483
confirmed victims in 66 countries since mid-2025; 380 compromised in 2026 alone, making The Gentlemen the second most prolific ransomware brand of the year
48
security vendors targeted by the GentleKiller framework across 400+ processes, including CrowdStrike, SentinelOne, Microsoft Defender, Palo Alto, and Sophos
<24h
typical time from initial access to domain-wide file encryption: SystemBC and EtherRAT deploy in hours 0-2, GentleKiller disables EDR in hours 6-18, encryption completes before the 24-hour mark
90/10
affiliate revenue split offered by The Gentlemen RaaS, one of the most generous in the ransomware ecosystem, driving rapid recruitment of skilled operators from competing groups

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

The Gentlemen ransomware compromised 380 organizations in 2026 alone across 66 countries, deploying a BYOVD-based EDR killer that defeats 48 security vendors and a novel remote access trojan that resolves its command-and-control server address through Ethereum smart contracts, making the C2 infrastructure immune to traditional domain takedowns. The group is the second most prolific ransomware brand of 2026 by confirmed victim count, behind only Qilin, with 483 total victims since its founding in mid-2025.

The attack chain is fast and destructive. Initial access arrives through CVE-2024-55591, a critical authentication bypass in FortiOS and FortiProxy that grants super-admin access without credentials, or through stolen VPN credentials purchased from initial access brokers. Within two hours of access, the group deploys SystemBC, a SOCKS5 proxy malware providing encrypted C2 tunneling, and EtherRAT, which retrieves its C2 server address from a smart contract on the Ethereum blockchain. By hour 18, GentleKiller has disabled endpoint security across the entire domain using kernel-level BYOVD driver exploitation. Domain-wide encryption completes before the 24-hour mark.

The Gentlemen targets mid-to-large enterprises with 500 or more employees and complex Active Directory environments, with manufacturing as the primary sector. The group's 90/10 affiliate revenue split, the most generous in the ransomware ecosystem, has driven rapid recruitment of skilled operators from competing RaaS programs including Qilin.

Three immediate actions: block outbound connections to SystemBC C2 IPs 45.86.230.112 and 193.233.202.17; enable Windows Memory Integrity (HVCI) to prevent BYOVD driver loading; and audit your environment for the six persistence artifacts described in the IOC section below. The SonicWall SMA1000 zero-day covered September 2 is a parallel perimeter-entry vector The Gentlemen's affiliates have exploited alongside FortiOS in confirmed incidents.

How The Gentlemen Achieves Full Compromise in Under 24 Hours

The Gentlemen attack chain follows seven discrete phases executed in under 24 hours from initial access to domain-wide encryption.

Hours 0 to 2: Initial access arrives primarily through CVE-2024-55591, a CVSS 9.6 authentication bypass in FortiOS and FortiProxy that allows unauthenticated attackers to obtain super-admin privileges by sending a crafted Node.js websocket request to the management interface. Alternatively, the group purchases pre-compromised RDP, RDWeb, or VPN credentials from initial access brokers. Immediately after gaining access, the operator deploys SystemBC, a SOCKS5-over-RC4 encrypted proxy malware that tunnels all subsequent C2 traffic. EtherRAT deploys alongside SystemBC; rather than a hardcoded C2 IP, EtherRAT queries a public Ethereum RPC service to retrieve the C2 address stored in a smart contract, making the infrastructure resistant to domain or IP-based takedown.

Hours 2 to 6: SharpADWS enumerates Active Directory users, groups, and computer objects via Active Directory Web Services. NetScan and Advanced IP Scanner map the internal network. PsExec handles lateral movement to identified targets.

Hours 6 to 18: GentleKiller deploys across the domain. The tool drops a signed but vulnerable kernel driver, registers it as a Windows service, and uses IOCTL calls to terminate 400+ security product processes across 48 vendors. Simultaneously, deploy_gpo.ps1 executes from the NETLOGON share, pushing a fake Windows Update GPO policy to every domain machine that disables Windows Defender via the DisableAntiSpyware registry key. TukTuk C2, a modular framework using SaaS platforms including Slack and Dropbox as dead-drop channels, handles continued operator interaction. OxideHarvest steals credentials and sensitive data from all compromised machines.

