‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out

the gentlemen ransomware group blog

The Gentlemen is a financially motivated ransomware group that combines data theft with encryption to increase pressure on victims. They first came onto the threat scene in July 2025. Rather than relying on encryption alone, the group exfiltrates sensitive business data before locking files, leaving organizations to deal with both operational disruption and the risk of stolen information being exposed.

Bitsight Threat Intelligence (TI) indicates The Gentlemen targets medium-to-large organizations across multiple sectors, with notable activity in the Asia-Pacific region. Its operations are particularly focused on gaining and maintaining control of an environment before encryption begins. The Gentlemen uses legitimate administrative tools alongside its own tooling to elevate privileges, establish persistence, interact with systems remotely, weaken security controls, and interfere with recovery.

Who is (are?) The Gentlemen ransomware group?

The Gentlemen, also tracked as Thegentlemen and Storm-2697, is a financially motivated ransomware operation that uses a Ransomware-as-a-Service (RaaS) model. In a RaaS model, the ransomware operators develop and maintain the malware and supporting infrastructure, then allow affiliates to use it to carry out attacks, typically in exchange for a share of ransom payments.

The group follows a dual-extortion approach: sensitive information can be stolen before systems are encrypted, giving attackers another source of leverage if a victim refuses to pay. Its ransomware is relevant across Windows, Linux, and ESXi environments, giving The Gentlemen the ability to affect more than employee workstations. Windows and Linux systems may include business-critical servers and applications, while ESXi is commonly used to host multiple virtual machines on a single physical server.

If attackers reach virtualization infrastructure, they can potentially disrupt several systems and workloads at once, significantly increasing the impact of an attack. As of August 2026, The Gentlemen remains highly active. Bitsight TI shows activity associated with the group has increased by 2,100% compared with its typical activity level. It is also 267% more active than other threat similar groups and 214% more active than adversarial entities overall. Together, these signals show a significant increase in activity around the group and make The Gentlemen particularly relevant for defenders to monitor.

the gentleman ransomware blog figure1

How The Gentlemen ransomware operates

The Gentlemen puts considerable effort into preparing an environment before encryption. One part of that is privilege escalation. Bitsight TI associates the group with abuse of legitimate utilities such as PowerRun.exe, giving attackers a way to perform privileged actions using software that may not immediately look malicious.

The group also emphasizes persistence. Observed behavior includes self-restart, run-on-boot execution, registry-based persistence, autostart mechanisms, and scheduled tasks. These techniques can help attacker-controlled processes survive a reboot or regain execution after an interruption. Once inside an environment, The Gentlemen makes broad use of administrative functionality. Bitsight TI identifies Task Scheduler, Windows Management Instrumentation (WMI), and remote PowerShell among the mechanisms associated with its activity. Those are all legitimate technologies, which makes context clues especially important when monitoring them.

The group also works to weaken defenses before encryption. Reported behavior includes disabling security tools, deleting logs and other traces, manipulating permissions, and terminating services that could interfere with the ransomware. Database, backup, remote-access, and virtualization-related services are among those targeted. Shutting them down can make additional data available for encryption while also limiting the victim’s ability to respond or recover.

Encryption and data theft

The Gentlemen supports configurable encryption behavior that can change depending on file size. Bitsight Threat Intelligence identifies XChaCha20 and Curve25519 as cryptographic components associated with the ransomware. The ability to affect Windows, Linux, and ESXi environments increases the potential blast radius, particularly when attackers reach server or virtualization infrastructure.

Encryption, however, is only one side of the incident. The Gentlemen also exfiltrates business data as part of its extortion model. Restoring encrypted systems therefore does not necessarily end the incident. Security teams still need to establish what the attackers accessed and whether sensitive information left the environment.

Ransom note and extortion

The Gentlemen’s ransom note reinforces the group’s dual-extortion strategy. Victims are told that their files have been encrypted and that confidential and business data has also been exfiltrated. The note threatens to publish stolen information on the group’s leak site if the victim does not make contact.

The note also discourages recovery efforts. It warns victims against modifying encrypted files, using third-party recovery services, or attempting to restore systems without negotiating with the attackers. Victims are directed to communicate through Tox, while a Tor-based leak site is provided as part of the group’s extortion infrastructure.

The observed note gives the victim a 239-hour deadline — just under 10 days — to cooperate before the threatened publication of stolen data. This should be treated as an observed deadline from this particular ransom note rather than a fixed timeline used in every Gentlemen attack.

the gentleman ransomware blog figure2

At the time of review on August 19, 2026, the .onion address listed in the ransom note was unavailable. Tor services can become temporarily inaccessible or move to different infrastructure, so the outage alone doesn’t mean the group is inactive.

