Last updated 1 month ago
Check Point Research published an analysis of The Gentlemen ransomware-as-a-service (RaaS) operation, which emerged around mid-2025. The group advertises its platform on underground forums, recruiting affiliates including penetration testers and technically skilled actors. As of 2026, victims are listed on the group's data leak site (DLS), indicating active targeting and extortion.
The attack chain involves affiliates deploying the ransomware payload, likely through initial access vectors such as phishing or vulnerability exploitation, though specific techniques are not detailed in the summary. The ransomware encrypts victim systems and exfiltrates data for double extortion, with the DLS used to pressure non-paying victims. No specific CVEs or MITRE ATT&CK techniques are cited in the article summary.
No post-incident details such as regulatory actions, litigation, ransom payments, or containment milestones are provided in the article summary.
Ransomware-as-a-service operation targeting victims via affiliates
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Threat Actor