Malware
The Gentlemen
- First Reported
- May 11, 2026
- Latest Reported
- Sep 1, 2026
Reported Context (2)
- Counter Threat Unit™ (CTU) researchers identified a consistent post-exploitation playbook used in The Gentlemen ransomware-as-a-service (RaaS) scheme, operated by a threat group that CTU™ researchers track as GOLD Sophos Details GOLD SHERWOOD’s The Gentlemen Ransomware Playbook
- Using this access, they successfully exfiltrated data to a cloud service and then deployed The Gentlemen ransomware. EtherRAT and TukTuk C2 Lead to The Gentlemen Ransomware Deployment
CVE (2)
Malware (2)
People (3)
Threat Actors (1)
MITRE ATT&CK (27)
Vendors (7)
Products (16)
Tools (14)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.