# The Gentlemen Ransomware: From RaaS Affiliate to Worm-Like Threat Accounting for 10% of Global Attacks
A detailed investigation by Swiss cybersecurity firm PRODAFT has exposed the anatomy of The Gentlemen ransomware operation—a threat group that evolved from a service-dependent affiliate into an independent, AI-augmented ransomware empire claiming 478 victims and representing 10% of all ransomware activity as of April 2026.
## The Threat
The Gentlemen operates as a financially motivated ransomware group deploying double extortion attacks against enterprise targets worldwide. What distinguishes this operation from traditional ransomware campaigns is its worm-like propagation capability—the ability to spread laterally across networks with minimal human intervention—combined with adaptive attack techniques that allow threat actors to modify their tactics mid-compromise.
The group targets organizations primarily through vulnerable internet-facing services or stolen credentials, establishing footholds that evolve into enterprise-wide compromise. Once inside, operators demonstrate sophisticated post-exploitation tradecraft: manipulating Group Policy Objects (GPOs) to disable security controls, compromising privileged accounts, and deploying custom methods to bypass endpoint protection systems.
The ransomware itself has been characterized as "highly adaptive and fast-moving," capable of targeting multiple platforms and working in concert with flexible affiliate support structures. This combination makes The Gentlemen a particularly dangerous threat to organizations lacking robust network segmentation and access controls.
## Background and Context: From Affiliate to Independent Operator
The Gentlemen's operational timeline reveals a critical inflection point in how ransomware-as-a-service (RaaS) ecosystems function:
March 2025: LARVA-368, a Russian-speaking cybercriminal based in Izhevsk, Russia, launches operations under the alias ArmCorp, initially operating as an affiliate of established RaaS platforms including LockBit, Qilin, and Medusa—schemes PRODAFT identifies as Tenacious Mantis, Pestilent Mantis, and Venomous Mantis respectively.
July 2025: Following a payment dispute with Qilin—during which LARVA-368 accused the RaaS operation of conducting an exit scam and defrauding them of $48,000—the group rebrands to The Gentlemen and transitions to independent operations. This shift marks a critical moment: rather than remaining dependent on external RaaS infrastructure, The Gentlemen establishes itself as a standalone partnership program.
August 2025 onward: LARVA-368, supported by co-operator DevMan (LARVA-367), allegedly spreads disinformation claiming Qilin maintains backdoors in its affiliate panel—potentially a recruitment tactic to siphon other affiliates toward their emerging operation. The group invests in visibility, purchasing Premium accounts on underground forums and establishing The Gentlemen IM as a dedicated communication and support channel.
Operator Identity: Cybersecurity journalist Brian Krebs identified LARVA-368 as Alexander Andreevich Yapaev (Япаев Алексанр Андреевич), 36, from Izhevsk. PRODAFT confirmed this attribution with high confidence. Prior to launching ArmCorp, Yapaev was assessed to have been a member of the Embargo ransomware group.
## Technical Details: How The Gentlemen Operates
The group's operational approach reflects both mature ransomware technique and emerging technological leverage:
| Attack Component | Capability |
|---|---|
| Initial Access | Vulnerable internet-facing applications; credential theft from prior breaches |
| Lateral Movement | Worm-like propagation; GPO manipulation; privilege escalation |
| Persistence | Custom methods designed to evade endpoint protection |
| Encryption | Multi-platform ransomware (Windows, potentially others) |
| Extortion | Double extortion model: encrypt data + exfiltrate files for extortion leverage |
| Affiliate Support | Structured partnership program with dedicated support channels |
### AI-Driven Development
A notable capability distinguishing The Gentlemen is its heavy reliance on artificial intelligence for:
This suggests the operation has industrialized its development process, reducing dependency on specialized expertise and accelerating innovation cycles—a troubling evolution in how ransomware groups leverage emerging technologies.
## Scale and Impact: 478 Victims Across Five Continents
According to Ransomware.Live, The Gentlemen has claimed 478 victims as of June 2026—a substantial number given the group's independent operations began only 11 months prior. This figure understates actual impact, as victims who pay ransoms often avoid public disclosure.