Hours 18 to 24: The Go-based ransomware binary deploys domain-wide through GPO, encrypts Windows, Linux, and ESXi systems, appends the .GENTLEMEN extension, drops README-GENTLEMEN.txt in every directory, and sets gentlemen.bmp as the desktop wallpaper.

1

Initial access via FortiOS CVE-2024-55591 or IAB credentials

CVE-2024-55591 authentication bypass grants super-admin access to FortiOS/FortiProxy without credentials. Alternatively, stolen RDWeb and VPN access purchased from initial access brokers on underground markets.

2

SystemBC proxy and EtherRAT C2 deployed within 2 hours

SystemBC establishes encrypted SOCKS5 tunneling for all operator traffic. EtherRAT resolves its C2 address from an Ethereum smart contract, bypassing IP and domain blocklists.

3

AD enumeration and lateral movement: hours 2-6

SharpADWS enumerates Active Directory via ADWS. PsExec handles lateral movement to high-value targets including domain controllers, backup servers, and VMware hosts.

4

GentleKiller BYOVD terminates 400+ security processes: hours 6-18

GentleKiller drops a vulnerable kernel driver, loads it as a service, then sends IOCTLs to terminate all security product processes across 48 vendors before the ransomware binary runs.

5

GPO-delivered Defender disable and OxideHarvest credential theft

deploy_gpo.ps1 from NETLOGON pushes Defender-disabling registry keys to every domain machine. OxideHarvest steals credentials and sensitive data from all compromised hosts.

6

Domain-wide Go ransomware encryption: hours 18-24

GPO deploys the Go-based ransomware binary to Windows, Linux, and ESXi targets. Files receive the .GENTLEMEN extension. README-GENTLEMEN.txt drops to every directory.

Scale: 483 Victims in 66 Countries, the Second Fastest-Growing Ransomware Brand of 2026

The Gentlemen confirmed 483 victims across 66 countries between its mid-2025 founding and September 2026, with 380 of those compromised in 2026 alone. By published victim count, The Gentlemen is the second most prolific ransomware operation of 2026, behind only Qilin.

The group's 90/10 affiliate revenue split is the highest in the ransomware ecosystem, drawing operators from competing programs. Confirmed former affiliates from Qilin represent the largest bloc of The Gentlemen operators, based on infrastructure overlaps and leaked internal communications analyzed by KELA Cyber. A September 2026 analysis of a SystemBC C2 server compromise revealed 1,570 victims across active and completed campaigns in the group's backend infrastructure, exceeding the 483 publicly confirmed on the data leak site.

Manufacturing is the primary targeted sector, followed by energy, government, healthcare, retail, and technology. The group deliberately selects organizations with 500 or more employees and complex Active Directory environments. South America and Asia represent the highest victim concentration by HQ region, though operations span every major continent. The Commonwealth of Independent States is excluded from targeting, consistent with Russian-speaking operator conventions.

The group operates as a fully structured RaaS with a backend platform labeled Rocket, operator onboarding, and managed exfiltration infrastructure. The data leak site lists victims publicly, with a countdown timer before data release used as extortion leverage. The Gentlemen's velocity makes it a current-priority threat requiring immediate IOC deployment rather than deferred investigation.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

GentleKiller: How The Gentlemen Defeats 48 Security Vendors via BYOVD

GentleKiller is The Gentlemen's proprietary EDR killer framework, with at least 8 documented variants. The tool targets 400 or more processes mapped to approximately 48 security vendors. ESET's WeLiveSecurity published a full technical dissection of the framework in 2026, with Check Point Research independently verifying the vendor targeting list.

