Back to Ransomware Database
Ransomware Group
thegentlemen
The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
Known victims867
Threat Level
CRITICAL
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- DumpBrowserSecrets
- Hydra
- KslDump
- KslKatz
- XenAllPasswordPro
DefenseEvasion
- EDRStartupHinder
- GFreeze
- GLinker
DiscoveryEnum
- ADFind
- BloodHound
- Censys
- CertiHound
- MANSPIDER
- +4 more
Exfiltration
- rclone
Networking
- Chisel-ng
- ProxyChains
- Tor / Onion C2
- openconnect
Offsec
- Custom Go Locker (Windows/Linux/NAS)
- NetExec (nxc)
- PetitPotam
- PrivHound
- RegPwn
- +6 more
RMM-Tools
- AnyDesk
Check If You’re Affected
Search our database to see if your organization appears in thegentlemen’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request