Ransomware Intelligence

thegentlemen

Ransomware group profile

480Victims
RussiaSource country
89Impact score
Also Known As
The Gentlemen Ransomware
the gentlemen

Description

The Gentlemen is a financially motivated ransomware-as-a-service group that emerged in early 2023 and gained significant prominence by 2025. They utilize a double-extortion model, encrypting data while threatening to leak sensitive information, often accelerating pressure tactics without extensive negotiations.

Key insights

  • Targets primarily sectors like healthcare, technology, and construction, avoiding Commonwealth of Independent States entities.
  • Initial access often gained through exploitation of CVE-2024-55591 in FortiOS and FortiProxy devices.
  • Employs advanced tactics including BYOVD attacks for evasion and a pre-ransomware script to disable security measures.
  • Maintains a database of compromised credentials to enhance targeting and operational effectiveness.
  • Demonstrates a preference for rapid data publication to maximize pressure on victims.

Threat Level & Status Breakdown

For thegentlemen · Based on incidents in selected period

4.2threat level
Aggressiveness10/ 10
Lethality0.1/ 10
Criticality2.2/ 10

Status Breakdown

Data Leaked0.6%3
Negotiating0.4%2
Claimed65.2%313
First seenJun 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 23, 2026

Recent activity

Monthly attack count for thegentlemen in the selected period

480Total attacks
98peak in Apr
36.9avg / month
↑ 69 vs first month
JunJulAugSepOctNovDecJanFebMarAprMayJun0255075100

Intelligence

IOCs, YARA/Sigma rules, and related families for thegentlemen

  1. 7e366683f1d175278feefaaa35d87e87076931974506b9f373a775a428c28f10
View full IOC feed16 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for thegentlemen

CVE-2025-7771
CVE-2025-33073
CVE-2025-32433
CVE-2024-55591
CVE-2024-37085
CVE-2023-27532
Other

T1486

T1486

T1490

T1490

T1078

T1078

T1068

T1068

T1059

T1059

T1562

T1562

T1021

T1021

T1021.001

T1021.001

T1047

T1047

T1218

T1218

T1550

T1550

T1555

T1555

Victims(200)

CompanyDomainCountryIndustryStatusDiscovered
Athens Orthopedic Clinicathensorthopedicclinic.comGR GreeceHealthcare
Unknown
5 days ago
hiddenn
Unknown
5 days ago
Al Khaja Holdingalkhajaholding.comAE United Arab EmiratesProfessional Services
Unknown
5 days ago
Cofaqcofaq.frFR FranceRetail & E-Commerce
Unknown
5 days ago
Sertranssertrans.esES SpainTransportation
Unknown
5 days ago
Burris MacOmberburrismacomber.comUS United StatesProfessional Services
Unknown
5 days ago
Yudu Technologyyudutek.comSG SingaporeTechnology
Unknown
5 days ago
Amigestamigest.frFR FranceOther
Unknown
5 days ago
Ty Thac Cotythac.com.vnVN VietnamManufacturing
Unknown
5 days ago
TERRIO Therapy Fitnessterriotherapy.comMX MexicoRetail & E-Commerce
Unknown
5 days ago
SGS Malaysiasgsmalaysia.comMY MalaysiaProfessional Services
Unknown
5 days ago
Alexander Buch Bilanzbuchhalterbuch-bilanzbuchhalter.deDE GermanyProfessional Services
Unknown
5 days ago
Vera Chimie Managementverachimie.frFR FranceManufacturing
Unknown
5 days ago
Buechel Stonebuechelstone.comUS United StatesManufacturing
Unknown
10 days ago
Maine Oxymaineoxy.comUS United StatesEnergy & Utilities
Unknown
10 days ago
Cole Manufacturingcolemfg.comUS United StatesManufacturing
Unknown
10 days ago
Kozminski Universitykozminski.edu.plPL PolandEducation
Unknown
10 days ago
Constructions Pirainopiraino.frFR FranceOther
Unknown
10 days ago
Fecovitafecovita.comAR ArgentinaOther
Unknown
10 days ago
Traublingertraublinger.deDE GermanyManufacturing
Unknown
10 days ago

Page 1 of 10

Affected countries(89)

Countries where this group has been reported to target or leak victims.