Skip to main content
HIGH Threat Intel #RaaS

The Gentlemen Ransomware: Operations, Tools, and Mitigation

4 min read Runtime Rebel Intel
Primary source: unit42.paloaltonetworks.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • The Gentlemen (Storm-2697) RaaS program rapidly expanded in 2026, targeting diverse sectors globally.
  • Affected systems include edge devices vulnerable to exploitation, and any endpoint susceptible to custom Go-based malware.
  • Prioritize patching edge device vulnerabilities, implementing multi-factor authentication, and comprehensive backup strategies.

Advertisement

The Gentlemen Ransomware: A Rapidly Escalating RaaS Threat

The Gentlemen, also tracked by Unit 42 as Storm-2697, represents a significant and rapidly evolving Ransomware-as-a-Service (RaaS) threat. Active since at least July 2025, the group’s operators were initially observed as affiliates, known as ArmCorp, for the Qilin RaaS program (tracked by Unit 42 as Spikey Scorpius). Public reporting indicates that The Gentlemen transitioned to an independent RaaS model around September 2025. A distinguishing feature of their operation is an exceptionally high affiliate payout of 90% of paid ransoms, far exceeding the traditional 70-80% offered by other RaaS programs. This lucrative incentive has likely contributed to their rapid expansion and increased victim count throughout 2026, positioning them as a prominent threat in the ransomware landscape, according to Unit 42.

Operational Tactics and Tooling of The Gentlemen Ransomware

Initial Access and Execution

The Gentlemen RaaS operators employ a diverse array of initial access techniques common among sophisticated ransomware groups. These methods include the exploitation of edge device vulnerabilities by ransomware in devices such as firewalls and VPNs, brute-force attacks, and leveraging leaked or stolen credentials. They also frequently collaborate with initial access brokers (IABs) to gain footholds into target networks. Once access is established, their ransomware variants, written in both C and Go programming languages, enable broad deployment across different operating systems and virtual infrastructure, enhancing their operational flexibility.

Custom Malware and Evasion Techniques

The group distinguishes itself through the use of custom tooling designed for defense evasion and persistence. Researchers have identified a custom Go-based backdoor, which aids in maintaining access within compromised environments. Another notable tool is “GentleKiller,” an EDR killer framework specifically designed to terminate Endpoint Detection and Response solutions, thereby hindering incident response efforts. Furthermore, there is suspicion of The Gentlemen utilizing an unspecified zero-day vulnerability exploit to further amplify their evasion capabilities, though specific CVEs remain unconfirmed. The ability for security teams to effectively implement strategies for detecting The Gentlemen RaaS custom tooling is paramount for early intervention.

The Gentlemen’s Growing Impact and Targeted Sectors

Unit 42 data reveals an alarming surge in The Gentlemen’s activities in 2026 compared to 2025. Through July 7, 2026, the group had claimed 580 victims across 77 countries since their inception. Notably, 103 of these victims operate within the manufacturing industry, a sector frequently targeted due to its critical need for operational uptime, making it highly susceptible to disruption and coercion. Comparing the last six months of 2025 to the first six months of 2026, the number of claimed victims increased by more than six-fold, even considering the group was only active for four months in 2025. June 2026 recorded their highest monthly victim count to date with 117, nearly a four-fold increase from January 2026. This rapid escalation has cemented The Gentlemen as the second most active RaaS program of 2026 in terms of victim volume, trailing only established giants like Qilin and Akira (tracked as Howling Scorpius by Unit 42).

Actionable Recommendations for Mitigating The Gentlemen Ransomware

Organizations must adopt a proactive and layered security approach for mitigating The Gentlemen ransomware and similar RaaS threats:

  • Patch Management: Prioritize the timely application of security patches, especially for edge devices such as firewalls, VPNs, and other internet-facing systems that are common initial access vectors.
  • Strong Authentication: Implement multi-factor authentication (MFA) across all services, particularly for remote access, VPNs, and critical systems, to counter brute-force and stolen credential attacks.
  • Network Segmentation: Segment networks to limit lateral movement. This can contain the spread of ransomware even if an initial compromise occurs, preventing it from reaching critical assets.
  • Data Backup and Recovery: Maintain immutable and isolated backups of critical data, and regularly test recovery procedures to ensure business continuity in the event of a successful ransomware attack.
  • Endpoint Detection and Response (EDR): Deploy and configure EDR solutions to monitor for suspicious activities, including the presence of custom backdoors or EDR-killing frameworks like GentleKiller. Ensure EDR agents are up-to-date and configured for maximum detection capabilities.
  • Threat Hunting: Actively hunt for indicators of compromise (IoCs) associated with known ransomware groups and their tooling. This includes searching for unusual network connections, anomalous file executions, and attempts to disable security software.

Related: GentleKiller EDR Framework: The Gentlemen RaaS Defense Evasion Tactics, The Gentlemen Ransomware: Worm-like Spread, 478 Victims, RaaS Ties

Advertisement

Advertisement