The Gentlemen: A RaaS Affiliate That Grew Up and Wrote Its Own Worm
A double-extortion crew that started out renting LockBit, Qilin, and Medusa lockers has graduated to its own toolkit — including a payload with self-propagation.

The Gentlemen did not arrive fully formed. Before they were claiming 478 victims on a leak site, they were just another affiliate, paying rent to bigger ransomware-as-a-service brands and running the standard double-extortion playbook: steal first, encrypt second, post to the blog if the wire doesn't clear.
A new technical writeup pieces together the group's evolution from RaaS tenant to independent operator with custom tooling. Early activity links the crew to lockers from LockBit (tracked as Tenacious Mantis), Qilin (Pestilent Mantis), and Medusa (Venomous Mantis). That is a fairly cosmopolitan affiliate résumé, and it matches a pattern we have seen across the ecosystem since LockBit's takedown — operators do not retire, they just switch landlords.
What makes The Gentlemen worth paying attention to now is the worm behavior.
The group's current payload is built to spread laterally on its own once it lands inside an environment, rather than relying purely on the operator-driven, hands-on-keyboard lateral movement that defines most modern ransomware intrusions. That is a deliberate design choice. Hands-on intrusions are stealthier, but slower. A self-propagating payload trades stealth for blast radius, which is a very 2017 idea dressed in 2024 clothes. If you remember WannaCry and NotPetya, you already understand the threat model. The novelty is not the worm primitive. It is a financially motivated affiliate-turned-operator deciding the math now favors speed.
The victim count — 478 named on the leak infrastructure — should be read with the usual skepticism applied to ransomware blogs. Leak sites are marketing. Crews relist victims, inherit names from defunct brands, and occasionally invent entries to pad the board. Even discounted, the volume suggests a working operation with real intrusion capacity rather than a vanity project.
On the defender side, none of the initial-access tradecraft described in the analysis is exotic: exposed remote services, credential reuse, post-exploitation via standard living-off-the-land binaries, exfiltration to commodity cloud storage before encryption. The worm component changes triage, not prevention. Once it is loose inside a flat network, the response window collapses, and segmentation that looked merely adequate during tabletop exercises will be doing actual work.
A few things worth watching:
- Whether The Gentlemen begin offering their own affiliate program, which is the natural next step for a crew with custom tooling and brand recognition.
- Whether other former LockBit affiliates converge on similar self-propagating designs, or whether this remains a one-off.
For now, treat The Gentlemen as what they appear to be: a competent mid-tier crew that learned the trade on someone else's locker, kept the contact lists, and decided the margins were better in-house. The interesting question is not whether they are dangerous. It is what the next graduate of the RaaS apprenticeship system brings to market.



