The Gentlemen: the bespoke ransomware with over 1,500 hidden victims

The Gentlemen: the “bespoke” ransomware with over 1,500 hidden victims

A cybercriminal group that emerged in 2025 has now reached second place globally by ransomware victim count, with 504 publicly claimed victims and a confirmed presence in more than 50 countries. A new ESET analysis has exposed GentleKiller — a proprietary, operator-maintained EDR-killing framework with 8 variants targeting 400 processes across 48 security tools — while recent incidents, including an attack on Australian sugar producer Mackay Sugar, demonstrate the group’s capacity to shut down critical physical infrastructure. The group has also formalized a recruitment partnership with BreachForums. The identity of its lead operator, exposed in June 2026, has not slowed its operations in the slightest.


In July 2025, a new ransomware group called The Gentlemen emerged on the cybercriminal scene — yet few anticipated how quickly it would scale. Nine months later, research published on April 21, 2026 by Check Point Research uncovered a finding that fundamentally changed the perceived scope of the threat: by conducting threat hunting against the command-and-control (C2) server of one of its affiliates, investigators identified more than 1,570 compromised corporate networks that had never been publicly reported (Lakshmanan, 2026a). By late June 2026, the group had accumulated 504 publicly claimed victims on its data leak site (DLS) according to Ransomware.Live, making it the second most prolific ransomware operation of 2026, behind only Qilin. A detailed report by Swiss cybersecurity firm PRODAFT — which tracks the group under the name Phantom Mantis — shed light on its infrastructure and origins (Lakshmanan, 2026b), and a landmark ESET analysis published on June 18, 2026 has now dissected what may be the group’s most dangerous capability: its centralized, operator-maintained GentleKiller EDR-killing framework (Lakshmanan, 2026c; Souček, 2026).

The figure is especially alarming when one considers that what appears on the DLS is merely the tip of the iceberg. As Eli Smadja, head of research at Check Point, noted, the real operational scale is significantly larger than what is publicly known, and it continues to grow (Lakshmanan, 2026a).

Who are “The Gentlemen”?

The name is no accident. According to ESET analysts, the group pays aesthetic homage to Guy Ritchie’s films, projecting a disciplined and methodical brand identity, complete with a professional logo and motto on their onion site (Ali Bravo, 2026). But that aesthetic is more than branding: it is reflected in the technical maturity of their operations, to the point that several researchers assume the actors behind the group have prior experience in other ransomware ecosystems (SOCRadar, 2026).

Although its origins remained classified as “unknown” for months, PRODAFT’s June 2026 report revealed that the group is led by a Russian-speaking cybercriminal tracked as LARVA-368, who operates under the aliases hastalamuerte, ArmCorp, zeta88, nobody0, and santamuerte (Lakshmanan, 2026b). FortiGuard Labs had already identified a telling indicator: the group expressly prohibits its affiliates from attacking organizations located in Russia and Commonwealth of Independent States (CIS) countries — a restriction historically associated with Russian-speaking threat actors (Fortinet, 2026). A significant expansion move took place in May 2026, when the group formalized an official partnership with BreachForums, a major cybercriminal marketplace, to recruit a broader pool of affiliates including penetration testers and initial access brokers (IABs). Microsoft’s threat intelligence team noted that this partnership may significantly accelerate the group’s growth by lowering barriers to entry for new operators (Microsoft, 2026).

The Gentlemen operates under a Ransomware-as-a-Service (RaaS) model with unusually generous terms: 90% of ransom proceeds go to the executing affiliate. A parallel data-only extortion track — exfiltration and publication without encryption — pays affiliates an even higher 97% (PI Solutions, 2026). SOCRadar detected the original recruitment announcement on underground forums in September 2025, and the 90% payout has since proven to be a deliberate growth strategy that pulls high-capability operators away from competing groups (SOCRadar, 2026; Cybersecurity Insiders, 2026).

