Written by: DarkWebSonar Research Team

The Gentlemen is one of the highest-velocity ransomware operators DarkWebSonar tracks. Leak-site telemetry puts the group almost level with Qilin on 90-day posting volume (340 vs 355), with 610 victim listings across 75 countries and a manufacturing concentration that matches the industrial hit list we already flag for Qilin. Of those 610 listings, 125 landed in the last 30 days, and DarkWebSonar classifies activity as Spiked.
Where most ransomware datasets skew toward large US enterprises, The Gentlemen's August 2026 batches mix marquee brand claims with small manufacturers, construction subcontractors, lottery infrastructure, and a physical-security integrator. That mix is the story: RaaS-scale output aimed at mid-market and supply-chain targets that often sit outside enterprise SOC coverage.

Key findings from DarkWebSonar telemetry (through 2026-08-28):
- 610 ransomware victim listings observed.
- 340 listings in the last 90 days; 125 in the last 30 days (activity classification: Spiked).
- United States accounts for 155 listings (25%); France (28), Italy (25), India (25), and Germany (24) lead the long global tail.
- Top industry: Manufacturing & Construction at 171 listings (28%), ahead of Healthcare & Pharma (57) and Technology & Telecom (49).
- Largest single day: 60 listings on 2026-04-07 (2026-W15); August batches include 23 on Aug 6, 14 on Aug 14, 19 on Aug 21, and 16 on Aug 28.
Public reporting describes The Gentlemen as a Ransomware-as-a-Service operation (Microsoft tracks the operator as Storm-2697) that matured from a prior Qilin-affiliate persona (ArmCorp) into its own brand around September 2025, with affiliate economics and cross-platform encryptors that favor rapid affiliate onboarding. Open-source analysis places operators in a Russian-speaking cybercrime ecosystem (medium confidence), including reporting that ties administration to handles such as hastalamuerte / zeta88; that attribution is analytic correlation from forum posts and operational leaks, not a law-enforcement finding. DarkWebSonar's earliest sparse attributions date to 2022, but sustained leak-site volume aligns with that 2025 RaaS launch window.
By the Numbers (DarkWebSonar Telemetry)
DarkWebSonar monitors The Gentlemen's Tor-based data leak site continuously. The 610 victim listings below reflect what the group chooses to publish; posting volume is a useful proxy for extortion activity and affiliate output, though it undercounts victims who pay quietly or are never listed on the site.
- Total victim listings: 610 across 75 countries; the United States represents 25% of named targets
- Recent momentum: 125 of 610 listings landed in the last 30 days; 340 in the last 90 days
- DarkWebSonar risk score: 97 / 100 (High)
- Activity classification: Spiked, meaning recent 30-day posting volume significantly exceeds the group's established baseline cadence
- Primary network: dark web (Tor) leak site, 100% of listings
- Attack-type mix: Ransomware 610 (100%)
Reading the trend line
The weekly bar chart tells a story that most vendor coverage compresses into "scaled in early 2026." DarkWebSonar's ISO-week aggregation pinpoints where, when, and how the shift happened.

Two separate onsets, not one. A first visible bump appears at 2025-W37 (6 listings, mid-September 2025), aligning with when Kaspersky/Securelist dates the group's emergence and its Go-based encryptor debut. Volume then settles back to low single digits through early 2026. The second inflection is 2026-W15 (week of April 6), which jumps to 72 listings from a baseline that had not exceeded 6 in any prior week. In DarkWebSonar's daily timeline that spike is effectively one event: roughly 60 victims published on April 7, 2026. Vendors say "scaled in early 2026"; our data pins the debut (September 2025) and the scale-up (April 2026) as two distinct inflections.
The spike is a publication artifact. 60 listings in a day does not mean 60 same-day intrusions. Leak-site counts track when victims are named, not when they were breached. A one-day burst signals batch publishing: accumulated victims dumped at once, a mass edge-device harvest cleared out in a single publication round, or both. That framing matters for defenders reading the chart: the underlying compromise cadence is likely smoother than the publication spikes suggest.

The inflection aligns with documented behavior changes. Public reporting in the weeks before and after 2026-W15 describes two capacity shifts. First, a move to systematic FortiGate and Cisco edge-device exploitation with worm-like network propagation, which is exactly the kind of access pipeline that produces batch victim dumps. Second, an affiliate influx from the group's Qilin-spinoff roots, bringing experienced operators with existing tooling. More affiliates plus edge-device automation equals a capacity step-change, which is what the chart shows. Sequencing note: an affiliate leak exposing internal details landed around March 19, 2026; volume detonated roughly three weeks later.
The real story is the plateau, not the spike. After 2026-W15 the chart does not decay. Volume holds at 16–38 listings per week for 20 consecutive weeks through 2026-W35 (458 listings, averaging roughly 23 per week). Most single-event spikes fade; this one institutionalized into a sustained operating tempo, the signature of a maturing RaaS with steady affiliate throughput rather than a lone operator's one-off campaign.
The plateau pulses in waves. Within that sustained band, volume oscillates in a rough biweekly rhythm: peaks of 36–38 alternate with troughs of 5–20, matching August's batch cadence of 23, 14, 19, and 16 on successive drop days. For a defender watching the chart, a quiet week is the trough of a dump cycle, not evidence of a decline.
Targeting distribution
The Gentlemen's victim geography is US-led but globally distributed:

