The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. The operators advertise their services across multiple underground forums, promoting their ransomware platform and inviting penetration testers (and other technically skilled actors) to join as affiliates.
The RaaS provides affiliates with multi‑OS lockers for Windows, Linux, NAS, BSD imp...
The Gentlemen RaaS operation exemplifies the evolving sophistication of cybercriminal ecosystems, where modular tools, affiliate recruitment, and adaptive tactics create resilient attack chains. The use of SystemBC and Cobalt Strike highlights a trend toward hybrid malware deployment, blending off-the-shelf tools with custom ransomware. The group’s reliance on Tox for negotiations and public shaming via Twitter/X underscores the psychological pressure tactics central to modern ransomware operati...