The BYOVD mechanism follows a consistent pattern. GentleKiller drops one of seven confirmed vulnerable drivers to disk, registers it as a Windows kernel service via sc.exe or NtCreateKey, then uses IOCTLs through the kernel driver handle to invoke privileged operations that terminate user-mode processes regardless of tamper protection settings. The six confirmed BYOVD drivers in active use are ProcessMonitorDriver.sys, wamsdk.sys, gamedriverx64.sys, biontdrv.sys, inpoutx64.sys, wsftprm.sys, and Havoc.sys. All are legitimately signed drivers with known exploitable vulnerabilities.

Companion killer tools HexKiller, HavocKiller, and ThrottleBlood extend coverage to processes GentleKiller misses in specific vendor configurations. The GentleKiller binary itself is protected by commercial packers Enigma and Themida to defeat static analysis. Stolen digital signatures from legitimate software vendors are appended to bypass certificate-based execution controls.

Defender-specific disabling runs in parallel via GPO: deploy_gpo.ps1 writes DisableAntiSpyware = dword:00000001 to HKLM\SOFTWARE\Policies\Microsoft\Windows Defender on every domain machine. This registry key disables Microsoft Defender even in environments where tamper protection is enabled, because tamper protection in Group Policy-managed environments defers to policy settings.

Defensive countermeasures: Enable Windows Memory Integrity (HVCI) in UEFI firmware to prevent unsigned or blocklisted drivers from loading at the kernel level. Add all seven documented GentleKiller driver filenames to your Windows Defender Application Control driver blocklist. Monitor System Event Log Event ID 7045 for new driver service installations and alert on driver names matching the known list.

GentleKiller is among the most comprehensive EDR-killing frameworks we have analyzed. Its use of multiple BYOVD drivers with commercial packer protection against all major EDR vendors represents a significant operational maturity step over predecessor tools.

ESET WeLiveSecurity, Killing me gently: Inside Gentlemen's EDR killer framework (2026)

EtherRAT and TukTuk C2: The Infrastructure No Takedown Can Reach

The Gentlemen operates two novel C2 frameworks that defeat traditional takedown methods: EtherRAT, which resolves C2 addresses from Ethereum smart contracts, and TukTuk, which uses legitimate SaaS platforms as dead-drop channels.

EtherRAT is a remote access trojan that does not contain a hardcoded C2 IP or domain. Instead, on startup it queries a public Ethereum RPC service, specifically 1rpc.io, to read a smart contract deployed by the operators. That smart contract contains the current C2 server IP address, which the operators can update at any time by submitting a new Ethereum transaction. Law enforcement agencies and security researchers cannot take down EtherRAT C2 infrastructure through domain seizures or IP null-routing. Removing the C2 address requires either compromising the operators' Ethereum wallet or waiting for the smart contract to expire. Hunt.io's analysis of EtherRAT infrastructure identified the Ethereum RPC queries as a reliable network-layer detection signal, since legitimate enterprise workstations do not routinely query Ethereum public RPC endpoints.

TukTuk is a modular C2 framework described in Check Point Research and DFIR Report analyses as AI-generated and purpose-built by The Gentlemen operators. TukTuk uses a rotating set of legitimate SaaS platforms as dead-drop configuration channels: ClickHouse, Supabase, Ably, Dropbox, GitHub Issues, Slack, and Arweave. Each TukTuk module contacts a different SaaS platform to retrieve next-stage instructions, making network-layer blocking impossible without disrupting legitimate business SaaS traffic. TukTuk handles credential theft and additional EDR disabling tasks during the hours-6-to-18 phase.

Detection for EtherRAT: alert on outbound DNS or HTTPS queries to public Ethereum RPC endpoints from enterprise workstations. The domains 1rpc.io and eth.llamarpc.com have no legitimate enterprise use case. Alert on these queries as high-confidence EtherRAT activity.

The Gentlemen Ransomware Indicators of Compromise

Block the SystemBC C2 IP addresses at perimeter firewalls and SIEM egress rules immediately. The driver file names below should be added to your WDAC driver blocklist. Any occurrence of README-GENTLEMEN.txt or the .GENTLEMEN file extension on your network indicates active ransomware deployment and requires immediate isolation and incident response. The persistence artifacts (DefSvc, UpdateSvc services; GupdateS, GupdateU Run keys) indicate a dwell-time phase before encryption and should trigger immediate host isolation if detected.

