News Room
16
Share
The Gentlemen Ransomware Group Overtakes Qilin as Global Threat Leader Following Mass FortiGate Exploitation
criticalThreat Intelligence

The Gentlemen Ransomware Group Overtakes Qilin as Global Threat Leader Following Mass FortiGate Exploitation

The Gentlemen RaaS group has claimed 17% of all global ransomware attacks this month, utilizing a dual-threat model that integrates initial access brokerage with automated data exfiltration.

14 July 2026Last updated 20 August 20265 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2024-55591
Source:
Check Point Research
Read Time:
5 min

Executive Summary Over the past 48 hours, threat intelligence reports have confirmed a significant shift in the global ransomware landscape. The Gentlemen, a Ransomware-as-a-Service (RaaS) operation that emerged in mid-2025, has officially overtaken Qilin to become the world’s most active ransomware collective. Data from the last 48 hours shows The Gentlemen were responsible for 17% of all published attacks globally, a surge attributed to their innovative dual-service model. By acting as both a RaaS provider and an Initial Access Broker (IAB), the group has managed to compromise thousands of enterprise environments simultaneously. Most notably, the group has exploited a critical vulnerability in FortiGate devices (CVE-2024-55591) to provide their affiliates with immediate, self-service entry points into high-value corporate networks. ## Threat Analysis The Gentlemen represent a new evolution in cybercrime efficiency. Unlike traditional groups that rely on affiliates to find their own way into a network, The Gentlemen provide a turnkey solution. Affiliates are granted access to pre-exploited enterprise environments through a centralized, dark-web dashboard. This removes the reconnaissance and initial access hurdles, which are typically the most time-consuming phases of a ransomware campaign. The group focuses heavily on Business Services and Industrial Manufacturing, sectors known for high uptime requirements and a greater likelihood of paying ransoms to avoid operational paralysis. Their double-extortion strategy is ruthless, frequently leaking snippets of sensitive data within hours of the initial encryption to accelerate negotiations. ## Technical Details The group’s primary vector involves the exploitation of CVE-2024-55591, a critical vulnerability in Fortinet’s FortiGate firewall and VPN appliances. Once the group secures initial access, they deploy a customized version of the Gentleman’s Suite, a proprietary toolset that automates lateral movement and credential harvesting. Technical analysis of recent intrusions indicates the use of an advanced LLM-integrated script—dubbed JadePuffer—which conducts autonomous Active Directory discovery. By mimicking legitimate administrative traffic, the group successfully bypasses traditional Endpoint Detection and Response (EDR) systems. The ransomware payload itself is written in Rust, optimized for multi-threaded encryption across both Windows and Linux/VMware ESXi environments. Data exfiltration is handled via a private, encrypted tunnel to various S3 buckets, bypassing standard egress monitoring. ## Attribution Assessment While The Gentlemen are a relatively new entity, behavioral analysis and code overlap suggest they are composed of experienced operators from the fragmented remains of the LockBit and ALPHV/BlackCat syndicates. Intelligence suggests the group is likely based in a jurisdiction that provides a safe haven for cybercriminals, potentially Eastern Europe or Russia. The professionalism of their communication portals and the scale of their infrastructure indicate substantial financial backing and a highly disciplined organizational structure. However, unlike previous big game hunters, The Gentlemen operate with a degree of anonymity that suggests they are consciously avoiding the public profile that led to the law enforcement takedowns of their predecessors. ## Implications The rise of The Gentlemen marks a dangerous trend toward the industrialization of initial access. By providing affiliates with ready-to-use backdoors, the barrier to entry for conducting high-impact ransomware attacks has been significantly lowered. The 34% increase in cyberattacks across the UK and North America in the last 48 hours is directly tied to this automated access model. Furthermore, the integration of autonomous AI tools for internal reconnaissance means that the dwell time between initial breach and full-scale encryption is shrinking from days to mere hours, leaving security teams with almost no time to react. ## Recommendations Encrygma recommends the following immediate actions: 1. Patch and Audit: Prioritize the immediate patching of all FortiGate devices to address CVE-2024-55591 and conduct a forensic audit for existing indicators of compromise (IOCs). 2. Network Segmentation: Implement strict micro-segmentation to prevent the lateral movement observed in recent Gentlemen attacks. 3. MFA Enforcement: Transition all remote access to phishing-resistant Multi-Factor Authentication (MFA), as the group heavily utilizes compromised session tokens. 4. AI-Driven Monitoring: Deploy behavioral-based anomaly detection that can identify the subtle patterns of AI-automated reconnaissance scripts. 5. Backup Resilience: Ensure all critical data is backed up to immutable, offline storage that is physically or logically separated from the primary network.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo