The GentlemenThe Gentlemen

Also known as: The Gentlemen

Known aliases
1

Profile

The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure victims into paying ransoms. Their operations leverage advanced techniques such as abusing legitimate utilities like PowerRun.exe for privilege escalation, using custom-built tools for defense evasion, and employing flexible encryption methods based on file size. The group targets medium to large organizations across various sectors, particularly in the Asia-Pacific region, and has demonstrated a high level of technical maturity and operational discipline. Their activities include systematic compromise of enterprise environments, mass account enumeration, and the use of encrypted channels for data exfiltration.

Aliases· 1

The Gentlemen

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
GCMAN
Actor
Dalbit
Software
Gendarmerie
Actor
GOLD GARDEN
Software
Dark Power
Software
holyghost
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.