Bitsight Threat Intelligence indicators

The following indicators were included in the Bitsight Threat Intelligence supplied for this profile:

Hash          ff709591615a26f037a465ce97cc59d6
Hash          1ecaf7098bedaa4ffae0fff3e077f937
Hash          30b49ae2f685d4403d3013410f80c2e2

What defenders should watch for

The best opportunity to stop The Gentlemen is detecting activity before encryption happens. Security teams should watch for:

  • Unusual use of privileged administrative tools
  • Unexpected scheduled-task or autostart activity
  • Suspicious WMI and remote PowerShell execution
  • Changes to security controls
  • Deletion of logs
  • Permission manipulation
  • Unexpected shutdown of database, backup, remote-access, or virtualization services.

Any one of those events may have a legitimate explanation, but all events should be verified when possible. For example, unexpected privileged execution followed by a new persistence mechanism, security-tool disruption, service shutdowns, and unusual outbound data movement should receive immediate attention. The value comes from connecting the behavior rather than treating each alert in isolation.

Organizations should also make sure backup administration is separated from everyday privileged access, retain critical logs somewhere attackers cannot easily delete them, restrict remote administration where it is not required, and regularly test restoration rather than assuming backups will work during an incident. Because The Gentlemen uses dual extortion, ransomware preparation should include data-loss investigation as well as system recovery.

Why this matters

By the time files begin locking, an attacker may already have elevated privileges, established persistence, interacted with other systems, weakened security controls, interfered with backups, and removed data. That gives defenders a much wider detection window than the ransomware payload itself. Privileged-access monitoring, endpoint visibility, network telemetry, resilient logging, backup security, and threat intelligence all have a role to play before the final encryption stage.

How Bitsight can help

Bitsight can help teams connect intelligence about groups such as The Gentlemen to the exposures that actually matter to their organization.

  • Bitsight Cyber Threat Intelligence (CTI), including Ransomware Intelligence, provides intelligence on ransomware groups, their activity, TTPs, victim trends, related vulnerabilities, and pre-ransomware indicators using intelligence from open, deep, and dark web sources. Bitsight CTI is designed to enrich threat information with attack-surface context rather than presenting it as a standalone feed. For The Gentlemen, that can help security teams move beyond simply knowing that the group exists and track changes in ransomware activity, indicators, targeting, and behavior that may be relevant to their environment.
  • Bitsight Attack Surface Intelligence adds the exposure side of that picture. It continuously maps externally facing assets and combines that visibility with threat intelligence so teams can prioritize exposures based on factors such as business criticality, exploit likelihood, and active threat context. 
  • Bitsight Beacon™: Supply Chain Exposure Management gives Security Operations and Third-Party Risk teams visibility into threats affecting critical vendors and suppliers. It is designed to identify infrastructure exposure before an incident, malicious activity during an intrusion, and evidence of compromise across the vendor ecosystem.
  • Bitsight Beacon delivers validated, evidence-backed alerts across infrastructure exposure, malicious activity, intrusions, ransomware victimization, stolen credentials, and other post-compromise signals. That is particularly relevant when a ransomware group may affect a critical supplier before the customer receives a formal breach notification.
  • Bitsight Third-Party Risk Management provides the broader vendor-risk context around those signals. It supports assessment and continuous monitoring of vendors, suppliers, partners, and downstream dependencies, helping teams understand which third parties are most important to the business and where emerging cyber risk deserves attention first.

Together, these capabilities help turn a threat actor profile into something more useful: not just who The Gentlemen is, but where its activity intersects with your own assets, exposures, and supply chain.

The bottom line

The Gentlemen is a financially motivated ransomware operation with a playbook that goes well beyond encryption. Its activity includes data theft, privilege escalation, persistence, broad system interaction, defense evasion, anti-forensics, service disruption, and configurable encryption across Windows, Linux, and ESXi environments. 

Its ransom note makes the extortion strategy especially clear: victims face not only the loss of access to encrypted systems, but also a direct threat that stolen business data will be published if they do not engage with the attackers.

The most useful warning signs may appear well before a ransom note does. Unexpected privileged activity, new persistence mechanisms, remote administration, security-tool disruption, log deletion, service shutdowns, and suspicious data movement can all provide opportunities to catch an intrusion earlier. By the time encryption begins, much of the attack may already have happened.

Bitsight cta background color
SOTU 2026 Image

Report: Exposed AI Services Surged 360% In 2025 & more

The attack surface is expanding as AI becomes more embedded in enterprise and attacker workflows. Get the full picture on AI exposure, exploit pressure, and the underground trends security teams need to watch.

 

Get the report

Bitsight cta background color