A significant aspect of the affiliate onboarding process is worth noting: candidates must provide the administrator with at least 1 GB of data exfiltrated from a victim in order to gain access to the affiliate panel. This measure is designed to prevent security researchers or law enforcement from infiltrating the infrastructure under the guise of an affiliate (Lakshmanan, 2026b). Once inside, the panel supports user management, target configuration, and downloading ransomware tailored to each victim.

The toolkit is written primarily in Go and C, with the Go code obfuscated using the Garble tool to hinder static analysis. The group offers five locker versions: for Windows, Linux, ESXi, Windows XP+, and for LVM (Logical Volume Manager) environments on Linux (Lakshmanan, 2026b). The cryptographic scheme combines XChaCha20 and Curve25519 in a hybrid model — per-file ephemeral keys — and includes auto-restart capabilities, startup persistence, and configurable encryption speed throttling to evade detections based on anomalous CPU/IO consumption (Mikhalov, 2025).

A critical technical development revealed by Microsoft — which tracks the group under the identifier Storm-2697 — is the ransomware’s worm-like self-propagation capability: when activated with the --spread argument, the malware transforms from a single-host encryptor into a self-propagating worm that attempts to deploy its encryptor to every reachable system on the network. If the --wipe argument is also provided, the ransomware executes an additional post-encryption routine to eliminate recoverable artifacts from disk, significantly complicating forensic and recovery efforts (Lakshmanan, 2026b; Microsoft, 2026). Additionally, the operators have documented two flags for the local encryption routine: --system for local volume encryption via scheduled task and --shares for network share encryption (Shieldworkz, 2026).

Support services for affiliates are available through Tox, SimpleX Chat, and Ricochet Refresh — open-source messaging platforms that provide additional anonymity for the group’s operational communications.

Identity Exposed: Phantom Mantis and LARVA-368

PRODAFT’s June 2026 report is the most comprehensive analysis to date of The Gentlemen’s origins and internal structure. The Swiss firm tracked the group under the name Phantom Mantis and documented that LARVA-368 is not a new actor in the criminal ecosystem: they have been active since at least 2020 and accumulated operational experience as an affiliate of multiple RaaS groups — LockBit (Tenacious Mantis), Qilin (Pestilent Mantis), Medusa (Venomous Mantis), Embargo (Primeval Mantis), and BlackLock — before launching their own operation (Lakshmanan, 2026b).

The definitive transition toward independence in July 2025 was triggered by a payment dispute with Qilin, in which LARVA-368 accused the group of running an exit scam and defrauding them of $48,000 USD. PRODAFT was unable to independently confirm these accusations and noted the possibility that both LARVA-368 and a collaborator known as LARVA-367 (DevMan) deliberately spread disinformation to discredit Qilin and recruit its affiliates into Phantom Mantis (Lakshmanan, 2026b).

The most significant aspect of PRODAFT’s report is the identification of the person behind LARVA-368. Cybersecurity journalist Brian Krebs publicly exposed their identity on June 10, 2026 as Alexander Andreevich Yapaev (Япаев Александр Андреевич), a 36-year-old from the Russian city of Izhevsk. Breach tracking service Constella Intelligence reported that Yapaev’s Telegram ID is connected to the username bu4vs and to the Russian phone number 79127650004. PRODAFT confirmed to The Hacker News that its findings match this persona with “high confidence” (Lakshmanan, 2026b).

Another revealing element from the report is the role of artificial intelligence in the group’s operations: LARVA-368 makes extensive use of AI for the development and maintenance of the ransomware and auxiliary tools, as well as for assistance with post-exploitation procedures. The leaked internal chat logs confirmed this, with the group’s members openly debating which AI model to use for data analysis (Lakshmanan, 2026b; Security Affairs, 2026b).

A Ransomware That Adapts to Each Victim

What truly distinguishes The Gentlemen is not their code, but their operational philosophy: they do not attack at scale — they attack with precision.

