Skip to main content
Back to Ransomware Database
Ransomware Group

thegentlemen

The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.

Known victims867

Threat Level

CRITICAL

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • DumpBrowserSecrets
  • Hydra
  • KslDump
  • KslKatz
  • XenAllPasswordPro

DefenseEvasion

  • EDRStartupHinder
  • GFreeze
  • GLinker

DiscoveryEnum

  • ADFind
  • BloodHound
  • Censys
  • CertiHound
  • MANSPIDER
  • +4 more

Exfiltration

  • rclone

Networking

  • Chisel-ng
  • ProxyChains
  • Tor / Onion C2
  • openconnect

Offsec

  • Custom Go Locker (Windows/Linux/NAS)
  • NetExec (nxc)
  • PetitPotam
  • PrivHound
  • RegPwn
  • +6 more

RMM-Tools

  • AnyDesk
0

Check If You’re Affected

Search our database to see if your organization appears in thegentlemen’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request