‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out
The Gentlemen is a financially motivated ransomware group operating since July 2025 using a Ransomware-as-a-Service model with dual-extortion tactics. They exfiltrate sensitive data before encrypting systems, targeting Windows, Linux, and ESXi environments. The group focuses heavily on preparation before encryption, using legitimate administrative tools like PowerRun.exe for privilege escalation, and establishing persistence through multiple mechanisms including registry modifications, scheduled tasks, and autostart configurations. They disable security tools, delete logs, terminate database and backup services, and use XChaCha20 and Curve25519 encryption. Primarily targeting medium-to-large organizations in the Asia-Pacific region, their activity has increased by 2,100% compared to typical levels. Victims receive ransom notes with approximately 10-day deadlines threatening to publish stolen data on leak sites if demands are not met.
Indicators of Compromise
- hash: 30b49ae2f685d4403d3013410f80c2e2
- hash: 68225c5613afe2174ed46e074147676b0f9a3915
- hash: 8c87134c1b45e990e9568f0a3899b0076f94be16d3c40fa824ac1e6c6ee892db
- hash: 1ecaf7098bedaa4ffae0fff3e077f937
- hash: ff709591615a26f037a465ce97cc59d6
‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out
Description
The Gentlemen is a financially motivated ransomware group operating since July 2025 using a Ransomware-as-a-Service model with dual-extortion tactics. They exfiltrate sensitive data before encrypting systems, targeting Windows, Linux, and ESXi environments. The group focuses heavily on preparation before encryption, using legitimate administrative tools like PowerRun.exe for privilege escalation, and establishing persistence through multiple mechanisms including registry modifications, scheduled tasks, and autostart configurations. They disable security tools, delete logs, terminate database and backup services, and use XChaCha20 and Curve25519 encryption. Primarily targeting medium-to-large organizations in the Asia-Pacific region, their activity has increased by 2,100% compared to typical levels. Victims receive ransom notes with approximately 10-day deadlines threatening to publish stolen data on leak sites if demands are not met.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.bitsight.com/blog/the-gentlemen-ransomware-group-threat-actor-deep-dive"]
- Adversary
- The Gentlemen
- Pulse Id
- 6a9035ff9a03d932d9008b31
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash30b49ae2f685d4403d3013410f80c2e2 | — | |
hash68225c5613afe2174ed46e074147676b0f9a3915 | — | |
hash8c87134c1b45e990e9568f0a3899b0076f94be16d3c40fa824ac1e6c6ee892db | — | |
hash1ecaf7098bedaa4ffae0fff3e077f937 | — | |
hashff709591615a26f037a465ce97cc59d6 | — |
Threat ID: 6a90b51eacd9273b49c9fb4d
Added to database: 08/27/2026, 22:07:26 UTC
Last updated: 08/28/2026, 03:07:50 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.