#gentlemen


The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

Jun 19, 2026 // 21:41

The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates […]

Gentlemen ransomware uses multiple EDR killers to disable defenses

Jun 19, 2026 // 01:36

The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. The […]

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

Jun 11, 2026 // 20:07

A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion […]

SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation

Apr 21, 2026 // 23:48

Threat actors associated with The Gentlemen ransomware‑as‑a‑service (RaaS) operation have been observed attempting to deploy a known proxy malware called SystemBC. According to new research […]

The Gentlemen ransomware now uses SystemBC for bot-powered attacks

Apr 21, 2026 // 00:16

A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack […]