The Gentlemen is a financially motivated ransomware group that combines data theft with encryption to increase pressure on victims. They first came onto the threat scene in July 2025. Rather than relying on encryption alone, the group exfiltrates sensitive business data before locking files, leaving organizations to deal with both operational disruption and the risk of stolen information being exposed.
Bitsight Threat Intelligence (TI) indicates The Gentlemen targets medium-to-large organizations across multiple sectors, with notable activity in the Asia-Pacific region. Its operations are particularly focused on gaining and maintaining control of an environment before encryption begins. The Gentlemen uses legitimate administrative tools alongside its own tooling to elevate privileges, establish persistence, interact with systems remotely, weaken security controls, and interfere with recovery.
Who is (are?) The Gentlemen ransomware group?
The Gentlemen, also tracked as Thegentlemen and Storm-2697, is a financially motivated ransomware operation that uses a Ransomware-as-a-Service (RaaS) model. In a RaaS model, the ransomware operators develop and maintain the malware and supporting infrastructure, then allow affiliates to use it to carry out attacks, typically in exchange for a share of ransom payments.
The group follows a dual-extortion approach: sensitive information can be stolen before systems are encrypted, giving attackers another source of leverage if a victim refuses to pay. Its ransomware is relevant across Windows, Linux, and ESXi environments, giving The Gentlemen the ability to affect more than employee workstations. Windows and Linux systems may include business-critical servers and applications, while ESXi is commonly used to host multiple virtual machines on a single physical server.
If attackers reach virtualization infrastructure, they can potentially disrupt several systems and workloads at once, significantly increasing the impact of an attack. As of August 2026, The Gentlemen remains highly active. Bitsight TI shows activity associated with the group has increased by 2,100% compared with its typical activity level. It is also 267% more active than other threat similar groups and 214% more active than adversarial entities overall. Together, these signals show a significant increase in activity around the group and make The Gentlemen particularly relevant for defenders to monitor.
How The Gentlemen ransomware operates
The Gentlemen puts considerable effort into preparing an environment before encryption. One part of that is privilege escalation. Bitsight TI associates the group with abuse of legitimate utilities such as PowerRun.exe, giving attackers a way to perform privileged actions using software that may not immediately look malicious.
The group also emphasizes persistence. Observed behavior includes self-restart, run-on-boot execution, registry-based persistence, autostart mechanisms, and scheduled tasks. These techniques can help attacker-controlled processes survive a reboot or regain execution after an interruption. Once inside an environment, The Gentlemen makes broad use of administrative functionality. Bitsight TI identifies Task Scheduler, Windows Management Instrumentation (WMI), and remote PowerShell among the mechanisms associated with its activity. Those are all legitimate technologies, which makes context clues especially important when monitoring them.
The group also works to weaken defenses before encryption. Reported behavior includes disabling security tools, deleting logs and other traces, manipulating permissions, and terminating services that could interfere with the ransomware. Database, backup, remote-access, and virtualization-related services are among those targeted. Shutting them down can make additional data available for encryption while also limiting the victim’s ability to respond or recover.