Gentlemen Ransomware Targets Windows, Linux, NAS, BSD, and ESXi Systems
Key Takeaways The Gentlemen ransomware group has rapidly emerged as a significant threat, becoming one of the top two most active ransomware operations globally by early 2026. This sophisticated...
Key Takeaways
- The Gentlemen ransomware group has rapidly emerged as a significant threat, becoming one of the top two most active ransomware operations globally by early 2026.
- This sophisticated ransomware is highly versatile, capable of targeting a broad spectrum of enterprise systems, including Windows, Linux, NAS, BSD, and VMware ESXi environments.
- The group employs a double extortion strategy, encrypting files and exfiltrating sensitive data to pressure victims, and operates with a structured affiliate model linked to the Qilin ecosystem.
- Defenders should prioritize securing internet-facing infrastructure, enforcing multi-factor authentication, and actively hunting for early-stage attack indicators.
The Gentlemen, a ransomware collective, has rapidly escalated its operations to become one of the most aggressive and pervasive cybercriminal threats observed in recent years. This group has demonstrated remarkable adaptability, deploying ransomware across a diverse range of operating systems, including Windows, Linux, network-attached storage (NAS) devices, BSD, and VMware ESXi systems. A detailed analysis of their tactics, techniques, and procedures (TTPs) has been compiled by researchers, highlighting the extensive nature of their attack capabilities.
Table Of Content
Emerging publicly in the latter half of 2025, The Gentlemen quickly scaled its activities, establishing itself among the two most prolific ransomware groups worldwide by early 2026. This rapid growth is attributed not only to the speed of their operations but also to the wide array of systems they compromise and the sophisticated organizational structure supporting their campaigns.
Operational Modus Operandi
The group executes its attacks through a meticulously organized workflow. Initial access is typically gained via compromised credentials or exploiting vulnerabilities in exposed remote services. Once inside a network, the ransomware is deployed to encrypt critical systems. In addition to file encryption, The Gentlemen employs a double extortion tactic, exfiltrating sensitive data prior to encryption. This stolen information serves as additional leverage, increasing pressure on victims to comply with ransom demands.
Analysts at LevelBlue indicated in a report shared with Cyber Security News (CSN) that The Gentlemen is not an entirely new entity. Instead, it appears to be a continuation of prior ransomware affiliate activities associated with the Qilin ecosystem. This lineage suggests the group is managed by a Russian-speaking actor known as “hastalamuerte.” This background provides The Gentlemen with a significant operational advantage, leveraging existing knowledge, established affiliate networks, and seasoned experience in orchestrating ransomware campaigns.

The Gentlemen Ransomware
By May 10, 2026, The Gentlemen had publicly claimed responsibility for 352 attacks within the first half of the year alone. Data from their leak site reveals victims across more than 70 countries, with significant representation from the APAC region, Europe, Latin America, and North America. The most frequently targeted sectors include professional services, manufacturing, technology, and healthcare.
Dark web intelligence has also unearthed an unverified lead concerning an individual offering data purportedly stolen from The Gentlemen’s internal systems for $10,000 in Bitcoin. This alleged cache included actor handles, victim negotiation logs, and file mapping data. While the authenticity of this information remains unconfirmed, it adds a layer of intrigue to an already complex operation.
The Gentlemen ransomware is specifically engineered for multi-platform attacks. The Windows variant, developed in the Go programming language, necessitates a password for execution, a mechanism designed to evade early detection and sandbox analysis. Encrypted files are appended with random six-character extensions, and victims find a ransom note titled “READMEGENTLEMEN.txt” on affected systems.

The encryption strategy is optimized for rapid and widespread damage. Smaller files undergo full encryption, while larger files are partially encrypted in chunks. This method allows the ransomware to propagate quickly across extensive environments, rendering recovery extremely challenging without the decryption key. Before initiating file encryption, the malware systematically terminates services related to databases, backups, virtualization platforms, and remote access tools, preempting straightforward restoration efforts.
Attacks targeting ESXi and other virtualization infrastructure are particularly devastating, capable of disrupting entire server estates within minutes. The group’s affiliate panel facilitates this operational model, enabling operators to generate custom payloads, manage victim negotiations, estimate potential ransom revenue, and handle the upload of stolen data from a unified backend platform.
What You Should Do
Organizations must adopt a proactive and multi-layered defense strategy to mitigate the threat posed by The Gentlemen ransomware and similar sophisticated operations.
- Secure Internet-Facing Assets: Conduct thorough audits of all internet-facing infrastructure, including VPNs, firewalls, and remote access portals. Ensure all systems are patched, securely configured, and adhere to a principle of least privilege.
- Strengthen Authentication: Implement and enforce multi-factor authentication (MFA) for all user accounts, especially privileged ones. Immediately rotate credentials that may have been exposed in previous breaches or stolen by info-stealing malware, and disable all stale or unused accounts.
