The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm Ravie LakshmananJun 11, 2026Cybercrime / Ransomware A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis). According to a detailed report published by PRODAFT, the group, which it tracks as Phantom Mantis, is led by a Russian-speaking cybercriminal it calls LARVA-368, who goes by the online aliases hastalamuerte, ArmCorp, zeta88, nobody0, and santamuerte. The Gentlemen is known to be active since March 2025, claiming a total of 478 victims to date,…
CVEs: CVE-2024-55591, CVE-2025-32433, CVE-2025-33073, CVE-2026-11645
Original source: thehackernews.com