Ransomware group

The Gentlemen

The Gentlemen is a rapidly expanding ransomware-as-a-service (RaaS) operation that emerged in mid-2025 and became one of the most prominent ransomware brands during the first half of 2026. Microsoft tracks the operators as Storm-2697 and documents a Go-based Windows encryptor with aggressive self-propagation and defense-evasion behavior.

Check Point reports a multi-platform locker portfolio covering Windows, Linux, NAS and BSD in Go plus an ESXi locker in C. The program recruits affiliates and uses double extortion, combining encryption with data theft and public-leak pressure.

Core ransomware capabilities are high-confidence because independent technical sources provide behavior-level evidence. Affiliate-specific tooling, particularly SystemBC, is kept separate from core program capability unless additional evidence establishes centralized integration.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-18

ATT&CK

MITRE ATT&CK

T1021.002SMB/Windows Admin Shares
T1021.006Windows Remote Management
T1047Windows Management Instrumentation
T1053.005Scheduled Task
T1059.001PowerShell
T1070.001Clear Windows Event Logs
T1070.004File Deletion
T1135Network Share Discovery
T1486Data Encrypted for Impact
T1490Inhibit System Recovery
T1562.001Disable or Modify Tools
T1569.002Service Execution

Research

Selected OSINT