INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Infostealers, AI, and 90% Affiliate Cut Fuel Gentlemen's Rise

| 2026-06-15 06:58 CRITICAL MEDIUM
Executive Summary AI-generated
The Gentlemen ransomware group has emerged as a formidable force in the world of cybercrime, with their tactics and techniques (T&T) continuing to evolve. Their ability to scale quickly and efficiently is due in part to their use of advanced tools such as infostealers and AI-powered extortion methods. This sophistication has allowed them to target victims across multiple countries, including Thailand, Brazil, the UK, France, India, Germany, Italy, Japan, Taiwan, and Spain. The group's willingness to get personal with their targets is also a key factor in their success, making them one of the most prolific ransomware brands of the year.
Technical Mitigations AI-generated
* Implement a robust patch management system to ensure timely updates and security patches for all systems, including those used by the Gentlemen group. * Use secure authentication protocols, such as multi-factor authentication (MFA) or token-based authentication, to prevent unauthorized access to sensitive areas of the network. * Regularly monitor and analyze traffic patterns, including dark-web and infostealer monitoring, to detect potential threats and identify vulnerabilities in the Gentlemen operation's infrastructure. * Conduct regular security audits and penetration testing to identify weaknesses in the Gentlemen group's systems and procedures, and implement remediation measures as needed.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilinEmbargoEmbargoBlack BastaBlack Basta CVE-2025-32433CVE-2025-32433 CVE-2024-55591CVE-2024-55591 CVE-2025-33073CVE-2025-33073
Target & Sectors
NORTH_AMERICA NORTH_AMERICA LATAM LATAM DACH DACH ASEAN ASEAN energyenergy logisticslogistics technologytechnology defensedefense manufacturingmanufacturing healthcarehealthcare
Incident Timeline
‎February 2025
The Gentlemen group used stolen data and their own contact list to target victims across 66 countries, with the ransomware attack resulting in 483 high-value access thefts within a year.
tactic Phishing
malware Black Basta
organisation SecurityAffairs
victims 483 victims
organisation Microsoft
organisation MFA
organisation Harden Active Directory
organisation ZeroLogon
‎March 2025
The Gentlemen group used AI to infect its victims with ransomware.
organisation Ransomware
victims 478 Victims
‎2025/06/11
Threat actors used the Gentlemen group's ransomware to extort affiliates, fueling their rise as a highly adaptive and fast-moving operation.
tactic Ransomware
tactic Extortion
organisation LevelBlue
‎July 2025
Phantom Mantis transitioned into The Gentlemen, an independent partnership program in Switzerland.
source_region Switzerland
‎August 2025
Threat actors used the Gentlemen group's rise to target Qilin through an AI-powered infostealer.
malware Qilin
organisation LARVA-368
‎September 2025
The Gentlemen group used ransomware to target 483 victims, with approximately 380 of them being listed on their dark-web leak site by June 13, 2026.
tactic Ransomware
victims 483 victims
general_metric 380 leak site
‎November 7, 2025
Threat actors used a 90% affiliate cut fuel to target The Gentlemen group's rise.
‎November 2025
Threat actors used a 90% affiliate cut from the Gentlemen group's access to a chat database of nearly 3,366 messages.
organisation VMware Aria Operations
general_metric 3,366 comprising messages
general_metric 2026 late April
‎March 2026
Threat actors used a 90% affiliate cut fuel to target the Gentlemen group by exploiting an open directory on Proton66 hosting Russian bulletproof infrastructure.
tactic Ransomware
target_region Russian Federation
data_breach 126 files
‎April 2026
The Gentlemen group, an active threat actor that emerged as one of the most active ransomware attackers in April 2026.
tactic Ransomware
general_metric 10 %
‎April 30, 2026
The Gentlemen group used the infostealer to target 2GO, a Philippine logistics firm.
victims 44 listed victims
financial 20 dollar
financial 200 dollar
organisation Active Directory
organisation PetitPotam
‎2026/05/12
Threat actors used a Gentlemen group affiliate to exploit vulnerabilities in Rocket's internal systems and infect its users with infostealers.
‎May 2026
The Gentlemen group's internal chat logs were leaked, revealing nine core members and access models built using AI-assisted tooling.
‎June 13, 2026
The Gentlemen, a ransomware operation, targeted 483 victims on their dark-web leak site by June 13, 2026.
tactic Ransomware
victims 483 victims
general_metric 380 leak site
‎2026/06/15
Phantom Mantis, an affiliate group of The Gentlemen ransomware, launched a multi-channel extortion operation using red team utilities like NetExec and RelayKing to infect its targets.
victims 483 victims
victims 478 Victims
organisation LockBit
infrastructure Windows
infrastructure Linux
organisation Logical Volume
organisation Microsoft
organisation ZeroFox
organisation affiliates
organisation CVE-2025
organisation NTLM
organisation ArmCorp
organisation Infection
organisation NetExec
organisation TaskHound
organisation PrivHound
organisation CertiHound
organisation System
organisation Security Windows Event Logs
organisation Microsoft Defender
infrastructure Fortigate
organisation The Hacker News
organisation the Pestilent Mantis's
victims 20 targets
organisation NCC Group
organisation EDR
organisation VMware
data_breach 1 GB
Tactical Metrics
Metrics
victims
44
Listed Victims
Metrics
victims
483
Victims
Metrics
financial
20,000,000
Dollar
Metrics
financial
200,000,000
Dollar
Metrics
data_breach
126
Files
Metrics
victims
478
Victims
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Fortigate
Affected Product
Metrics
victims
20
Targets
Metrics
data_breach
1
Gb
Intelligence Sources