Gentlemen Ransomware‑as‑a‑Service Escalates with 90% Affiliate Payout, Targeting 580 Victims in 77 Countries
What Happened — The “Gentlemen” ransomware‑as‑a‑service (RaaS) operation, active since mid‑2025, has claimed 580 victims across 77 nations, offering affiliates a 90 % ransom share. The group employs a mix of edge‑device exploits, brute‑force credential attacks, a custom Go‑based backdoor (“GentleKiller”), and an alleged zero‑day to evade detection.
Why It Matters for Compliance & Audit Readiness
- The attack chain hinges on weak access controls and credential reuse—exactly the controls SOC 2 CC6.1 (Logical Access) is designed to protect.
- Continuous evidence of privileged‑access monitoring and MFA enforcement is essential to demonstrate due‑diligence during an audit.
- Security‑awareness training that covers phishing, credential‑theft tactics, and ransomware response is a required component of the SOC 2 CC7.2 (Security Awareness) control set.
Who Is Affected – Manufacturing, hospitality, retail, and other sectors that rely on legacy firewalls, VPNs, and un‑hardened endpoints.
Recommended Actions
- Review and tighten logical‑access policies: enforce MFA, least‑privilege, and regular credential rotation.
- Deploy continuous monitoring for anomalous login attempts and backdoor activity (e.g., EDR‑killer frameworks).
- Conduct organization‑wide security‑awareness training focused on ransomware and credential‑theft techniques.
Technical Notes – The ransomware is written in C and Go, enabling cross‑platform deployment. Initial access vectors include firewall/VPN vulnerabilities, brute‑force attacks, stolen credentials, and a suspected zero‑day exploit. The group also runs a custom Go backdoor (“GentleKiller”) that disables endpoint detection and response tools. Source: Palo Alto Unit 42