The Chrome extension supply chain attack covered August 31 demonstrated the same EDR bypass and credential theft pattern in a browser-based vector. The Gentlemen operates the same pre-encryption credential theft via OxideHarvest before the ransomware deploys.

Subscribe to unlock Indicators of Compromise

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Sigma Detection Rules for The Gentlemen Ransomware

No CVE-specific Sigma rules exist for The Gentlemen ransomware campaign. The two rules below were generated by Decryption Digest from the documented GentleKiller and persistence mechanism behaviors. Both carry status: experimental. Validate against your environment baseline before production deployment. The detection logic targets two high-confidence behavioral signals: BYOVD driver service installation using a known vulnerable driver name, and the creation of the group's signature persistence artifacts.

Rule 1 targets Windows service creation events where the driver filename matches any of the seven confirmed GentleKiller BYOVD drivers. Deploy against Windows System Event Log (Event ID 7045) or Sysmon Event ID 6. This is a high-confidence indicator with minimal expected false positives; the listed driver names have no legitimate enterprise service use.

Rule 2 targets the Defender-disabling registry modification and the known persistence Run key names. Deploy against Windows Security Event Log or Sysmon registry monitoring. The DisableAntiSpyware key under the Windows Defender policy path combined with either GupdateS or UpdateSvc is a near-certain The Gentlemen indicator.

No CVE-specific community Sigma rules exist yet. These rules were generated by Decryption Digest from the threat's known behavior. Validate against your environment before production deployment. Status: experimental.

Subscribe to unlock Sigma Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Subscribe to unlock Sigma Hunt Queries

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Subscribe to unlock WAF Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

The Gentlemen ransomware is the fastest-scaling criminal operation of 2026, defeating endpoint security through kernel-level BYOVD exploitation and making its C2 infrastructure immune to traditional takedowns via Ethereum smart contracts. Defenders have three immediate priorities: block the three SystemBC C2 IPs at the perimeter, enable HVCI to prevent BYOVD driver loading, and audit your environment for the six persistence artifacts (DefSvc, UpdateSvc services; GupdateS, GupdateU Run keys; README-GENTLEMEN.txt; .GENTLEMEN file extension) that indicate an active intrusion. The group's 24-hour full-compromise timeline leaves no room for deferred response. Run the Sigma rules above against your last 30 days of Windows event logs before end of day.

This analysis is generic. create a free account to score threats like this against your own stack.

Frequently asked questions

What is The Gentlemen ransomware group?

The Gentlemen is a Ransomware-as-a-Service operation tracked by Microsoft as Storm-2697 and by other vendors as LARVA-368. Founded in mid-2025 by Russian-speaking operators using the aliases hastalamuerte and zeta88, the group recruited former Qilin ransomware affiliates with an unusually generous 90/10 revenue split. The group operates a public data leak site, maintains a Go-based ransomware binary targeting Windows, Linux, and ESXi systems, and uses a proprietary EDR killer called GentleKiller alongside novel C2 infrastructure including EtherRAT, which resolves command-and-control addresses via Ethereum smart contracts.

How does GentleKiller defeat endpoint security tools?

GentleKiller uses Bring Your Own Vulnerable Driver attacks to terminate security processes at the kernel level. The tool drops a legitimately signed but vulnerable kernel driver, registers it as a Windows service, then sends IOCTLs through the driver to terminate processes belonging to 48 security vendors covering 400+ process names. Targeted vendors include CrowdStrike, SentinelOne, Microsoft Defender, Palo Alto Networks, Sophos, Trend Micro, ESET, Bitdefender, McAfee/Trellix, and Kaspersky. The GentleKiller binary is protected by commercial packers Enigma and Themida and uses stolen digital certificates from legitimate software vendors.

What is EtherRAT and why is it hard to take down?

