Ransomware Intelligence

the gentlemen

Ransomware group profile

447Victims
RussiaSource country
89Impact score
Also Known As
The Gentlemen Ransomware
the gentlemen

Description

The Gentlemen is a financially motivated ransomware-as-a-service group that emerged in early 2023 and gained significant prominence by 2025. They utilize a double-extortion model, encrypting data while threatening to leak sensitive information, often accelerating pressure tactics without extensive negotiations.

Key insights

  • Targets primarily sectors like healthcare, technology, and construction, avoiding Commonwealth of Independent States entities.
  • Initial access often gained through exploitation of CVE-2024-55591 in FortiOS and FortiProxy devices.
  • Employs advanced tactics including BYOVD attacks for evasion and a pre-ransomware script to disable security measures.
  • Maintains a database of compromised credentials to enhance targeting and operational effectiveness.
  • Demonstrates a preference for rapid data publication to maximize pressure on victims.

Threat Level & Status Breakdown

For the gentlemen · Based on incidents in selected period

4.2threat level
Aggressiveness10/ 10
Lethality0/ 10
Criticality2.4/ 10
First seenSep 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for the gentlemen in the selected period

447Total attacks
103peak in Apr
44.7avg / month
↓ 24 vs first month
SepOctNovDecJanFebMarAprMayJun0306090120

Intelligence

IOCs, YARA/Sigma rules, and related families for the gentlemen

  1. 7e366683f1d175278feefaaa35d87e87076931974506b9f373a775a428c28f10
View full IOC feed16 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for the gentlemen

CVE-2025-7771
CVE-2025-33073
CVE-2025-32433
CVE-2024-55591
CVE-2024-37085
CVE-2023-27532
Other

T1486

T1486

T1490

T1490

T1078

T1078

T1068

T1068

T1059

T1059

T1562

T1562

T1021

T1021

T1021.001

T1021.001

T1047

T1047

T1218

T1218

T1550

T1550

T1555

T1555

Victims(200)

CompanyDomainCountryIndustryStatusDiscovered
Grupo LTZBR BrazilRetail & E-Commerce
Unknown
2 days ago
Suburban WaterUS United StatesEnergy & Utilities
Unknown
2 days ago
Soniva DentalUS United StatesHealthcare
Unknown
2 days ago
Brian Jessel BMWCA CanadaManufacturing
Unknown
2 days ago
Harrell Martin PeaceUS United StatesProfessional Services
Unknown
2 days ago
Computime GroupUS United StatesManufacturing
Unknown
2 days ago
Bouri GroupEG EgyptManufacturing
Unknown
2 days ago
National IndustriesIN IndiaManufacturing
Unknown
2 days ago
Arabian Procession HoldingSA Saudi ArabiaOther
Unknown
2 days ago
Smile Siam Printing ServiceTH ThailandManufacturing
Unknown
2 days ago
FibrenoireCA CanadaTechnology
Unknown
2 days ago
Weckworth ManufacturingUS United StatesManufacturing
Unknown
2 days ago
M Rocha J Serra LdaPT PortugalManufacturing
Unknown
2 days ago
Anandji HaridasIN IndiaManufacturing
Unknown
2 days ago
Corporacion ProkompraVE VenezuelaRetail & E-Commerce
Unknown
6 days ago
Heartland GrowersUS United StatesOther
Unknown
6 days ago
Grupo PremierMX MexicoManufacturing
Unknown
6 days ago
Fonderia CorraIT ItalyManufacturing
Unknown
6 days ago
TechmarNL NetherlandsTechnology
Unknown
8 days ago
Mayelia AutomotiveCI Ivory CoastManufacturing
Unknown
8 days ago

Page 1 of 10