A one-in-four US share is high in absolute terms but materially lower than the ~50% US concentration we document for Qilin. Europe and Asia together form a thick second tier, which means regional SOCs outside North America still see relevant listings week to week.
Industry targeting concentrates on manufacturing and adjacent supply chains:

The manufacturing share matches the industrial bias we already highlight for Qilin. Combined with recent named victims that are small subcontractors and mid-market plants rather than only Fortune-scale brands, we assess The Gentlemen's affiliate book is optimized for organizations with limited security headcount and high operational uptime pressure.
Tactics, Techniques & Procedures (TTPs)
DarkWebSonar's visibility into The Gentlemen begins and ends at the leak site, not inside victim networks. The ATT&CK techniques below come from two places: techniques DarkWebSonar infers from how a listing is classified (a ransomware listing implies encryption and recovery inhibition), and techniques documented in public reporting on the group's tooling. Neither is derived from forensic evidence in a victim environment, and nothing below should be read as DarkWebSonar observing exploitation directly.
Extortion strategy
The Gentlemen operates a ransomware-centric double-extortion model. T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery) and T1027 (Obfuscated Files or Information) are inherent to that model and are therefore inferred across the entire ransomware classification, not confirmed listing by listing.
Beyond encryption, DarkWebSonar incident tagging associates a meaningful minority of listings with internal defacement and data-manipulation techniques (T1491.001, 107 listings; T1565.003, 103; T1565.001, 45) and financial-theft framing (T1657, 29). Collection and exfiltration techniques appear on a smaller subset (T1005 and T1041, 15 each; T1537, 10; T1567.002, 8), consistent with steal-then-encrypt tradecraft.
Initial access and privilege escalation
DarkWebSonar tags a small number of listings to exploitation of public-facing applications (T1190, 8 listings) and spearphishing links (T1566.002, 7 listings). Public analysis of the group's leaked internal chats describes a broader access mix: exposed edge appliances with a particular focus on Fortinet FortiGate and Cisco, NTLM relay paths, credential logs for OWA and Microsoft 365, brute force against web and VPN panels, and access purchased from third-party brokers. The same analysis documents technique-driven escalation paths without fixed CVE identifiers, including Veeam backup infrastructure abuse, Dell iDRAC weaknesses, and registry-based MSI service abuse, alongside heavy investment in EDR evasion and ETW tampering.

Source: Microsoft.com
DarkWebSonar's profile associates the actor with CVE-2025-7771. Per NVD and Unit 42 recommendations, that CVE is a local privilege-escalation issue in the TechPowerUp ThrottleStop.sys driver (bring-your-own-vulnerable-driver), not a confirmed remote initial-access vector. Treat it as post-compromise EDR impairment and kernel escalation risk when scoping detections.
Encryptor and propagation (open-source reporting)
Microsoft Threat Intelligence documents a Go-based locker obfuscated with Garble, using per-file ephemeral Curve25519 / XChaCha20 cryptography, an optional --spread self-propagation mode that moves laterally to reachable hosts, and a --wipe mode that fills free disk space after encryption to frustrate recovery. Microsoft's analysis covers the Windows encryptor; Check Point's indicator set for the group includes Linux samples alongside the Windows builds, and affiliate chats reference locking ESXi environments. None of those encryptor behaviors are observable from DarkWebSonar leak-site metadata.
Business model (open-source reporting)
Public reporting characterizes The Gentlemen as a RaaS advertising a 90/10 split in the affiliate's favor, recruited via underground forums, with custom tooling for defense evasion including EDR-killer frameworks. Check Point's analysis of the group's leaked internal data documents eight distinct affiliate TOX identities around an administrator operating as zeta88 / hastalamuerte, a core of roughly nine coordinating accounts, and a May 2026 compromise of an internal backend database the group calls Rocket, which exposed affiliate workflows without producing a public law-enforcement takedown. That analysis also indicates the administrator personally conducts intrusions rather than only running the platform. Worm-like lateral propagation and affiliate playbooks should be attributed to those external analyses rather than to DarkWebSonar telemetry.
Evolution & Trends
The Gentlemen's operational timeline in DarkWebSonar telemetry aligns with open-source reporting on a fast RaaS maturation:
- 2022–mid-2025: Sparse DarkWebSonar attributions; not yet the high-volume brand of 2026.
- July–September 2025: Public reporting places operators as a former Qilin affiliate (ArmCorp) transitioning to an independent RaaS brand; DarkWebSonar volume begins climbing in September 2025.
- April 2026: Single-day peak of 60 listings (2026-W15), marking the shift to sustained high-tempo batch publication.
- May 2026: On May 4 the administrator publicly acknowledged the leak of the group's internal Rocket backend database, exposing affiliate tooling, chats and workflows; leak-site posting tempo continued afterward rather than collapsing.
- May–August 2026: Multi-week runs of 20–38 listings; August alone includes repeated double-digit drop days through Aug 28.
We assess the 2026 acceleration reflects successful affiliate recruitment and batch leak-site operations rather than a one-off campaign. The manufacturing-heavy victim mix and mid-market named targets are consistent with opportunistic affiliate hunting across exposed edge infrastructure and underserved SMBs, not a narrow sector campaign. Continuity after the May 2026 operational leak supports that assessment: the affiliate machine kept publishing victims at scale.
Notable Campaigns / Victims

