Threat Actor Profile

The Gentlemen

Aliases
  • Thegentlemen
  • Gentlemen
  • Storm-2697
Active Since
2025-07-01
Motivation
Financial gain, Extortion, Data theft, Ransomware deployment
Cause
Cybercriminal
Recent Activity

The Gentlemen emerged around mid-2025 and began offering ransomware-as-a-service access to affiliates in September 2025. Recent reporting describes the operation as using a Go-based Windows locker with strong encryption, self-propagation capabilities, defense evasion, anti-forensics, and double-extortion tactics involving data theft and encryption.

Primary Targets
  • Medium-sized organizations
  • Large organizations
  • Education organizations
  • Transportation organizations
  • Healthcare organizations
  • Financial organizations
  • Organizations in Asia-Pacific
  • Organizations across North America
  • Organizations across South America
  • Organizations across Europe
  • Organizations across Africa
  • Organizations across Asia
Target Locations
  • Asia-Pacific
  • North America
  • South America
  • Europe
  • Africa
Target Sectors
  • Education
  • Transportation
  • Healthcare
  • Finance
  • Business Services
  • Technology
Vulnerabilities

Weak privilege controls

Exposed administrative tools

Over-permissioned service accounts

Remote PowerShell exposure

Windows Management Instrumentation abuse

Task scheduler abuse

Insufficient monitoring of legitimate utilities

Inadequate backup and recovery controls

Insufficient endpoint protection hardening

Techniques
  • Ransomware-as-a-service

  • Double extortion

  • Data exfiltration

  • File encryption

  • Privilege escalation

  • Defense evasion

  • Security tool disabling

  • Anti-forensics

  • Log deletion

  • Trace deletion

  • Permission manipulation

  • Service termination

  • Database service termination

  • Backup service termination

  • Remote access service termination

  • Virtualization service termination

  • Persistence through self-restart

  • Run-on-boot persistence

  • Registry autostart usage

  • Scheduled task abuse

  • Windows Management Instrumentation abuse

  • Remote PowerShell usage

  • Encrypted data exfiltration channels

  • Flexible encryption based on file size

  • Self-propagation

  • Lateral movement

Malware Tools
  • Gentlemen ransomware
  • PowerRun.exe
  • Task Scheduler
  • Windows Management Instrumentation
  • Remote PowerShell
  • Golang locker
  • Garble obfuscation
  • XChaCha20
  • Curve25519
  • PsExec
Bitsight Contextualized Intelligence
  • The Gentlemen is a financially motivated RaaS operation using double extortion, Go lockers, strong encryption, self-propagation, service termination, and anti-forensics.

Defensive Takeaways
  • Monitor for abuse of legitimate utilities such as PowerRun.exe

  • Detect suspicious use of task schedulers, Windows Management Instrumentation, and remote PowerShell

  • Harden privileged accounts and service accounts

  • Restrict lateral movement paths and administrative tool abuse

  • Monitor for attempts to disable security tools

  • Monitor for deletion of logs, traces, and shadow copies

  • Alert on termination of database, backup, remote-access, and virtualization-related services

  • Maintain offline or immutable backups

  • Test backup restoration regularly

  • Monitor for unusual encrypted outbound data transfers

  • Review endpoint detection coverage for Go-based ransomware and legitimate tool abuse

How Bitsight Helps

Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.

Request threat intel demo