news.mlab.sh
Back to the feed
ransomware

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

High
Summary

The Gentlemen ransomware group, initially operating as the affiliate-focused Phantom Mantis, has evolved into an independent RaaS operation led by the cybercriminal LARVA-368 (aka hastalamuerte). The group, responsible for 478 victims as of late 2025, utilizes a sophisticated approach combining mature ransomware techniques with RaaS features, including AI-assisted development and double extortion tactics. A key element of their operation involves exploiting vulnerabilities and leveraging affiliate networks, with a recent dispute over a $48,000 exit scam highlighting their operational dynamics.

The Gentlemen ransomware operation has been a significant force in the ransomware landscape since its emergence in March 2025. Initially operating as the affiliate-driven Phantom Mantis, the group has transitioned to a more independent RaaS model, spearheaded by LARVA-368, a Russian-speaking cybercriminal with a history linked to the Embargo ransomware group. Their tactics involve a combination of established ransomware techniques alongside the flexibility and support offered by a RaaS structure, including the use of AI for tool development and post-exploitation assistance. The group’s adaptability is further demonstrated by their ability to shift tactics during attacks, such as manipulating Group Policy Objects (GPOs) and bypassing endpoint protections. Recent analysis indicates that The Gentlemen accounts for approximately 10% of overall ransomware activity, primarily targeting enterprise environments through initial access gained via vulnerable internet-facing services or stolen credentials.

The group’s operational model includes a profit-sharing arrangement of 90% for affiliates and 10% for the operator, incentivizing participation. To manage affiliates, The Gentlemen utilizes a dedicated communication platform and provides technical support, including EDR killers to bypass security solutions. A key element of their recruitment strategy involves requiring affiliates to provide 1GB of exfiltrated data, a tactic designed to deter law enforcement and researchers from accessing their infrastructure. Their ransomware portfolio encompasses five versions targeting Windows, Linux, ESXi, Windows XP+, and Logical Volume Manager (LVM), showcasing a broad range of potential targets. The group’s geographic focus is concentrated in Thailand, the U.K., Brazil, Germany, and India, with only 13% of victims located in the U.S.

Read the full article at The Hacker News