The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
PRODAFT says The Gentlemen ransomware has claimed 478 victims since March 2025 and can spread rapidly across networks.
Intelligence analysis by GPT-5.4 Mini

A new report says The Gentlemen has evolved from a RaaS affiliate into its own operation, with AI-assisted tooling, aggressive affiliate support, and worm-like propagation. The group targets enterprise environments through exposed edge devices and stolen credentials.
The Gentlemen is like a break-in crew that keeps changing tools and routes to get into offices. Once inside, it can lock doors, copy files, and even spread from room to room like a fast bug.
Analysis
What PRODAFT says
PRODAFT tracks the operation as Phantom Mantis and says it was led by a Russian-speaking actor it labels LARVA-368. The report says the group first worked as an affiliate using multiple ransomware-as-a-service programs, then shifted in July 2025 into its own independent partnership program.
The article says The Gentlemen has claimed 478 victims since March 2025, based on Ransomware.Live data. It also notes that the group accounted for 10% of ransomware activity in April 2026, which points to a significant operational footprint.
How it operates
The group is described as enterprise-focused, entering through vulnerable internet-facing services or stolen credentials. NCC Group says the attackers adapt during intrusions, including by manipulating GPOs, compromising privileged accounts, and using custom methods to get around endpoint protections.
The report says the group provides support through The Gentlemen IM and other messaging platforms, and that it offers five ransomware builds for Windows, Linux, ESXi, Windows XP+, and LVM. Affiliates are reportedly offered a 90/10 split, which helps explain the group's recruitment appeal.
Defensive implications
The article highlights edge devices such as VPN appliances, firewalls, Cisco gear, and Fortinet FortiGate as key entry points. It also says the attackers use tools for AD discovery, certificate abuse, privilege escalation, file-share discovery, and defense evasion, plus attempts to disable Microsoft Defender and clear Windows event logs.
PRODAFT says the group asks for at least 1GB of exfiltrated victim data before granting affiliate panel access, a safeguard meant to keep researchers and law enforcement from posing as affiliates. The overall picture is of a well-supported ransomware operation that combines access, extortion, and broad propagation tactics.
Key points
- PRODAFT says The Gentlemen has claimed 478 victims since March 2025.
- The group reportedly moved from using other RaaS programs to running its own operation in July 2025.
- Attackers are said to enter through exposed services or stolen credentials and then use tools for privilege escalation and defense evasion.
- The article says the group can spread like a worm and offers multiple ransomware builds across Windows, Linux, ESXi, XP+, and LVM.
- Only about 13% of victims are in the U.S.; many victims are in Thailand, the U.K., Brazil, Germany, and India.
If defenders act on these findings, organizations can tighten protection around VPNs, firewalls, and identity systems before the group gets in. The detailed breakdown of tools and tactics also gives security teams better signals to detect and block similar attacks sooner.
If the group keeps recruiting affiliates and refining its tooling, it could continue scaling attacks across many sectors and regions. Its worm-like spread and defense-evasion steps could make intrusions harder to contain once an initial foothold is gained.



