Skip to content
You can now search across every topic, entity and event.What's new
The Gentlemen
OrganisationZZ

The Gentlemen

RaaS operation offering affiliates 90% revenue share; second-most-active globally as of May 2026.

The Gentlemen split from Qilin's own affiliate programme around 22 July 2025 over a payment dispute, and by early August 2026 leak-site tracking briefly put it ahead of its former parent.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Is The Gentlemen about to overtake the world's most active ransomware group?

Timeline for The Gentlemen

#12 2 Aug

Posted 31 leak-site victims between 24 July and 3 August, more than Qilin

Cybersecurity: Threats and Defences: Qilin's own affiliate now outposts it
#3 19 Apr

KB5091157, Gentlemen C2 intel, ENISA CNAs: in brief

Cybersecurity: Threats and Defences
View full timeline →

Background

The Gentlemen is a ransomware-as-a-service (RaaS) operation that emerged from inside Qilin's own affiliate programme, under the handle ArmCorp, splitting off around 22 July 2025 after a dispute over roughly $48,000 in unpaid revenue share; a Windows ransomware sample from the new operation had already appeared on VirusTotal five days earlier, on 17 July 2025. Group-IB, the Singapore-based investigations firm, documented the split on 19 March 2026 and put the group at roughly 20 members .

Group-IB puts the affiliate share at 70 to 80 per cent; ransomware.live's leak-site tracker profile puts it at 90 per cent, either figure among the highest reported in the ransomware-as-a-service market. The two figures rest on different evidentiary bases, Group-IB's investigative analysis against a leak-site aggregator's self-reported figures, and this page reports both rather than averaging or picking one.

By 6 May 2026, Check Point Research had identified the group as the second-most-active ransomware operation globally after infiltrating a SystemBC command server used by its affiliates, surfacing 1,570 confirmed victims . Leak-site postings between 24 July and 3 August 2026 put The Gentlemen ahead of Qilin, 31 claims to 19, though that is a ten-day scrape from one tracker set against a different counting basis, an unconfirmed lead rather than a settled overtake.

Common Questions
How many victims does The Gentlemen ransomware group have?
Check Point Research identified at least 1,570 confirmed victims after gaining visibility into a SystemBC C2 server used by The Gentlemen, as of May 2026.Source: Check Point Research
Why is The Gentlemen ransomware growing so fast?
The group offers affiliates 90% of ransom receipts — significantly above the 60–80% industry norm — attracting experienced ransomware operators and access brokers quickly.Source: Check Point Research
What is SystemBC and how does The Gentlemen use it?
SystemBC is proxy malware that tunnels C2 traffic to evade network detection. The Gentlemen uses it to maintain persistent access to victim networks and coordinate ransomware deployment.Source: Check Point Research
Who is behind The Gentlemen ransomware group?
The group's operators have not been publicly identified or attributed to a nation-state. It operates as a RaaS with anonymous affiliates accessing the platform in exchange for sharing ransom proceeds.
Source Material