- Proactive Threat Hunting: Focus on detecting early-stage attack behaviors rather than waiting for ransomware deployment. Monitor for suspicious administrative logins, the presence of unauthorized scanning tools (e.g., Nmap, Advanced IP Scanner), unexpected usage of remote access tools like AnyDesk or WinSCP, and any modifications to Group Policy or mass service shutdowns.
- Isolate and Test Backups: Ensure backup systems and ESXi environments are logically isolated from the main production network. Regularly test backup restoration capabilities to confirm data integrity and recovery readiness.
- Employee Training: Educate employees about phishing, social engineering, and the importance of strong password hygiene to prevent initial access vectors.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP Address | 91.107.247.163 | SystemBC C2 Server |
| IP Address | 45.86.230.112 | SystemBC C2 Server |
| SHA256 | 992c951f4af57ca7cd8396f5ed69c2199fd6fd4ae5e93726da3e198e78bec0a5 | The Gentlemen Windows ransomware |
| SHA256 | 025fc0976c548fb5a880c83ea3eb21a5f23c5d53c4e51e862bb893c11adf712a | The Gentlemen Windows ransomware |
| SHA256 | 22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67 | The Gentlemen Windows ransomware |
| SHA256 | 2ed9494e9b7b68415b4eb151c922c82c0191294d0aa443dd2cb5133e6bfe3d5d | The Gentlemen Windows ransomware |
| SHA256 | 3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235 | The Gentlemen Windows ransomware |
| SHA256 | 48d9b2ce4fcd6854a3164ce395d7140014e0b58b77680623f3e4ca22d3a6e7fd | The Gentlemen Windows ransomware |
| SHA256 | 62c2c24937d67fdeb43f2c9690ab10e8bb90713af46945048db9a94a465ffcb8 | The Gentlemen Windows ransomware |
| SHA256 | 860a6177b055a2f5aa61470d17ec3c69da24f1cdf0a782237055cba431158923 | The Gentlemen Windows ransomware |
| SHA256 | 87d25d0e5880b3b5cd30106853cbfc6ef1ad38966b30d9bd5b99df46098e546c | The Gentlemen Windows ransomware |
| SHA256 | 8c87134c1b45e990e9568f0a3899b0076f94be16d3c40fa824ac1e6c6ee892db | The Gentlemen Windows ransomware |
| SHA256 | 91415e0b9fe4e7cbe43ec0558a7adf89423de30d22b00b985c2e4b97e75076b1 | The Gentlemen Windows ransomware |
| SHA256 | 994d6d1edb57f945f4284cc0163ec998861c7496d85f6d45c08657c9727186e3 | The Gentlemen Windows ransomware |
| SHA256 | 9f61ff4deb8afced8b1ecdc8787a134c63bde632b18293fbfc94a91749e3e454 | The Gentlemen Windows ransomware |
| SHA256 | a7a19cab7aab606f833fa8225bc94ec9570a6666660b02cc41a63fe39ea8b0ad | The Gentlemen Windows ransomware |
| SHA256 | b67958afc982cafbe1c3f114b444d7f4c91a88a3e7a86f89ab8795ac2110d1e6 | The Gentlemen Windows ransomware |
| SHA256 | c46b5a18ab3fb5fd1c5c8288a41c75bf0170c10b5e829af89370a12c86dd10f8 | The Gentlemen Windows ransomware |
| SHA256 | c7f7b5a6e7d93221344e6368c7ab4abf93e162f7567e1a7bcb8786cb8a183a73 | The Gentlemen Windows ransomware |
| SHA256 | ec368ae0b4369b6ef0da244774995c819c63cffb7fd2132379963b9c1640ccd2 | The Gentlemen Windows ransomware |
| SHA256 | efaf8e7422ffd09c7f03f1a5b4e5c2cc32b05334c18d1ccb9673667f8f43108f | The Gentlemen Windows ransomware |
| SHA256 | f736be55193c77af346dbe905e25f6a1dee3ec1aedca8989ad2088e4f6576b12 | The Gentlemen Windows ransomware |
| SHA256 | fc75ed2159e0c8274076e46a37671cfb8d677af9f586224da1713df89490a958 | The Gentlemen Windows ransomware |
| File Name | gentlemen.bmp | Ransomware wallpaper/artifact |
| SHA256 | fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68 | The Gentlemen Linux ransomware |
| SHA256 | 5dc607c8990841139768884b1b43e1403496d5a458788a1937be139594f01dca | Initial KillAV tool |
| SHA256 | 7a311b584497e8133cd85950fec6132904dd5b02388a9feed3f5e057fb891d09 | PowerRun utility |
| SHA256 | 4c82fbafef9bab484a2fbe23e4ec8aac06e8e296d6c9e496f4a589f97fd4ab71 | Additional tool |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.