The typical kill chain begins with initial access through internet-facing services — particularly misconfigured firewalls and VPNs, with a documented focus on FortiGate appliances and Cisco devices. A leaked FortiGate intelligence database from the seized SystemBC C2 server revealed a maintained catalogue of 14,700 compromised FortiGate devices and 969 validated brute-forced FortiGate VPN credentials — in some cases credentials stolen years before being weaponized, such as an SFTP credential from 2023 used in a 2026 intrusion (PI Solutions, 2026). This targeting is primarily technically driven rather than geographically driven: victim candidates are selected and vetted centrally based on the configuration of the target’s FortiGate firewall, not on regional preference. The geographic spread observed in victimology is a downstream artifact of where vulnerable or misconfigured FortiGate deployments cluster (Souček, 2026).

The documented red team toolset includes Advanced IP Scanner and Nmap for Active Directory mapping, alongside: NetExec, RelayKing, TaskHound, PrivHound, and CertiHound for Active Directory discovery, certificate abuse, privilege escalation, and file share discovery (Lakshmanan, 2026b). For C2 communication, the group abuses Velociraptor, an open-source DFIR tool repurposed for malicious ends. For defense evasion, dedicated tools include EDRStartupHinder, gfreeze, glinker, and DumpBrowserSecrets (Lakshmanan, 2026b).

For lateral movement they rely on PsExec over SMB admin shares, WMI, PowerShell Remoting, and SCHTASKS — a living off the land (LOLBAS/LOLBins) approach. For persistence, data transfer, and ACL manipulation the arsenal also includes AnyDesk, PuTTY, WinSCP, and ICACLS (Fortinet, 2026).

For the impact phase, they abuse Group Policy Objects (GPO) and the NETLOGON share to propagate the ransomware simultaneously across the entire domain. Prior to encryption, the group executes thorough anti-forensic routines: disabling Windows Defender, adding broad AV exclusions, shutting down the firewall, re-enabling SMB1, stopping backup services, deleting Volume Shadow Copies (VSS), and purging System, Application, and Security Windows Event Logs (Lakshmanan, 2026a; Mikhalov, 2025). Encrypted files receive the extension .7mtzhh and a ransom note named README-GENTLEMEN.txt is left behind.

GentleKiller: The EDR-Killing Framework That Defines This Group

The most technically significant finding in the ESET analysis published on June 18, 2026 is the full anatomy of GentleKiller — The Gentlemen’s proprietary, in-house EDR-killing framework — which the research team led by Jakub Souček spent months reconstructing, later corroborated by the group’s own internal data leak (Souček, 2026; Lakshmanan, 2026c).

Unlike the vast majority of ransomware gangs, which leave affiliates responsible for sourcing their own tools to defeat endpoint security, The Gentlemen centralize this function: operators actively develop, maintain, and distribute a complete EDR-killer suite to vetted affiliates. ESET notes this makes the group one of the most attractive RaaS operators in the current market, as it materially lowers the entry barrier for affiliates and produces more consistent, faster attack chains.

GentleKiller comes in at least eight variants, each impersonating a different legitimate security product while exploiting a different vulnerable or malicious kernel-level driver via the BYOVD technique. Despite surface-level differences, all variants share the same internal code structure, process-killing logic, and target list — a modular design that allows operators to swap a patched or blocklisted driver for a newly disclosed vulnerable one without touching the core tool. Together, GentleKiller targets over 400 processes associated with 48 distinct security products from vendors including Microsoft, CrowdStrike, SentinelOne, Palo Alto Networks, Sophos, Trend Micro, ESET, Bitdefender, McAfee/Trellix, and Kaspersky. The eight documented variants and their respective drivers are:

Impersonated product Driver abused
Kaspersky eb.sys
FACEIT Anti-Cheat nseckrnl.sys
Valorant GameDriverX64.sys
Javelin stpm_old.sys / stpm_new.sys
WatchDog dmx.sys
Network Blocker 360netmon_wfp.sys
Cleaner IMFForceDelete.sys
G11 PoisonX.sys

The abuse of PoisonX.sys is particularly notable: this driver has been independently recorded in connection with attacks that terminated CrowdStrike Falcon EDR, and in a separate campaign documented by Huntress, threat actors used it alongside hrwfpdrv.sys to disable security tooling before deploying ransomware via a compromised BeyondTrust Remote Support instance (Lakshmanan, 2026c).

