The Gentlemen Ransomware Gang Turns Your Own IT Tools Against You

A fast-spreading criminal group is using the software your IT team trusts every day to take over company networks. The real test is not whether they got in. It is what happens next.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A long row of illuminated server racks in a darkened enterprise data centre
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • The Gentlemen is a ransomware-as-a-service operation, meaning it rents attack tools to other criminals, first observed around mid-2025 and confirmed in attacks across six continents.
  • The malware tries up to 21 different methods to spread through a company's internal network before locking any files.
  • Before encrypting data, it disables backup systems and security software, making recovery far harder.
  • Microsoft Threat Intelligence published a technical breakdown of the group in late May 2025, followed by a detailed report from Picus Security.
  • Sectors hit include healthcare, education, transportation and financial services.

Some ransomware groups kick down the front door and make noise. The Gentlemen walk in through the staff entrance using a valid badge.

They don't rely on exotic tricks or newly discovered software flaws. The tools they abuse are the same ones your IT team uses every single day: PsExec, which lets administrators run programs on remote machines; PowerShell, the scripting language baked into almost every modern Windows computer; scheduled tasks; and Windows Management Instrumentation. The malware tries up to 21 different propagation methods per target. If one fails, it moves to the next.

How does this ransomware actually get around inside a company?

Once the criminals break into a single machine, the software enumerates reachable systems, stages a copy of itself through an SMB share (the standard Windows file-sharing protocol), and attempts remote execution. It keeps going until it has spread as far as it can.

Before locking any files, it does something arguably more damaging. It disables Microsoft Defender, deletes shadow copies (the automatic backup snapshots Windows keeps in the background), and stops services tied to databases, backup platforms and endpoint protection tools. By the time file encryption starts, the organisation's ability to detect the attack or recover from it has already been gutted.

Encryption uses a Curve25519 and XChaCha20 hybrid scheme with a unique key per file. There's no single master key a researcher can extract and publish. Picus Security noted that one sample tagged encrypted files with the .umc16h extension, though other campaigns have used different labels. The group also steals data before encrypting it, threatening to publish it if the ransom goes unpaid.

We've been tracking The Gentlemen since our 29 May 2026 story on Microsoft's lateral-movement analysis, and the Picus report confirms the pattern hasn't changed: spread first, encrypt later, cripple recovery in between.

Should you worry about your backups specifically?

Yes, and here's why the standard audit answer is wrong. Organisations buy backup software, tick the compliance box, and assume they're protected. The Gentlemen targets those tools before a single file is locked. If your backups authenticate against the same Active Directory your attackers already control, they're not a safety net. They're part of the attack surface.

IDC's Sakshi Grover, writing in the context of the Picus report, said organisations should test whether recovery systems remain usable during an active compromise, accounting for the possibility that Active Directory or security management consoles may already be offline.

For people whose data sits inside hospitals or financial firms that could be targeted: watch for breach notifications from these organisations, and treat any follow-up emails claiming to be from them with extra suspicion.

If your organisation hasn't tested whether its backups survive a partial network compromise, find that out now. Not during an incident.

© 2026 Threat Vectr