◇ SIGN IN
← all actors
ransomware

The Gentlemen

activemedium confidence
Ransomware
The Gentlemen
Attribution
RaaS (financially motivated, unattributed)
Origin
Unknown
First seen
2025
Last active
2026
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Saudi Arabia, UAE
Sectors
Construction, power, manufacturing

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, UAE (Construction, power, manufacturing sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

The Gentlemen is a ransomware group first documented in August 2025, characterized by custom tooling, targeted defense-evasion techniques, and a self-propagating Go-based encryptor.

History

The Gentlemen was first observed in August 2025 by Trend Micro during an active campaign, with no prior threat-intelligence footprint. Its leak site went live around early September 2025. The operation began as a closed group and started offering RaaS to affiliates in September 2025. Researchers highlight advanced, target-tailored defense-evasion tradecraft (custom anti-AV/anti-EDR tooling adapted mid-campaign) rather than generic techniques. In May 2026 Microsoft published analysis of a self-propagating Go-based Gentlemen encryptor.

Reporting through mid-2026 (e.g., Ransomware.live tracking) credits The Gentlemen with a rapidly growing victim count across many countries and sectors, with manufacturing, construction, healthcare and insurance among the hardest hit and an initial concentration in the Asia-Pacific region before broader expansion.

The Gentlemen has claimed victims in Saudi Arabia and the UAE among its listings. These are extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.

Notable campaigns

2025
Emergence and Trend Micro disclosure
Trend Micro uncovered The Gentlemen's campaign in August 2025, documenting custom tooling and targeted defense evasion.
2026
Self-propagating Go encryptor
Microsoft dissected a self-propagating Go-based Gentlemen encryptor in May 2026.
2025
Gulf leak-site listings
Saudi and UAE organizations appeared on The Gentlemen's leak site (claimed, not independently confirmed).

Known tooling · Ransomware Tool Matrix

Tools observed in intrusions leading to The Gentlemen's ransomware, per the community Ransomware Tool Matrix — observed use, not exhaustive. Snapshot 2026-08-07.

Discovery · 12
Advanced IP ScannerAPI-C99-NLCensysCertiHoundGogoMANSPIDERNmapPrivHoundRelayKing-DepthShodanSoftPerfect NetScanTaskHound
RMM Tools · 3
AnyDeskFreeRDPMeshAgent
Defense Evasion · 5
EDRStartupHinderKslDumpPowerRunRedSunThrottleStop driver (BYOVD)
Credential Theft · 3
DumpBrowserSecretsKslKatzMimikatz
OffSec · 8
ImpacketNetExecPowerZureRegPwnResponderTitanisVelociraptorZeroPulse
Networking · 8
Amnezia VPNChiselCloudflaredOpenSSHOpenVPNProxychainsPuTTYWireguard VPN
LOLBAS · 1
PsExec
Exfiltration · 1
WinSCP

4 source reports · latest 15 May 2026

Claimed victims · 723 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
Hartfiel AutomationDEManufacturing
YY Business SolutionsOther
Halliday Watkins MannUSProfessional Services
ZS SalovnovaCZ
Holborn European MarketingCYProfessional Services
Phase TechnologiesUSTechnology
LensAss ArchitectenBEProfessional Services
VemecARManufacturing
NobemaDETechnology
Feraboli ZootechITAgriculture and Food Production
Intranet Gov BrasilBRGovernment & Defense
TESIIT