Source: The Gentlemens' Data Leak Site
Recent listings observed in DarkWebSonar telemetry (August 2026). All are alleged claims published on the group's leak site:
- Glassdoor (job-review platform; Recruit Holdings; posting dated August 28, 2026). The group claims access touching large volumes of employee reviews and salary data. This is a marquee name; treat as an unverified claim until the company or independent reporting corroborates impact.
- Ixa Systems (Switzerland, Professional Services; August 28, 2026). A surveillance and access-control integrator serving police, banks, museums, and prisons. A physical-security vendor appearing on a ransomware leak site is a sharp supply-chain signal for those client sectors.
- Tecno Acción (Argentina, Professional Services; August 28, 2026). Lottery-technology provider operating thousands of terminals across multiple jurisdictions.
- G R Infraprojects (India, Manufacturing & Construction; August 28, 2026). Infrastructure EPC firm; the leak-site claim cites roughly 531 GB of alleged exfiltration spanning NDAs, HR, drawings, and financial records.
- Probe Test System / Semiprobe (US, Manufacturing & Construction; August 28, 2026). Semiconductor test/probe supplier; supply-chain angle for chipmakers.
- Brebur (UK, Manufacturing & Construction; August 28, 2026). Small steel-frame and dry-lining subcontractor to major builders (including BAM, Kier, and Willmott Dixon), illustrating construction supply-chain targeting.
- Thai Film Industries PCL (Thailand, Manufacturing & Construction; August 28, 2026). Publicly traded BOPP film manufacturer.
- General Gruppo (Italy; August 28, 2026). Retail group operating hundreds of beauty and personal-care stores.
- Nutrypollo (Mexico, Agriculture & Farming; August 28, 2026). Vertically integrated poultry producer.
- Adkisson Group (US, Real Estate & Housing; August 28, 2026). Houston industrial real estate developer.
- Northwest Trophy (US; August 28, 2026). Small family-owned awards business, reinforcing the SMB end of the hit list.
- ESB Puerto Rico (Puerto Rico; August 28, 2026). Automotive/industrial distributor and federal contractor claim.
DarkWebSonar Insights
- Qilin adjacency on volume, not just branding. Ninety-day leak-site counts put The Gentlemen within roughly 4% of Qilin (340 vs 355). Teams that only monitor "top five legacy RaaS" lists miss a peer-scale operator whose manufacturing share (28%) mirrors that industrial bias.
- Year-week cadence tracking separates true quiet periods from batch-drop weeks. August's 14–23 listing days would look like noise in a monthly rollup; ISO-week views show a sustained Spiked operator.
- Victim-size mix is visible in named targets (subcontractors, mid-market manufacturers, lottery and security integrators) rather than enterprise-only hunting. That distribution changes who needs early warning: Tier-1 suppliers and OT-adjacent firms, not only household brands.
- CVE association discipline matters for detection engineering. DarkWebSonar tags CVE-2025-7771 on the profile, but NVD and Unit 42 place it in privilege escalation and BYOVD, so patch and detection priorities should still lead with edge initial-access issues such as CVE-2024-55591. Equally, the CVEs visible in the group's leaked chats show what operators are evaluating, not what they have proven to exploit. We assess the more reliable planning signal is the technique-level pattern (edge appliances, NTLM relay, backup and management-controller abuse), which persists as individual CVEs come and go.
Defender Outlook 2026
Persistent risk: Organizations in Manufacturing & Construction, Healthcare & Pharma, Technology & Telecom, Professional Services, Financial Services, Education, and Transportation should treat The Gentlemen as an active RaaS threat. The 25% US share does not diminish risk elsewhere: Western Europe, South Asia, Southeast Asia, and Latin America all show recurring listings.
Tempo: Output arrives in ISO-week batches (2026-W15, W25, W28, W30–W32, W34–W35) with 125 listings in the last 30 days. Detection and response readiness matter more than calendar-based monitoring windows; new affiliates can produce additional burst weeks with minimal warning. Open-source reporting of worm-like --spread propagation raises the cost of delayed containment once an affiliate is inside the network.
Defensive actions:
- Patch and inventory internet-facing edge appliances (VPN, firewall management planes, hypervisor and Aria management planes) cited in Gentlemen access reporting; prioritize Fortinet and related CVE backlogs including CVE-2024-55591.
