Ransomware Intelligence

the gentlemen

Ransomware group profile

535Victims
RussiaSource country
89Impact score
Also Known As
The Gentlemen Ransomware
the gentlemen

Description

The Gentlemen is a financially motivated ransomware-as-a-service group that emerged in early 2023 and gained significant prominence by 2025. They utilize a double-extortion model, encrypting data while threatening to leak sensitive information, often accelerating pressure tactics without extensive negotiations.

Key insights

  • Targets primarily sectors like healthcare, technology, and construction, avoiding Commonwealth of Independent States entities.
  • Initial access often gained through exploitation of CVE-2024-55591 in FortiOS and FortiProxy devices.
  • Employs advanced tactics including BYOVD attacks for evasion and a pre-ransomware script to disable security measures.
  • Maintains a database of compromised credentials to enhance targeting and operational effectiveness.
  • Demonstrates a preference for rapid data publication to maximize pressure on victims.

Threat Level & Status Breakdown

For the gentlemen · Based on incidents in selected period

4.3threat level
Aggressiveness10/ 10
Lethality0.1/ 10
Criticality2.7/ 10

Status Breakdown

Data Leaked0.6%3
First seenSep 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 23, 2026

Recent activity

Monthly attack count for the gentlemen in the selected period

535Total attacks
103peak in Apr
53.5avg / month
↑ 64 vs first month
SepOctNovDecJanFebMarAprMayJun0306090120

Intelligence

IOCs, YARA/Sigma rules, and related families for the gentlemen

  1. 7e366683f1d175278feefaaa35d87e87076931974506b9f373a775a428c28f10
View full IOC feed16 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for the gentlemen

CVE-2025-7771
CVE-2025-33073
CVE-2025-32433
CVE-2024-55591
CVE-2024-37085
CVE-2023-27532
Other

T1486

T1486

T1490

T1490

T1078

T1078

T1068

T1068

T1059

T1059

T1562

T1562

T1021

T1021

T1021.001

T1021.001

T1047

T1047

T1218

T1218

T1550

T1550

T1555

T1555

Victims(200)

CompanyDomainCountryIndustryStatusDiscovered
Au Vieux Campeur
Unknown
about 24 hours ago
Plateau Excavation
Unknown
1 day ago
Bell Hardware
Unknown
1 day ago
CHIFENG GOLD SEPON
Unknown
1 day ago
Natren
Unknown
1 day ago
Al Dhow Group
Unknown
1 day ago
Beran Concrete
Unknown
1 day ago
BDS CZ
Unknown
1 day ago
Stadttheater Giessen
Unknown
1 day ago
Gegenbauer Elektrotechnik
Unknown
1 day ago
Meccanica Gn
Unknown
1 day ago
MBO GmbH
Unknown
3 days ago
CTM India Limited motherson INDIAOther
Unknown
3 days ago
GIA Partners
Unknown
3 days ago
Hooke Laboratories
Unknown
3 days ago
Rowley Properties
Unknown
3 days ago
Canada Wide Media
Unknown
3 days ago
ErgoMed
Unknown
3 days ago
Royal Thai Navy Housing Cooperative
Unknown
3 days ago
International Freight Services
Unknown
3 days ago

Page 1 of 10

Affected countries(89)

Countries where this group has been reported to target or leak victims.