Sentrix

Actor · RaaS · since 2025

The Gentlemen: the RaaS that spreads on its own

Profile of The Gentlemen, a RaaS from mid-2025 that exploits firewalls and VPNs, disables EDR and spreads a self-propagating Go encryptor. Targets and controls.

Model
RaaS · since 2025-07
Aliases
Storm-2697, ArmCorp
Ways in
Firewall and VPN vulnerabilities (FortiGate, Cisco) · Brute force against web and VPN portals · Leaked or stolen credentials · Initial access brokers
Targets
Manufacturing · Healthcare · Education · Transportation · Finance

By Sentrix · Published 2026-09-20

Who they are

The Gentlemen is a ransomware-as-a-service program active since at least July 2025, according to Palo Alto Networks Unit 42, which also tracks it under the Storm-2697 name assigned by Microsoft. The group first operated as a closed entity, then opened its program to affiliates in September 2025; Microsoft and Unit 42 agree on that date. Before going independent, the team operated as ArmCorp, an affiliate of the Qilin RaaS, according to Unit 42.

What attracts affiliates is the cut: Unit 42 notes a 90% payout, against 70 to 80% elsewhere. What attracts defenders' attention is the growth rate. Check Point Research counts approximately 332 victims published on the leak site in the first five months of 2026; Unit 42 counts 580 across 77 countries through July 2026, including 103 in manufacturing, with a peak of 117 in June 2026.

On May 4, 2026, the program's administrator acknowledged on underground forums that its internal "Rocket" database had leaked, according to Check Point Research. The exposed data shows a small team: nine operator accounts and eight affiliate TOX IDs according to Check Point Research, around twenty operators according to Unit 42, and an administration panel built in three days with AI-assisted coding.

How they get in

Unit 42 lists four routes: exploitation of vulnerabilities in edge devices (firewalls, VPNs), brute force, leaked or stolen credentials, and collaboration with initial access brokers. Check Point Research adds that FortiGate and Cisco devices are the primary targets and tracks CVE-2024-55591 (FortiOS), CVE-2025-32433 (Erlang SSH) and CVE-2025-33073 (NTLM relay).

Once inside, the sequence is industrial: scanning for NTLM relay opportunities with the RelayKing tool, extraction of ntds.dit and shadow copies, browser session theft to reach Microsoft 365 and Okta, then EDR neutralization with a dedicated family of tools, the GentleKiller framework named by Unit 42 and the EDRStartupHinder, gfreeze and glinker utilities described by Check Point Research. The encryptor, written in Go, uses per-file ephemeral Curve25519 keys with XChaCha20 and attempts to spread through several simultaneous lateral movement methods, according to Microsoft.

What they have done

  • September 2025: the RaaS opens. Microsoft and Unit 42 date the shift from a closed group to an affiliate program to September 2025, with an official recruitment partnership on BreachForums according to Microsoft.
  • First half of 2026: rising volume. Check Point Research places The Gentlemen among the most active RaaS programs of 2026, with approximately 332 victims published in five months.
  • May 4, 2026: backend leak. Check Point Research documents the administrator's admission and the exposure of infrastructure details and affiliate communications.
  • May 28, 2026: encryptor analysis. Microsoft publishes its analysis of the self-propagating Go encryptor and confirms victims in education, transportation, healthcare and finance across North America, South America, Europe, Africa and Asia.

What stops them

  1. Patching and hardening of edge devices. FortiOS, Cisco, VPN gateways: patch within days, disable administration from the internet, remove unneeded local accounts. ISO 27001:2022, 8.8 and 8.20; SOC 2, CC7.1.
  2. Phishing-resistant MFA on VPNs and portals. Brute force and purchased credentials are useless against a second factor that is not an SMS code. ISO 27001:2022, 8.5; SOC 2, CC6.1.
  3. SMB signing and NTLM relay hardening. Require SMB and LDAP signing, disable NTLM where possible, patch CVE-2025-33073. ISO 27001:2022, 8.9 and 8.20.
  4. EDR tamper protection and driver monitoring. The group invests in EDR neutralization; tamper protection and alerts on sensor shutdown must be enabled and tested. SOC 2, CC7.2; ISO 27001:2022, 8.7.
  5. Segmentation and tiered accounts. An encryptor that spreads on its own stops at network boundaries and at accounts that do not hold rights everywhere. Separate administrative credentials by tier. ISO 27001:2022, 8.2 and 8.22.
  6. Browser sessions and tokens. Session theft against Microsoft 365 and Okta bypasses MFA: short session lifetimes, conditional access requiring a compliant device, token revocation during an incident. ISO 27001:2022, 5.17; SOC 2, CC6.6.

Sources

Frequently asked questions

Why did The Gentlemen grow so fast?
Unit 42 notes a 90% payout to affiliates, against 70 to 80% at competitors, and Microsoft reports an official recruitment partnership with BreachForums. Add ready-made tooling against firewalls and EDR, and the program attracts teams that are already experienced. Check Point Research measures the effect: approximately 332 victims published in the first five months of 2026.
What does a self-propagating encryptor mean for us?
That the time between the first encrypted machine and the last shrinks to almost nothing. Microsoft describes a Go encryptor that attempts several lateral movement methods simultaneously. A detection that fires on the first encrypted host is already too late; you need to detect earlier, at the NTLM relay or EDR shutdown stage, and rely on segmentation to contain the spread.
Did the May 2026 backend leak weaken the group?
Not visibly. Check Point Research documents the leak acknowledged on May 4, 2026 and, over the same period, Unit 42 measures the group's peak activity in June 2026 with 117 claimed victims. Internal leaks tell defenders about tools and habits, but they do not close entry points; only your patching and your MFA do that.

Let's talk about your compliance program.

Last updated: 2026-09-20