Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Ransomware » Microsoft Warns The Gentlemen Ransomware Ranks Among Top Active Threats

Microsoft Warns The Gentlemen Ransomware Ranks Among Top Active Threats

By:
Last updated:August 14, 2026
Human Written
  • Microsoft says The Gentlemen has recorded one of the highest victim counts among active RaaS groups.

  • The ransomware can encrypt files and spread itself across reachable systems on a network.

  • Microsoft ranks its payload fourth among active ransomware offerings, behind Akira, Qilin, and LockBit.

Microsoft Warns The Gentlemen Ransomware Ranks Among Top Active Threats

Microsoft Threat Intelligence has warned that The Gentlemen ransomware is becoming a major threat. The company linked the operation to a financially motivated actor called Storm-2697. Microsoft said leak site data showed a high victim count recently.

Microsoft also placed The Gentlemen fourth among active ransomware offerings. Akira, Qilin, and LockBit ranked ahead of it. Microsoft said the operation combines file encryption with network spreading. Microsoft Threat Intelligence information.

Microsoft Flags The Gentlemen

The ransomware operation emerged around mid-2025, according to Microsoft’s analysis. It later expanded into a ransomware-as-a-service model using affiliates. Those affiliates carry out attacks while operators manage the wider platform.

Microsoft has seen victims across several sectors. These sectors include education, transportation, healthcare, and financial services. The findings show that the operation has affected different types of organizations.

The Gentlemen ransomware uses the Go programming language, Microsoft said. It also uses Curve25519 keys and the XChaCha20 cipher to lock files. These features allow the malware to encrypt files during an attack.

The ransomware’s spreading feature is one of its key dangers. Microsoft said attackers can launch the malware with a “–spread” option. That setting can change the program from a single computer encryptor into a self-spreading worm.

Ransomware can Spread Across Networks

When the spreading option runs, the malware tries to reach other systems. It can then attempt to place its encryptor on reachable systems. One infected computer could therefore become the start of a wider attack.

The Hacker News reported in June that The Gentlemen had claimed 478 victims. The report cited PRODAFT research and data from Ransomware.Live. It also said the operation previously worked within LockBit, Qilin, and Medusa ecosystems. The Hacker News report on The Gentlemen

PRODAFT’s research described a change in how the group operated. The Gentlemen moved from an affiliate role into an independent RaaS operation. The shift gave the group greater control over its own ransomware service.

The operation also uses a strong payment offer to attract affiliates. Research cited by The Hacker News said affiliates can receive up to 90%. The operators keep the remaining share from ransom proceeds.

The report said affiliates have used stolen login details and internet-facing system flaws. Those methods can help attackers gain access before deploying ransomware. The operation also supports ransomware versions for different computing environments.

Microsoft’s analysis shows why the spreading feature matters. Attackers may otherwise need to deploy malware on separate systems. The Gentlemen can instead try to move through reachable systems after gaining access.

The Hacker News reported that The Gentlemen has been active since March 2025. PRODAFT tracks the group as Phantom Mantis. Microsoft tracks the operator cluster as Storm-2697. The names come from different security research systems.

Microsoft also described the ransomware’s encryption process. The malware creates temporary keys for individual files before using XChaCha20. This process helps protect file contents during an attack.

Microsoft’s Defensive Guidance

Microsoft has advised organizations to strengthen their security controls against The Gentlemen. The company recommends stronger identity protection and tighter control over privileged accounts. It also recommends endpoint security tools that can detect suspicious activity early.

Microsoft further recommends cloud-delivered protection where available. It also points to tamper protection and controlled folder access. These measures can help detect or block suspicious ransomware activity.

The company said organizations should focus on stopping attackers early. This matters because The Gentlemen can attempt to spread after reaching one system. A quick response may limit how far an attack moves across a network.

The Gentlemen’s growth also shows the wider role of RaaS operations. These groups provide ransomware tools and services to affiliates. Affiliates then use those resources to attack victims and share proceeds.

The partnership with BreachForums represents a significant escalation, turning the forum from a passive marketplace into an active operational hub where affiliates can access the ransomware directly while keeping 90 percent of ransom payments, a cut higher than many competing RaaS programs.

The Hacker News reported that The Gentlemen’s victim total reached 478. The figure came from Ransomware.Live data cited by PRODAFT. That number reflects claims linked to the operation and does not prove every incident.

Microsoft’s findings show an operation with broad capabilities. Its encryption feature can lock files, while its spreading feature targets reachable systems.

Organizations can therefore face a larger incident after one successful entry. Microsoft says stronger identity controls and limited privileged access can help. Early detection can also help reduce the damage caused by an intrusion.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.