Thegentlemen

Active
The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
867 Victims
Feb 28, 2023 First Discovered
Sep 14, 2026 Last Discovered
2 Days Inactive
0% Infostealer
1/2 Sites Online
Known Locations (2)
i2ohjeeqe37jre4f2u7pyq73cbm6lecumdxapkvrlryna6rc3it4zsid.onion
Gentlecloud Protection
tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion
Tools Used
CredentialTheft
DumpBrowserSecrets, Hydra, KslDump, KslKatz, XenAllPasswordPro
DefenseEvasion
EDRStartupHinder, GFreeze, GLinker
DiscoveryEnum
ADFind, BloodHound, Censys, CertiHound, MANSPIDER, PowerZure, Shodan, gogo scanner, ldapdomaindump
Exfiltration
rclone
Networking
Chisel-ng, ProxyChains, Tor / Onion C2, openconnect
Offsec
Custom Go Locker (Windows/Linux/NAS), NetExec (nxc), PetitPotam, PrivHound, RegPwn, RelayKing, Responder, TrustedSec Titanis, Velociraptor, ZeroPulse, ntlmrelayx
RMM-Tools
AnyDesk
Intelligence
Victims (867)

Detailed victim list temporarily unavailable

This group has 867 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.