Ransomware Intelligence

thegentlemen

Ransomware group profile

406Victims
RussiaSource country
89Impact score
Also Known As
The Gentlemen Ransomware
the gentlemen

Description

The Gentlemen is a financially motivated ransomware-as-a-service group that emerged in early 2023 and gained significant prominence by 2025. They utilize a double-extortion model, encrypting data while threatening to leak sensitive information, often accelerating pressure tactics without extensive negotiations.

Key insights

  • Targets primarily sectors like healthcare, technology, and construction, avoiding Commonwealth of Independent States entities.
  • Initial access often gained through exploitation of CVE-2024-55591 in FortiOS and FortiProxy devices.
  • Employs advanced tactics including BYOVD attacks for evasion and a pre-ransomware script to disable security measures.
  • Maintains a database of compromised credentials to enhance targeting and operational effectiveness.
  • Demonstrates a preference for rapid data publication to maximize pressure on victims.

Threat Level & Status Breakdown

For thegentlemen · Based on incidents in selected period

4.2threat level
Aggressiveness10/ 10
Lethality0/ 10
Criticality2.4/ 10

Status Breakdown

Negotiating0.5%2
Claimed77.3%314
First seenJun 2025
Last seenMay 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for thegentlemen in the selected period

406Total attacks
98peak in Apr
33.8avg / month
↑ 68 vs first month
JunJulAugSepOctNovDecJanFebMarAprMay0255075100

Intelligence

IOCs, YARA/Sigma rules, and related families for thegentlemen

  1. 7e366683f1d175278feefaaa35d87e87076931974506b9f373a775a428c28f10
View full IOC feed16 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for thegentlemen

CVE-2025-7771
CVE-2025-33073
CVE-2025-32433
CVE-2024-55591
CVE-2024-37085
CVE-2023-27532
Other

T1486

T1486

T1490

T1490

T1078

T1078

T1068

T1068

T1059

T1059

T1562

T1562

T1021

T1021

T1021.001

T1021.001

T1047

T1047

T1218

T1218

T1550

T1550

T1555

T1555

Victims(200)

CompanyDomainCountryIndustryStatusDiscovered
Corporacion Prokompradnb.comCL ChileProfessional Services
Unknown
6 days ago
Heartland Growersheartlandgrowers.comUS United StatesOther
Unknown
6 days ago
Fonderia Corrafonderiacorra.comIT ItalyManufacturing
Unknown
6 days ago
Grupo Premiergrupopremier.com.mxMX MexicoRetail & E-Commerce
Unknown
6 days ago
Techmarzoominfo.comGB United KingdomTechnology
Unknown
6 days ago
Mayelia Automotivemayelia.comMX MexicoManufacturing
Unknown
6 days ago
Openmind Networksopenmindnetworks.comIE IrelandTechnology
Unknown
11 days ago
Koa Glasskoaglass.co.jpJP JapanManufacturing
Unknown
11 days ago
ACAM Systemautomationacam.atAT AustriaManufacturing
Unknown
11 days ago
TRANSSYSTEM Grouptranssystem.plPL PolandTransportation
Unknown
11 days ago
Caka Grup Lojistikcakagrup.comTR TurkeyTransportation
Unknown
11 days ago
Hussey Seatwayhusseyseatway.comGB United KingdomTransportation
Unknown
11 days ago
Sanatorio Deltasanatoriodelta.comAR ArgentinaHealthcare
Unknown
11 days ago
Le Perreux sur Marneleperreux94.frFR FranceGovernment & Defense
Unknown
11 days ago
Seeley Office Systemsseeleyoffice.comAU AustraliaProfessional Services
Unknown
11 days ago
YMCA of Columbiacolumbiaymca.orgUS United StatesRetail & E-Commerce
Unknown
13 days ago
Grupo Pasquelgrupopasquel.comEC EcuadorOther
Unknown
13 days ago
University of Finance and Administrationvsfs.czCZ Czech RepublicEducation
Unknown
16 days ago
Modern Displaymoderndisplay.comUS United StatesManufacturing
Unknown
16 days ago
DEVO-Techdevo-tech.chCH SwitzerlandTechnology
Unknown
16 days ago

Page 1 of 10