Beyond GentleKiller, the suite integrates three externally sourced EDR killers that have been standardized through the same shared defense-evasion pipeline:

All tools in the suite — including those for which the group does not own the source code — are standardized at the compiled binary level through a shared evasion pipeline: binary protection using Enigma or Themida packers, file names mimicking legitimate security vendors, fabricated version metadata, copied (invalid) digital signatures, and matching icons. This standardization creates significant attribution challenges: defenders who observe a ThrottleBlood or HexKiller signature may incorrectly attribute the incident to DragonForce or Warlock rather than The Gentlemen (Cybersecurity Insiders, 2026b).

A defining operational characteristic is the group’s speed in weaponizing newly disclosed BYOVD PoC exploits — in many cases integrating them into GentleKiller within days of public release. Tools like UnknownKiller and PoisonKiller were incorporated into the arsenal within days of their GitHub disclosure. This rapid development cadence distinguishes The Gentlemen from most other RaaS operators, who typically wait weeks or months (CyberSecurityNews, 2026).

This development coincides with an advisory from the CERT Coordination Center (CERT/CC) about multiple vendor-signed UEFI applications that are vulnerable to Secure Boot bypass via a BYOVD attack — research credited to ESET researcher Martin Smolár. The affected vendors include Acer, AMD, ASUS, ECS, Getac, GIGABYTE, Toshiba, and Uniwill. CERT/CC recommends applying updates to the UEFI Forbidden Signature Database (DBX) to revoke trust in the affected binaries. While the advisory is not exclusively linked to The Gentlemen, ESET published it simultaneously with the GentleKiller analysis, directly framing it within the context of the group’s BYOVD escalation (Lakshmanan, 2026c).

OxideHarvest: The Credential Stealer Linked to an Affiliate

Beyond the EDR-killing suite, ESET’s analysis also identified OxideHarvest (also tracked as buildx641 or buildx641.exe), a Rust-based credential stealer attributed not to the core operators but to a specific Gentlemen affiliate known as quant (Souček, 2026; Lakshmanan, 2026c).

OxideHarvest is capable of harvesting saved credentials and session data from a wide range of browsers, including Google Chrome, Microsoft Edge, Mozilla Firefox, Brave, Opera, OperaGX, Vivaldi, Waterfox, BlackHawk, IceCat, Torch, Comodo, and Epic Privacy Browser — covering both Chromium-based and Gecko-based engines. The tool uses supplied credentials to log into specified hosts, extracts browser credential stores, and writes the output to a file for later exfiltration. A sample was identified on VirusTotal under the filename buildx641.exe, confirming its operational integration with the group’s affiliate infrastructure (CyberPress, 2026).

While most of the GentleKiller variants show clear evidence of in-house development by the core operators, OxideHarvest’s Rust-based architecture and external attribution suggest the group’s ecosystem also incorporates affiliate-developed tooling, creating a layered supply chain of criminal tooling that further complicates incident attribution.

SystemBC and the Open Directory: The Pieces That Revealed the True Scale

The April 2026 Check Point investigation focused on how researchers found the 1,570 hidden victims. A Gentlemen affiliate deployed in their attacks a proxy malware known as SystemBC, establishing SOCKS5 tunnels encrypted with RC4 inside victim environments. By analyzing the corresponding C2 server, Check Point obtained the full list of compromised networks, primarily across the United States, United Kingdom, Germany, Australia, and Romania (Lakshmanan, 2026a).

