The gentlemen ransomware: from affiliate fallout to AI-fueled cybercrime juggernaut

The Hacker News

The gist

The Gentlemen ransomware gang exploded from obscurity to become a global cybercrime force, weaponizing AI tools and ruthless affiliate recruitment to grab 10% of the world’s ransomware market in under a year.

What to know

  • After a dramatic $48,000 exit scam split from Qilin in July 2025, The Gentlemen lured top talent with a 90% affiliate payout, fueling multi-platform attacks that hit over 320 victims by early 2026.
  • By mid-2026, the group turbocharged its operations with AI-assisted payload development (using Cursor and Claude Opus) and tested nearly 80 modules against 70+ evasion tactics—though their ransomware itself remained non-autonomous.
  • Their in-house GentleKiller toolkit, boasting at least 8 variants, rapidly exploits new driver vulnerabilities to disable up to 400 security processes, all while cloaked in spoofed certificates and icons to dodge detection.

Affiliate Power Surge

The Gentlemen’s explosive rise came from a radical 90% affiliate payout and aggressive recruitment, transforming them from a splinter group into a global ransomware force targeting every major sector.

The Gentlemen ransomware group surged from a closed operation in mid-2025 to become the second most active ransomware entity by early 2026, responsible for over 320 confirmed victims and 240 attacks in 2026 alone. This rapid ascent was fueled by their transition to a ransomware-as-a-service (RaaS) model offering affiliates an unusually generous 90% cut of ransom proceeds, which attracted skilled attackers and enabled multi-platform assaults across Windows, Linux, and ESXi environments. By April 2026, The Gentlemen accounted for approximately 10% of global ransomware activity, underscoring their explosive growth and operational scale.

Originally an affiliate operation known as Phantom Mantis, The Gentlemen broke away in July 2025 following a contentious payment dispute with the Qilin RaaS group, accusing them of an exit scam involving $48,000. This pivotal shift to independence allowed The Gentlemen to establish its own partnership program and aggressively recruit affiliates from rival groups, thereby consolidating its autonomy and expanding its reach. As Swiss cybersecurity analysts noted, this evolution marked a significant turning point in their operational sophistication and self-sufficiency.

The Gentlemen have strategically broadened their target sectors beyond their initial focus, now exploiting exposed internet-facing systems such as VPNs and firewalls to infiltrate manufacturing, technology, healthcare, financial, transportation, education, and industrial organizations. Their ransomware has been adapted to a diverse array of platforms including Windows, Linux, BSD, NAS, and VMware ESXi, demonstrating a high degree of technical adaptability. This sectoral and technological expansion has cemented their status as a versatile and formidable threat actor in the cybercrime landscape.

Sources

AI Behind the Attacks

AI agents like Cursor and Claude Opus supercharged The Gentlemen’s attack development and evasion tactics, enabling rapid module creation while keeping the ransomware itself non-autonomous.

By mid-2026, The Gentlemen ransomware group had harnessed AI-assisted toolkits, notably leveraging AI agents like Cursor and Claude Opus, to automate the development and refinement of payloads while significantly enhancing evasion of endpoint detection and response (EDR) systems. This integration accelerated their operational efficiency by automating complex tasks such as Active Directory discovery and systematically mapping bypass techniques to the MITRE ATT&CK framework, resulting in nearly 80 modules tested against over 70 evasion techniques. However, despite AI's pivotal role in pre-deployment sophistication, researchers from Sophos confirmed that the deployed ransomware itself did not embed AI components or operate autonomously within victim networks, underscoring AI's function as a force multiplier behind the scenes rather than an autonomous actor in attacks.

This AI-driven evolution coincided with The Gentlemen's strategic transformation in July 2025 from the Phantom Mantis affiliate into an independent partnership program, no longer reliant on other ransomware-as-a-service groups. According to Swiss cybersecurity firm LARVA-368, this shift was marked by heavy reliance on artificial intelligence not only for ransomware development and maintenance but also for post-exploitation assistance, signaling a move toward a self-sustaining cybercrime powerhouse that integrates AI throughout its operational lifecycle.

Sources
Bleeping ComputerThe Hacker News

Ransomware as Big Business

A lucrative profit-sharing model and relentless recruitment fueled The Gentlemen’s $52 million revenue boom, turning the group into a dominant player in the cybercriminal economy.

The Gentlemen ransomware group's innovative business model centers on a ransomware-as-a-service (RaaS) platform that offers affiliates an unusually generous 90% share of ransom proceeds, a strategy that has attracted highly experienced attackers and enabled operations across diverse environments including Windows, Linux, and ESXi. This aggressive profit-sharing, combined with shared tooling and stealth infrastructure, has fueled rapid scaling, making The Gentlemen the second most active ransomware group globally by April 2026, accounting for 10% of worldwide ransomware activity as noted by NCC Group and cybersecurity expert Matt Hull.

Originally a closed operation in mid-2025, The Gentlemen evolved into an independent partnership program by July 2025, breaking away from reliance on other RaaS groups such as Pestilent Mantis. This transition was marked by aggressive recruitment tactics including discrediting competitors through disinformation campaigns and investing in premium underground forum accounts to enhance visibility and outmaneuver rivals, as detailed by Swiss cybersecurity researchers LARVA-368 and LARVA-367.

The group's rapid revenue growth—approximately $52 million earned between July 2025 and March 2026—reflects not only their innovative RaaS model but also the broader maturation of the cybercriminal ecosystem. Easier access to target infrastructures via dark web brokers has synergized with The Gentlemen's business approach, enabling swift expansion and increased attack frequency, particularly impacting industrial sectors as highlighted in early 2026 analyses.

Sources

GentleKiller: EDR Nemesis

The Gentlemen’s GentleKiller toolkit rapidly weaponizes new driver vulnerabilities and cloaks attacks with fake certificates, crippling defenses while evading detection at scale.

By mid-2026, the Gentlemen ransomware group had engineered an advanced, in-house EDR-killing toolkit dubbed GentleKiller, boasting at least eight variants that exploit a range of vulnerable or malicious drivers to systematically disable up to 400 security processes. This rapid operationalization of Bring Your Own Vulnerable Driver (BYOVD) exploits—often within days of their public disclosure—underscores the group’s agility in integrating cutting-edge attack vectors to overwhelm defenses swiftly and effectively.

To maximize stealth and persistence, Gentlemen standardizes its defense evasion by applying a unified impersonation strategy across its entire arsenal of EDR killers, including third-party tools like HexKiller, ThrottleBlood, and HavocKiller. By embedding fake version information and cloning legitimate certificates and icons, the group crafts a convincing veneer of legitimacy, while applying sophisticated evasion techniques directly to compiled binaries rather than source code—ensuring their tools remain protected even when source code leaks or is unavailable.

Sources
GlobeNewswire - Industry News on Technology

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.