShell (VCENTER.ps1) to pivot into vSphere/ESXi environments. Persistence and lateral spread rely on new domain accounts (e.g. 'MicrosoftSupporte'), GPO manipulation (including privilege escalation via BadSuccessor, CVE-2025-32463, CVE-2024-37085), RDP group additions, SMB/admin-share access, and AnyDesk/MeshCentral remote-management deployment (hardcoded credentials in shared deployment scripts). Chisel is tunneled over 443 for reverse SOCKS C2, and SystemBC has been observed for auxiliary C2 traffic.
Defense evasion is anchored by GentleKiller, an in-house EDR-killer framework ESET assessed as an internal Gentlemen tool (later corroborated by Group-IB and Check Point) with at least eight distinct variants, each impersonating a legitimate security/gaming product (Kaspersky, FACEIT Anti-Cheat, Valorant, Javelin/EAAntiCheat, WatchDog, a network blocker branded as Qihoo 360, an IObit-branded 'Deletor' cleaner abusing CVE-2025-26125, and a 'G11'/Symantec-branded variant using a custom rootkit driver called PoisonX). Each variant drops and loads a distinct vulnerable or malicious kernel driver as a service (eb.sys, nseckrnl.sys, GameDriverX64.sys, stpm_old.sys/stpm_new.sys, dmx.sys, 360netmon_wfp.sys, IMFForceDelete, PoisonX) and issues DeviceIoControl/native-API IOCTLs from user mode to terminate 400+ processes mapped to 48 security vendors (Microsoft Defender, CrowdStrike, SentinelOne, Kaspersky, Bitdefender, Sophos, and more) at Ring 0, defeating user-mode tamper protection. Binaries are packed with Enigma/Themida, carry forged version info and vendor icons, and copy invalid digital signatures from legitimate executables. Affiliates additionally deploy third-party/leaked EDR killers HexKiller, ThrottleBlood (ThrottleBlood.sys), HavocKiller, viragt64.sys, and an 'EDR-Freeze' tool, plus AntSword webshells. Host-side, operators disable Windows Defender/EDR via PowerShell and GPO, modify registry keys to uninstall Bitdefender endpoint agents and redirect/disable WMI ReadyBoot and GlobalLogger event tracing, and clear Security/Application/System/RDP event logs.
Exfiltration is performed primarily via Rclone (renamed avastrclone.exe to blend in, scheduled through rclone.ps1) configured against an SFTP drop at 194.
Weaknesses (CWE)
CWE-287, CWE-306, CWE-269, CWE-693, CWE-732
Target sectors: manufacturing, technology, health, government administration, finance, professional services
Target regions: North America, Europe, germany, Global
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2024-55591, CVE-2025-32433, CVE-2025-33073, CVE-2025-55182, CVE-2025-32463, CVE-2024-37085, CVE-2025-26125, T1595.002, T1590, T1587.001, T1588.006, T1585.003, T1190, T1078, T1133, T1110.001, T1003.004