Skip to content
You can now search across every topic, entity and event.What's new
VirusTotal
ProductUS

VirusTotal

A Google-owned malware and file-scanning aggregation platform.

VirusTotal is Google's file and URL scanning platform, where a Windows ransomware sample from The Gentlemen's new operation appeared on 17 July 2025, five days before its split from Qilin.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

What did a VirusTotal upload reveal about The Gentlemen's split from Qilin?

Timeline for VirusTotal

#12 2 Aug

Mentioned in: Qilin's own affiliate now outposts it

Cybersecurity: Threats and Defences
View full timeline →

Background

VirusTotal is a Google-owned platform that aggregates dozens of antivirus and malware-scanning engines to check submitted files and URLs against known threat signatures. Researchers and defenders widely use it both to check suspicious files and to trace when particular malware samples first surfaced publicly.

It appears on this beat as an evidentiary marker rather than a party to any incident: a Windows ransomware sample tied to The Gentlemen, the ransomware operation that split from Qilin's affiliate programme, was uploaded to VirusTotal on 17 July 2025, five days before Group-IB's documented split date of 22 July 2025.

That timestamp is used by researchers to help date the operation's tooling independently of the actors' own claims, illustrating VirusTotal's role as a shared evidentiary resource across many unrelated threats, not a fact specific to this one campaign.

Common Questions
What is VirusTotal?
VirusTotal is a Google-owned platform that aggregates dozens of antivirus engines and file-reputation feeds to check whether a file or URL is malicious.Source: Group-IB, via ransomware.live tracking
When did a Gentlemen ransomware sample first appear on VirusTotal?
A Windows ransomware sample from the operation that became The Gentlemen appeared on VirusTotal on 17 July 2025, five days before its operator's public split from Qilin's affiliate programme.Source: Group-IB
Why does a VirusTotal upload date matter for ransomware attribution?
It shows the operator had already built The Gentlemen's own ransomware locker before formally splitting from Qilin, indicating the defection was planned rather than a snap decision.Source: Group-IB