The Gentlemen — Ransomware Profile
The Gentlemen is a ransomware-as-a-service operation that emerged in July–August 2025 (Microsoft tracks its operators as Storm-2697) and scaled rapidly by offering affiliates a 90% revenue share. It runs a cross-platform, Go-based locker obfuscated with Garble against Windows, Linux, ESXi, NAS, and BSD systems, using Curve25519/XChaCha20 encryption and self-propagating, worm-like lateral movement. Affiliates gain entry via exposed edge devices and exploitation of CVE-2024-55591, CVE-2025-32433, CVE-2025-33073 and CVE-2025-55182, then abuse Group Policy and the NETLOGON share for domain-wide deployment. Defense evasion relies on BYOVD through the vulnerable ThrottleStop/ThrottleBlood.sys driver (CVE-2025-7771) and the purpose-built GentleKiller EDR killer. The group practices double extortion; a May 2026 leak of its "Rocket" backend database exposed operator chats, and an affiliate's compromised SystemBC C2 server revealed more than 1,570 linked victims beyond public listings.
Read the full analysis on IntelFusions