
Qilin and TheGentlemen Lead Global Ransomware Surge Targeting Critical Infrastructure and Professional Services
A coordinated wave of ransomware attacks on September 1, 2026, has impacted organizations across the UK, US, and Bhutan, with Qilin and TheGentlemen emerging as the primary aggressors.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Unit 42
- Read Time:
- 4 min
Executive Summary
On September 1, 2026, global threat intelligence monitors recorded a significant spike in ransomware activity, characterized by a coordinated series of attacks against diverse sectors. The Qilin ransomware group, continuing its aggressive 2026 campaign, successfully breached multiple European entities, including Absolute Consultancy Services and Alter Consultores Legales. Simultaneously, the emerging threat actor known as 'TheGentlemen' launched a multi-pronged offensive against U.S. and U.K. targets, including Nutex Health and CareerSource Palm Beach County. These incidents underscore a persistent shift toward high-volume, double-extortion tactics targeting professional services and critical infrastructure.
Threat Analysis
The current surge highlights the operational maturity of Ransomware-as-a-Service (RaaS) models in late 2026. Qilin (also known as Agenda) remains a dominant force, leveraging its Rust-based architecture to bypass traditional signature-based detection. Their focus on legal and IT consultancy firms suggests a strategic intent to harvest sensitive client data for secondary extortion. Meanwhile, TheGentlemen group has demonstrated a rapid escalation in victim volume, claiming four major organizations in a single 24-hour window. This group appears to prioritize sectors with high data sensitivity but potentially lower defensive maturity, such as regional healthcare providers and real estate development firms like the Adkisson Group.
Technical Details
Recent telemetry indicates that Qilin affiliates are increasingly utilizing sophisticated living-off-the-land (LotL) techniques to maintain persistence. Initial access is frequently gained through compromised VPN credentials or exploited vulnerabilities in edge devices. Once inside, the actors deploy a Go-based variant of their encryptor, which features enhanced multi-threading for faster encryption of large network shares. TheGentlemen group, conversely, has been observed using a combination of Cobalt Strike beacons and custom PowerShell scripts for lateral movement. Both groups strictly adhere to the double-extortion playbook, exfiltrating data via Rclone to cloud storage providers before initiating the encryption phase.
Attribution Assessment
Encrygma analysts attribute the European activity with high confidence to the Qilin RaaS collective, based on the use of their unique leak site infrastructure and encryption headers. TheGentlemen is currently classified as an emerging cybercriminal syndicate, likely composed of former affiliates from defunct groups like LockBit or Black Basta, given their operational similarities. The attack on JSW Law in Bhutan by the Krybit group and VIVOTEK by Everest further illustrates the fragmented but highly active nature of the current threat landscape.
Implications
The targeting of IT support firms like Absolute Consultancy Services poses a significant supply-chain risk, as attackers may use these breaches to pivot into the networks of downstream clients. Furthermore, the continued focus on healthcare (Nutex Health) during a period of high regional demand increases the likelihood of ransom payments to avoid operational downtime. The geographic spread—from Bhutan to Canada—indicates that no region is currently immune to these high-velocity campaigns.
Recommendations
Organizations must prioritize the implementation of phishing-resistant Multi-Factor Authentication (MFA) across all external-facing services. We recommend immediate audits of VPN logs for anomalous connection patterns and the deployment of advanced Endpoint Detection and Response (EDR) solutions configured to block unauthorized Rclone activity. Regular, offline, and immutable backups remain the most effective defense against total data loss during encryption events.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Qilin Ransomware Group Escalates Extortion Tactics Targeting U.S. Federal Agency ATF

Qilin Ransomware Group Escalates Operations with Federal ATF Breach and Global Enterprise Extortion Campaign

