Actor Profile

The Gentlemen is a ransomware-as-a-service (RaaS) operation that has rapidly ascended to become the second most active ransomware group by victim count. The group operates through an affiliate recruitment model, offering an exceptionally high 90% ransom split to attract partners—significantly above typical RaaS commission structures. This aggressive revenue-sharing approach has enabled rapid scaling of operations. The group's administrator identity is under investigation based on operational security failures and digital breadcrumbs, though attribution remains incomplete. The Gentlemen represents both a threat actor organization and the associated ransomware malware family they deploy.

TTPs (Tactics, Techniques, Procedures)

The Gentlemen employs a ransomware-as-a-service model, leveraging affiliate networks to conduct extortion operations. Key TTPs likely include initial access through affiliate partners (T1078 - Valid Accounts, T1133 - External Remote Services), data exfiltration for double-extortion tactics (T1048 - Exfiltration Over Alternative Protocol), and deployment of ransomware payloads (T1486 - Data Encrypted for Impact). The high affiliate commission structure (90% split) indicates a focus on recruitment and scaling through third-party operators (T1583 - Acquire Infrastructure, T1587 - Develop Capabilities). OPSEC failures by the administrator have created investigative leads, suggesting potential attribution vectors through digital forensics and open-source intelligence gathering.

Targets & Patterns

Specific targeted sectors and geographic focus are not documented in available reporting. The group's rapid rise to second place by victim count suggests an opportunistic, volume-based targeting strategy rather than sector-specific focus. The affiliate model enables diverse targeting as independent affiliates select their own victims based on access opportunities. The 90% revenue split incentivizes affiliates to pursue high-value targets while the core group maintains infrastructure and leak site operations. This decentralized targeting approach maximizes attack surface and victim diversity across multiple industries and regions.

Historical Context

The Gentlemen represents a newer entrant to the ransomware ecosystem, distinguished by their exceptionally generous affiliate compensation model. The 90% ransom split significantly exceeds industry norms (typically 60-80%), suggesting either a strategy to rapidly gain market share from established groups or a focus on monetizing infrastructure and reputation rather than direct ransom revenue. The group's quick ascent to second place by victim count indicates successful execution of this affiliate recruitment strategy. Investigation into the administrator's identity suggests potential OPSEC compromises that may lead to attribution or law enforcement action, following patterns seen in previous ransomware takedowns where operational security failures enabled identification.

Defensive Recommendations

  • Monitor for indicators of double-extortion ransomware campaigns, including unusual outbound data transfers (T1048) and file encryption activity (T1486) across endpoints
  • Implement robust credential management and MFA to prevent initial access via compromised accounts (T1078) and external remote services (T1133)
  • Deploy network segmentation and least-privilege access controls to limit lateral movement and impact scope of affiliate-driven attacks
  • Maintain offline, immutable backups with regular restoration testing to enable recovery without ransom payment
  • Monitor dark web leak sites and threat intelligence feeds for early warning of data exfiltration, enabling rapid incident response before public disclosure