'The Gentlemen' Rapidly Rises to Ransomware Prominence

'The Gentlemen' Rapidly Rises to Ransomware Prominence

Dark Reading
Dark ReadingApr 22, 2026

Why It Matters

The Gentlemen’s speed and scale threaten large enterprises across multiple sectors, forcing defenders to reassess network segmentation and monitoring. Its lucrative affiliate model could accelerate ransomware proliferation industry‑wide.

Key Takeaways

  • Gentlemen ransomware claimed over 200 attacks in Q3 2025.
  • Botnet of 1,570+ compromised hosts used for proxy malware.
  • Ransomware written in Go, leverages AD group policy for mass deployment.
  • Affiliates receive 90% of extortion payouts, boosting RaaS attractiveness.
  • Researchers note reliance on Cobalt Strike and public chat apps as OPSEC risks.

Pulse Analysis

The ransomware ecosystem has shifted dramatically with the rise of ransomware‑as‑a‑service platforms, allowing even modestly skilled affiliates to launch enterprise‑scale attacks. The Gentlemen exemplifies this trend, emerging in 2025 and rapidly eclipsing predecessors like DragonForce by amassing a botnet of more than 1,570 compromised hosts. Their use of SystemBC as a covert proxy, combined with Cobalt Strike for initial footholds, underscores a sophisticated infection chain that bypasses many traditional defenses.

Technically, The Gentlemen’s locker is written in Go, enabling cross‑platform execution and frequent updates. Its most striking capability is leveraging Active Directory Group Policy to trigger simultaneous ransomware deployment across an entire domain, a method that dramatically reduces dwell time and maximizes impact. The group also targets VMware ESXi hosts, disables security tools such as Windows Defender and firewalls, and employs SOCKS5 tunnels for stealthy command‑and‑control communication, making detection challenging for conventional antivirus solutions.

From a business perspective, the gang’s 90% affiliate payout structure creates a powerful incentive for cybercriminals to adopt its RaaS model, potentially expanding the ransomware threat surface. Sectors with high-value data—government, healthcare, education, and manufacturing—are especially vulnerable given the gang’s focus on corporate environments. Experts recommend rigorous monitoring of internet‑facing assets, strict network segmentation, timely patching, and robust security awareness programs to mitigate the risk. While The Gentlemen shows signs of operational maturity, its reliance on public chat apps and legacy tools could become a weak point for law‑enforcement or rival groups seeking to disrupt its operations.

'The Gentlemen' Rapidly Rises to Ransomware Prominence

Comments

Want to join the conversation?

Loading comments...