### Geographic Distribution
The victim distribution reveals a globally dispersed targeting pattern:
This concentration outside North America suggests either deliberate targeting selection (avoiding U.S. law enforcement scrutiny) or exploitation of specific vulnerabilities prevalent in these regions. The relative underrepresentation of U.S. targets may also reflect U.S. organizations' greater likelihood to report and seek law enforcement assistance.
### Activity Intensity
By April 2026, The Gentlemen accounted for approximately 10% of all ransomware activity globally—a remarkable market share for an operation that transitioned to independence only nine months prior. This metric reflects both aggressive affiliate recruitment and successful campaign execution.
## Implications for Organizations
The Gentlemen's operational profile presents specific challenges for enterprise defenders:
Adaptive Tactics: Unlike formulaic ransomware deployments, The Gentlemen actively modifies attack strategies in response to observed defenses—a hallmark of sophisticated threat actors with both resources and expertise to iterate.
Worm-Like Propagation: The ability to spread autonomously across networks reduces dwell time detection windows and accelerates compromise scope, making early detection and containment exponentially more critical.
Supply Chain Vulnerability: Targeting internet-facing services means organizations with minimal perimeter monitoring or unpatched external-facing infrastructure face acute risk.
Privilege Exploitation: The group's focus on compromising privileged accounts suggests organizations with inadequate identity and access management are particularly vulnerable.
---
## HackWire Analysis: The Structural Shift in Ransomware Economics
The Gentlemen's evolution from RaaS affiliate to independent operation reflects a troubling structural shift in the cybercrime ecosystem. This isn't simply one group's rebranding—it signals a maturation pattern where experienced threat actors, having built expertise within RaaS frameworks, increasingly exit to establish competing platforms.
What makes this transition particularly significant is the role of payment disputes and perceived fraud within RaaS networks. LARVA-368's public accusations against Qilin—whether genuine or disinformation—exploit a fundamental weakness in the RaaS model: affiliates depend entirely on administrators' honesty and security practices. When that trust fractures, sophisticated actors with existing recruitment networks predictably migrate to independence.
The Gentlemen's AI-driven development represents a second-order threat escalation often overlooked in initial reporting. This isn't simply faster code generation—it's the industrialization of ransomware operations, reducing technical skill barriers and enabling smaller teams to maintain parity with established groups. LARVA-368 can operationalize novel evasion tactics without hiring specialized reverse engineers.
The geographic victim concentration—Thailand, UK, Brazil, Germany, India—suggests either deliberate targeting of regions with weaker cybersecurity enforcement or opportunistic exploitation of vertical-specific vulnerabilities. Organizations in these regions should treat The Gentlemen as a primary threat; organizations outside should recognize they operate in a global market where incidents abroad inform attacker techniques deployed domestically.
For defenders, the critical implication is clear: worm-like propagation + adaptive tactics + AI-driven development = compressed incident response timelines. Organizations cannot rely on detection windows measured in hours; they require detection measured in minutes, backed by network segmentation that assumes compromise will occur. The era of detecting ransomware by behavioral anomalies is ending; the era of designing networks to withstand lateral movement before detection must accelerate. — *HackWire Editorial*
---
## Recommendations for Enterprise Defenders
Organizations targeted by The Gentlemen or similar operations should prioritize:
1. Immediate Vulnerability Assessment: Inventory all internet-facing services; patch actively exploited vulnerabilities within 48 hours; disable unnecessary exposed ports.
2. Network Segmentation: Implement zero-trust segmentation preventing lateral movement; segment by data sensitivity and system criticality; test segmentation monthly.
3. Credential Hygiene: Enforce multi-factor authentication on all privileged accounts; implement passwordless authentication where feasible; audit and revoke dormant accounts monthly.
4. EDR and Detection: Deploy endpoint detection and response tools tuned to detect living-off-the-land techniques and GPO manipulation; enable behavioral analytics on privilege account activity.
5. Incident Response Preparation: Maintain detailed network topology documentation; conduct tabletop exercises assuming 30-minute detection windows; establish ransomware-specific playbooks.
6. Backup Strategy: Implement immutable, air-gapped backups; test restoration procedures quarterly; maintain backups for 90+ days to counter ransomware with extended encryption delays.
---
## Related Coverage