EtherRAT is a remote access trojan deployed by The Gentlemen that resolves its command-and-control server address by querying Ethereum smart contracts through public RPC services such as 1rpc.io. Because the C2 address is stored on a decentralized blockchain rather than a traditional domain or static IP, law enforcement and security researchers cannot take it down through standard domain seizures or IP blacklisting. Removing the C2 address requires compromising the threat actor's Ethereum wallet or waiting for the smart contract to expire, both of which are significantly harder than a traditional takedown.

How long does a Gentlemen ransomware attack take?

Full Active Directory compromise and domain-wide encryption typically completes in under 24 hours from initial access. Hours 0 to 2 cover initial access and establishing SystemBC proxy tunnels and EtherRAT C2. Hours 2 to 6 involve Active Directory enumeration using SharpADWS, lateral movement via PsExec, and credential harvesting with OxideHarvest. Hours 6 to 18 involve GentleKiller BYOVD deployment across the domain, Defender disabling via GPO, and data staging for exfiltration. The Go-based ransomware deploys domain-wide between hours 18 and 24, appending the .GENTLEMEN extension to all encrypted files.

What sectors does The Gentlemen ransomware target?

The Gentlemen primarily targets industrials and manufacturing, with confirmed victims also in energy, government, healthcare, retail, and technology. The group selects organizations with 500 or more employees and complex Active Directory environments. Geographic targeting is global across 66 countries, with South America and Asia representing the most frequent victim HQ locations. The only confirmed geographic exclusion is the Commonwealth of Independent States, consistent with Russian-speaking operator origin.

How do I detect The Gentlemen ransomware on my network?

Key behavioral indicators: new Windows services named DefSvc or UpdateSvc; Run registry keys named GupdateS or GupdateU under HKCU; the registry key HKLM\SOFTWARE\Policies\Microsoft\Windows Defender with DisableAntiSpyware set to 1; any .sys file matching known BYOVD driver names such as biontdrv.sys or gamedriverx64.sys loaded as a service; files named README-GENTLEMEN.txt or gentlemen.bmp; msimg32.dll loaded from any directory outside C:\Windows\System32; and outbound connections to the known SystemBC C2 IP addresses 45.86.230.112 or 193.233.202.17.

What is BYOVD and how do I defend against it?

Bring Your Own Vulnerable Driver is an attack technique where threat actors drop a legitimately signed Windows kernel driver that contains an exploitable vulnerability, then use that driver to execute privileged code in the kernel that cannot be blocked by user-mode security tools. Defense options include enabling Windows Defender Credential Guard and Memory Integrity (HVCI), which prevents unsigned or explicitly blocked drivers from loading; maintaining a driver blocklist via Windows Defender Application Control that includes the known vulnerable drivers used by GentleKiller; monitoring System Event Log Event ID 7045 for new driver installations; and alerting on IOCTL calls from unexpected processes targeting EDR process names.

Has The Gentlemen ransomware group been attributed to a nation-state?

The Gentlemen is not attributed to a nation-state. The group is assessed as a financially motivated criminal Ransomware-as-a-Service operation run by Russian-speaking operators. The deliberate exclusion of Commonwealth of Independent States countries from targeting is consistent with Russian cybercriminal conventions designed to reduce law enforcement attention. No government attribution report linking The Gentlemen to a state intelligence agency has been published. Former Qilin ransomware affiliates make up a significant portion of the operator network, based on infrastructure overlaps and chat logs analyzed by KELA Cyber.

Sources & references

  1. ESET WeLiveSecurity, Killing me gently: Inside Gentlemen's EDR killer framework (2026)
  2. Check Point Research, Thus Spoke...The Gentlemen (2026)
  3. The DFIR Report, Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware (May 2026)
  4. Unit 42 (Palo Alto Networks), No Manners Here: The Ruthless Rise of The Gentlemen Ransomware (2026)
  5. Hunt.io, The Gentlemen Affiliate Deploys EtherRAT via Ethereum Smart Contract C2 (2026)
  6. Halcyon, Threat Assessment: The Gentlemen Ransomware Group (2026)

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.