Full Report
The Gentlemen is a financially motivated, Russian-speaking ransomware-as-a-service (RaaS) operation that split from Qilin’s affiliate programme and has, within roughly a year, become one of the two most active ransomware operations globally. It has a confirmed footprint of at least six Belgian victims in 2026 and has demonstrated an impact on critical infrastructure elsewhere in the European Union. Its threat comes less from technical novelty than from an industrialised, affiliate-friendly platform that lowers the skill barrier for intrusion at scale.
Analysis Summary
# Threat Actor: The Gentlemen
## Attribution & Identity
* **Actor Type:** Financially motivated Ransomware-as-a-Service (RaaS) operation.
* **Origin:** Russian-speaking; assessed with moderate confidence to be based in Russia or a Russian-speaking CIS jurisdiction.
* **Associations:** A split-off from the **Qilin** affiliate program (July 2025).
* **State Relationship:** Activity is likely tolerated or informally encouraged by Russian state interests, though no direct state tasking is evident.
## Activity Summary
The Gentlemen emerged in mid-2025 and rapidly scaled to become one of the top two most active ransomware operations globally. Their operational tempo accelerated from 40 victims in Q4 2025 to 269 victims in Q2 2026. As of late 2026, they have established a confirmed footprint in Belgium and have impacted critical infrastructure within the European Union.
## Tactics, Techniques & Procedures
* **Industrialized Access:** Uses a centrally maintained staging pool of pre-compromised devices for affiliates.
* **Initial Access:** Exploitation of known n-day vulnerabilities and public proof-of-concept (PoC) exploits; brute-forcing of VPN credentials.
* **Lateral Movement:** Self-propagation toolset bundled within the encryption package.
* **Defense Evasion:** Operator-maintained "EDR-killer" service designed to disable security software.
* **Persistence:** Use of legitimate or open-source software for Command and Control (C2) to avoid fingerprinting.
* **Extortion:** 90/10 revenue split with affiliates; utilizes "chain-victimization" techniques.
## Targeting
* **Sectors:** Opportunistic and revenue-driven. The **Manufacturing** sector is the most consistently targeted. Impact has also been noted in **Critical Infrastructure**.
* **Geography:** Global, with a notable impact in the **European Union**. The United States is proportionally under-represented compared to other RaaS groups.
* **Victims:** At least six confirmed victims in **Belgium** (as of 2026).
## Tools & Infrastructure
* **Malware:** Mature encryption toolset with self-propagation capabilities.
* **Access Infrastructure:**
* Estimated 14,700 pre-compromised **FortiGate** devices.
* 969 validated **FortiGate VPN** credentials.
* **C2:** Built substantially on legitimate or open-source software (making infrastructure fingerprinting difficult).
## Implications
The Gentlemen represent a shift toward "industrialized" ransomware. Their primary threat is not technical novelty (no zero-day capability), but rather a highly efficient, affiliate-friendly platform that lowers the skill barrier for high-scale intrusions. Their rapid growth and targeting of EU critical infrastructure mark them as a top-tier strategic threat to regional stability.
## Mitigations
* **Vulnerability Management:** Prioritize patching of edge devices, specifically **FortiGate** firewalls and VPNs, to defend against known n-day exploits.
* **Identity Security:** Enforce multi-factor authentication (MFA) on all VPN and remote access points to neutralize brute-forced credentials.
* **Endpoint Protection:** Harden EDR configurations against "EDR-killer" scripts and monitor for the unauthorized use of legitimate administrative or open-source C2 tools.
* **Network Segmentation:** Implement strict segmentation to prevent the group’s self-propagating encryption tools from spreading laterally.