In March 2026, Hunt.io separately discovered an open directory hosted at 176.120.22[.]127:80 on the Russian bulletproof hosting provider Proton66, exposing 126 files containing a complete ransomware operator toolkit attributed to a Gentlemen affiliate and spanning every phase of the intrusion lifecycle (Lakshmanan, 2026b).

A High-Profile Victim: Mackay Sugar and the OT Impact

The most recent confirmed attack attributed to The Gentlemen with significant physical consequences struck Mackay Sugar, Australia’s second-largest sugar producer, on June 10, 2026. The cyberattack disrupted operations at two mills — Farleigh and Racecourse — in Queensland’s Mackay region, forcing the company to advise over 1,300 family-owned farms to cease harvesting (The Register, 2026; Rescana, 2026).

The timing was particularly damaging: the attack hit at the start of the crushing season, when mills run continuously and any interruption means harvested cane left in fields or trucks. Sugar cane must be processed within 48 hours of harvest to preserve sugar content — delays lead to sucrose converting to simple sugars, unwanted fermentation, and lower yields, directly impacting growers’ revenue.

On June 16, 2026, The Gentlemen ransomware group claimed responsibility for the attack and threatened to release stolen data within ten days. The attack exemplifies the group’s capacity to cause severe cyber-physical downtime without directly manipulating any industrial control systems: by crippling IT-side scheduling databases, historian systems, cane supply coordination platforms, and logistics systems, the attackers forced a physical mill shutdown without touching a single PLC or variable-speed drive (Shieldworkz, 2026; Rescana, 2026). By June 15, Mackay Sugar reported partial system restoration and limited manual crushing at Farleigh Mill.

The attack on Mackay Sugar, alongside prior incidents affecting the Romanian state energy operator Complexul Energetic Oltenia, confirms a growing trajectory of The Gentlemen targeting heavy manufacturing, agri-industrial, and energy environments where downtime directly translates to massive financial and physical-world consequences.

Why This Matters Now

The Gentlemen is no longer an emerging threat — it is the second most prolific ransomware operation on the planet in 2026, with 504 publicly claimed victims according to Ransomware.Live as of late June, trailing only Qilin (Cybersecurity Insiders, 2026). In Q1 2026, ZeroFox ranked it as the third most prolific operator worldwide (192 incidents), and by April 2026 NCC Group and Halcyon estimated the group accounted for 10% of all global ransomware activity (Lakshmanan, 2026b).

Although only 13% of their victims are based in the United States — a notable departure from most top-tier ransomware operations, for which the US accounts for roughly half of all announced victims — the group’s geographic distribution points to a deliberate targeting logic: victims are selected primarily based on FortiGate misconfigurations, not regional preference. The geographic spread is a downstream artifact of where vulnerable deployments cluster: Southeast Asia, South America, and Western Europe (Souček, 2026). Mexico appears consistently among the most attacked Latin American countries, alongside Colombia, Argentina, Brazil, Chile, and Peru (Ali Bravo, 2026).

Two recent events illustrate the group’s resilience and development pace. In April 2026, researchers published a free decryptor for Gentlemen victims on GitHub (Bedrock-Safeguard/gentlemen-decryptor), but the group responded with a same-day patch, neutralizing the tool before it could benefit a significant number of victims. A leak of the group’s internal Rocket.Chat database — 3,366 messages from November 2025 to late April 2026 — revealed active tracking of CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, alongside NTLM relay workflows and a clear division of roles among nine core members (Lakshmanan, 2026b).

ZeroFox documents a multi-channel extortion operation: ransomware combined with targeted email campaigns and direct phone-based pressure tactics to accelerate payment. 69% of attacks occur at night and on weekends. Dwell time averages two to six weeks from initial access to encryption, with particular focus on organizations running VMware infrastructure (Lakshmanan, 2026a; Lakshmanan, 2026b).

