The Gentlemen Ransomware: 90% Payouts and a Custom EDR Killer Fuel a 6x Victim Surge
A former Qilin affiliate turned RaaS is now 2026's second most active ransomware operation. The Gentlemen pay affiliates an unprecedented 90%, run a custom EDR killer dubbed GentleKiller, and have claimed 580 victims across 77 countries. Patch these five CVEs and hunt these behaviours now.
A ransomware crew that only opened its affiliate programme in September 2025 is already the second most active RaaS operation of 2026 by claimed victims. The Gentlemen, tracked by Microsoft as Storm-2697, has posted 580 victims across 77 countries by ransomware.live's count through 7 July, and the trajectory is the alarming part: claimed victims grew more than sixfold between the second half of 2025 and the first half of 2026, and the group was only active for the last four months of 2025.
They did not come from nowhere. Public reporting places the operators, roughly 20 people, inside the Qilin RaaS as an affiliate known as ArmCorp before they struck out on their own. Unit 42 tracks Qilin as Spikey Scorpius. The Gentlemen ran as a private operation first, then flipped to a full ransomware-as-a-service model around September 2025.
The economics explain the growth. A typical RaaS keeps 20 to 30% of every ransom and hands affiliates the rest; The Gentlemen hand over 90%, the most aggressive cut on the market. That is a recruitment weapon, and they are using it openly - in May 2026 the group announced a partnership with HasanBroker's BreachForums to pull in affiliates, penetration testers and initial access brokers. The same month, an alleged insider leaked an internal database, giving researchers an unusually clear look at how the operation is structured.

Technically, the group is built for reach. Its encryptors are written in both C and Go, which lets affiliates hit Windows, Linux and virtual infrastructure, ESXi included, in a single campaign, and Microsoft's analysis describes the Go encryptor as self-propagating, spreading itself over SMB once inside a network. Initial access is the familiar RaaS mix: exploited edge devices such as firewalls and VPNs, brute force, leaked or stolen credentials, and purchases from initial access brokers.
What separates them is how hard they go after the defences themselves. Researchers have tied the group to a custom Go-based backdoor, an EDR killer framework dubbed GentleKiller, and the suspected use of an unspecified zero-day exploit to switch off endpoint protection before encryption starts. Command and control has leaned on SystemBC, and the playbook finishes with the standard destruction of recovery options: clearing Security and System event logs with wevtutil and deleting Volume Shadow Copies with vssadmin and wmic.
The victim data fills in the rest. June 2026 was the group's biggest month yet at 117 claimed victims, close to four times its January figure. Manufacturing has taken the heaviest share, 103 of the 580, a sector attackers keep returning to because downtime pressure makes payment more likely. The legacy big-game operations, Qilin and Akira (Unit 42's Howling Scorpius), still lead on raw volume by running their established playbooks. But the gap is narrowing fast, and a 90% payout gives every capable affiliate in those programmes a reason to move.
Hunt and Harden
Patch first. Four vulnerabilities are being exploited for initial access: CVE-2024-55591 (Fortinet FortiOS and FortiProxy), CVE-2025-32433 (Erlang/OTP SSH server), CVE-2025-33073 (Windows SMB Client) and CVE-2025-55182 (React2Shell). Add CVE-2025-7771 (ThrottleStop.sys driver), abused for privilege escalation. While you patch, audit edge devices and internet-facing RDP for signs of earlier exploitation - assume the door may already have been opened.
Detect now. Raise a high-severity alert on the creation, deletion or execution of any scheduled task matching gentlemen*. Watch for wevtutil clearing Security or System logs, unsigned or known-vulnerable drivers loading (and turn EDR tamper protection on), Advanced IP Scanner appearing on hosts with no business running it, vssadmin or wmic deleting shadow copies, and outbound traffic on non-standard ports or matching SystemBC signatures.
Contain the spread. The encryptor moves itself over SMB, so enforce SMB signing, disable SMBv1 completely and restrict lateral movement between internal segments. Treat virtualisation as tier-0 infrastructure: SSH stays off on ESXi hosts except for explicit maintenance windows, and management interfaces live on a dedicated, isolated management VLAN. Deploy phishing-resistant MFA everywhere, audit and rotate credentials regularly, and monitor third-party tools and vendors for breaches that could become your initial access.
Recover on your terms. Maintain offline backups and actually test the restores. If the first time you test recovery is mid-incident, that 90% cut is coming out of your ransom.