Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.
The Gentlemen emerged around mid-2025 and began offering ransomware-as-a-service access to affiliates in September 2025. Recent reporting describes the operation as using a Go-based Windows locker with strong encryption, self-propagation capabilities, defense evasion, anti-forensics, and double-extortion tactics involving data theft and encryption.
Weak privilege controls
Exposed administrative tools
Over-permissioned service accounts
Remote PowerShell exposure
Windows Management Instrumentation abuse
Task scheduler abuse
Insufficient monitoring of legitimate utilities
Inadequate backup and recovery controls
Insufficient endpoint protection hardening
Ransomware-as-a-service
Double extortion
Data exfiltration
File encryption
Privilege escalation
Defense evasion
Security tool disabling
Anti-forensics
Log deletion
Trace deletion
Permission manipulation
Service termination
Database service termination
Backup service termination
Remote access service termination
Virtualization service termination
Persistence through self-restart
Run-on-boot persistence
Registry autostart usage
Scheduled task abuse
Windows Management Instrumentation abuse
Remote PowerShell usage
Encrypted data exfiltration channels
Flexible encryption based on file size
Self-propagation
Lateral movement
The Gentlemen is a financially motivated RaaS operation using double extortion, Go lockers, strong encryption, self-propagation, service termination, and anti-forensics.
Monitor for abuse of legitimate utilities such as PowerRun.exe
Detect suspicious use of task schedulers, Windows Management Instrumentation, and remote PowerShell
Harden privileged accounts and service accounts
Restrict lateral movement paths and administrative tool abuse
Monitor for attempts to disable security tools
Monitor for deletion of logs, traces, and shadow copies
Alert on termination of database, backup, remote-access, and virtualization-related services
Maintain offline or immutable backups
Test backup restoration regularly
Monitor for unusual encrypted outbound data transfers
Review endpoint detection coverage for Go-based ransomware and legitimate tool abuse
Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.