Blue Team Perspective: Honeypots and IDS as an Early Detection Layer

Against an adversary that intensively abuses legitimate tools, modifies its toolkit mid-campaign, and now provides affiliates with a centralized, rapidly-updating EDR-killing suite, defenses based exclusively on signatures and blocklists are insufficient. The detection of The Gentlemen requires a defense-in-depth approach in which honeypots and intrusion detection systems (IDS/NIDS/HIDS) play a strategic role.

Honeypots: Deception as Detection

Given that the group invests considerable time in the discovery phase — enumerating Active Directory, scanning internal ranges with Nmap and Advanced IP Scanner, and hunting for high-privilege accounts — an environment well-instrumented with decoys can become the first early-warning system:

The strength of deception is that it produces no false positives: no legitimate process should interact with a decoy resource.

IDS/IPS and Behavior-Based Detection

A well-tuned IDS — Suricata, Snort, Zeek, or a commercial NDR — can detect multiple phases of a Gentlemen attack with appropriate rules and analytics:

The combination of honeypots + IDS + SIEM + EDR + UEBA following MITRE D3FEND and mapping defenses against applicable ATT&CK TTPs (T1190, T1078, T1059.001, T1562, T1484.001, T1021.002, T1486) allows Blue Teams to reduce dwell times from hours to minutes.

Analysis: What This Threat Reveals About the Current State of Ransomware

The visibility problem. The most alarming finding from Check Point’s research is not the number of victims itself, but the proportion between what the group publishes on its DLS and what it actually compromises. A significant fraction of victims pay without the incident ever coming to light — inflating the group’s profits without increasing regulatory pressure or threat intelligence attention. This model subverts the industry’s threat-sharing mechanisms.

Centralized tooling as a competitive moat. The GentleKiller revelation marks a qualitative shift in how ransomware ecosystems are structured. By centralizing EDR-killing capabilities and distributing them to affiliates as a managed service — rather than leaving affiliates to source their own tools — The Gentlemen has created an operational model closer to a mature software product company than a criminal gang. The ability to update all eight GentleKiller variants within days of a new BYOVD PoC disclosure, and the standardized impersonation layer that makes attribution across incidents actively misleading, represents a level of professional engineering discipline previously unseen in ransomware operations. This is compounded by the cross-gang tool-sharing dynamic: the criminal tooling market has matured to the point where EDR killer components circulate between gangs the way security modules are licensed between legitimate vendors.

AI as a criminal accelerant. LARVA-368’s documented use of AI for ransomware development, tool maintenance, and post-exploitation assistance represents a qualitative evolution. If AI reduces the cost and development time of offensive tooling, the barrier to entry falls and the speed of counter-response to defensive countermeasures — as demonstrated by the same-day patch in response to the public decryptor — accelerates considerably.

OT infrastructure is now a realistic target. The Mackay Sugar incident confirms what threat intelligence teams had been warning about: The Gentlemen’s worm-like propagation, combined with its speed and BYOVD-driven ability to silence security software, makes it capable of forcing physical-world shutdowns without touching a single industrial control system directly. This implies that OT environments are not safe simply because their PLCs and SCADA systems are air-gapped from the IT network — the historian databases, MES, and logistical platforms that feed operational decisions are legitimate targets, and their loss paralyzes physical operations just as effectively.

The particular risk for Latin America. The group’s confirmed presence in Mexico, Colombia, Argentina, Brazil, and other countries in the region is not accidental. Latin American organizations present high adoption of FortiGate and VPNs as documented attack vectors, lower average patch management maturity, smaller SOC teams with limited overnight response capacity, and a deficient incident-reporting culture. The prohibition on CIS countries also redirects operational capacity toward markets like Latin America, where perceived impunity is higher.

A signal about the evolution of the criminal ecosystem. The Gentlemen represents something the threat intelligence community has been warning about for years: the professionalization of ransomware has reached a level where criminal groups apply software engineering discipline, operational intelligence, business strategy, and generative AI. Faced with adversaries at this level of sophistication, a reactive defensive posture is not viable. The only acceptable approach is proactive detection, continuous threat hunting, and systematic attack surface reduction.