- Enforce phishing-resistant MFA on remote access; assume credential and IAB paths alongside exploit-driven entry. Credential logs for OWA and Microsoft 365 are a documented access source for this group.
- Close NTLM relay paths and enforce SMB and LDAP signing. Operators are documented scanning for CVE-2025-33073 as routine reconnaissance, and relay workflows are a standing part of their playbook.
- Review Veeam backup infrastructure and Dell iDRAC management controllers for the misconfiguration-to-domain-admin paths the group's affiliates discuss; these carry no CVE to patch against.
- Hunt for BYOVD and vulnerable-driver load patterns associated with CVE-2025-7771 (ThrottleStop.sys and renamed variants) as a privilege-escalation and EDR-impairment signal.
- Detect rapid multi-host encryption and lateral-deployment patterns consistent with the self-propagating Go locker described in Microsoft's analysis; isolate early and constrain SMB/RDP/WMI paths during response.
- Validate backup isolation and test restoration from air-gapped or immutable copies; recovery inhibition (T1490) is inherent to this ransomware model, and the encryptor's documented free-space wipe further reduces recovery options on affected volumes.
- Monitor large outbound transfers and cloud-exfil patterns (T1041, T1537) as early double-extortion indicators.
- Establish early warning for your organization and key suppliers on leak sites so a Gentlemen listing surfaces before public disclosure; DarkWebSonar provides this coverage.
No public law enforcement takedown targeting The Gentlemen has been identified as of August 2026; the May 2026 internal chat and backend leak was an operational-security event, not a seizure. The group remains operationally active on its Tor leak site.
Threat Intelligence Indicators
DarkWebSonar CVE associations in The Gentlemen's profile:
- CVE-2025-7771 (ThrottleStop.sys BYOVD; privilege escalation / kernel code execution per NVD)
CVEs the group is documented tracking and evaluating in its leaked internal chats (not present as DarkWebSonar profile associations). Note the analysts who reviewed those chats state they could not confirm whether the targeted systems were actually vulnerable to these issues, so treat them as the group's working exploit interest rather than confirmed entry vectors:
- CVE-2024-55591 (Fortinet FortiOS management interface authentication bypass). Appears alongside the group's FortiGate targeting; the chats show no detailed exploitation steps.
- CVE-2025-32433 (Erlang/OTP SSH, discussed in a Cisco context). Affiliates shared and assessed a proof-of-concept, indicating active evaluation rather than confirmed use.
- CVE-2025-33073 (Windows SMB client NTLM reflection / relay). The strongest of the three: operators scan for it as part of a standard NTLM relay reconnaissance workflow.
Operational indicators from leak-site monitoring: Tor leak-site publication in multi-victim same-day batches; 100% ransomware categorization; manufacturing-heavy industry metadata; concurrent US and multi-region victim names in single drop days.
Conclusion
The Gentlemen has scaled into a peer of the highest-volume ransomware operators DarkWebSonar tracks, with 610 victim listings, 75 countries, and a 28% manufacturing concentration similar to Qilin. The practical differentiator for defenders is not another encyclopedia entry on RaaS economics. It is the victimology: mid-market manufacturers, construction suppliers, healthcare, and niche critical providers appearing in large August batches while 90-day volume sits within a few percent of the category leader.
For CTI and SOC teams, the exposure pattern is addressable: unpatched edge appliances, weak remote-access MFA, untested backups, slow containment against self-propagating encryptors, and no leak-site early warning for the organization or its suppliers. Closing those gaps is the highest-value control stack against this group.
Data notes: Statistics in this profile are derived from DarkWebSonar telemetry on The Gentlemen's Tor leak site unless attributed to open-source reporting. Posting dates may lag compromise; batch publication can inflate single-week counts. Country and industry fields reflect leak-site metadata.
👉 Dark Web Most Wanted profiles are powered by DarkWebSonar's continuous monitoring of ransomware leak sites. Want real-time visibility into groups like The Gentlemen? Contact Sales.