References

Ali Bravo, C. (2026, March 26). The Gentlemen: la nueva generación de ransomware que ataca a medida. WeLiveSecurity (ESET). https://www.welivesecurity.com/es/ransomware/the-gentlemen-la-nueva-generacion-de-ransomware-que-ataca-a-medida/

Cybersecurity Insiders. (2026, June 25). The Gentlemen Ransomware Group: Who Runs the #2 Active Gang | Krebs Investigation. https://www.cybersecurity-insiders.com/the-gentlemen-ransomware-group-krebs-investigation-administrator/

Cybersecurity Insiders. (2026b, June 21). Gentlemen Ransomware Builds Modular EDR Killer Suite From Rival Gang Tools. https://www.cybersecurity-insiders.com/gentlemen-ransomware-edr-killer-suite/

CyberPress. (2026, June 19). Gentlemen EDR Killer Suite Combines HexKiller, ThrottleBlood, and HavocKiller. https://cyberpress.org/gentlemen-edr-killer-suite/

CyberSecurityNews. (2026, June 20). GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes. https://cybersecuritynews.com/gentlekiller-ransomware-edr-processes/

Fortinet. (2026, April 24). The Gentlemen Ransomware — Threat Actor Profile. FortiGuard Labs. https://www.fortiguard.com/threat-actor/6387/the-gentlemen-ransomware

Lakshmanan, R. (2026a, April 21). SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation. The Hacker News. https://thehackernews.com/2026/04/systembc-c2-server-reveals-1570-victims.html

Lakshmanan, R. (2026b, June 11). The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm. The Hacker News. https://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html

Lakshmanan, R. (2026c, June 19). The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes. The Hacker News. https://thehackernews.com/2026/06/the-gentlemen-raas-uses-gentlekiller.html

Microsoft. (2026, May 28). The Gentlemen ransomware: Dissecting a self-propagating Go encryptor. Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/

Mikhalov, R. (2025, November 21). License to Encrypt: When “The Gentlemen” Go on the Offensive. SOC Prime. https://socprime.com/es/active-threats/caballeros-pasan-a-la-ofensiva/

PI Solutions. (2026, May). The Gentlemen Ransomware: Threat Actor Profile. Privacy Insight Solutions. https://privacyinsightsolutions.com/blog/the-gentlemen-ransomware-threat-profile

PRODAFT. (2026, June). Inside the Phantom Mantis Operation. PRODAFT Catalyst. https://catalyst.prodaft.com/public/report/inside-the-phantom-mantis-operation/overview

Rescana. (2026, June 17). Ransomware Attack on Mackay Sugar Disrupts Australian Mills. https://www.rescana.com/post/ransomware-attack-on-mackay-sugar-disrupts-australian-mills-cybersecurity-incident-analysis-and-lessons-learned

Security Affairs. (2026b, June 22). Inside GentleKiller: The EDR-Killer Powering The Gentlemen. https://securityaffairs.com/193941/malware/inside-gentlekiller-the-edr-killer-powering-the-gentlemen.html

Shieldworkz. (2026, June). Threat Intelligence Briefing: The Gentlemen Ransomware. https://shieldworkz.com/blogs/threat-intelligence-briefing-the-gentlemen-ransomware

SOCRadar. (2026, February 12). Dark Web Profile: The Gentlemen Ransomware. SOCRadar Cyber Threat Intelligence. https://socradar.io/blog/dark-web-profile-the-gentlemen-ransomware/

Souček, J. (2026, June 18). Killing me gently: Inside Gentlemen’s EDR killer framework. WeLiveSecurity (ESET). https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/

The Register. (2026, June 17). Cyberattack sees crops kept in the ground. https://www.theregister.com/cyber-crime/2026/06/17/cyberattack-sees-crops-kept-in-the-ground/5256321