Malware/Ransomware
The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
Cyber RTJune 11, 20263 min read

The Gentlemen, a financially motivated threat group, evolved from an affiliate of ransomware-as-a-service (RaaS) schemes to an independent operation led by Russian cybercriminal LARVA-368. Known for double extortion attacks, the group uses advanced ransomware techniques and AI for development. Active since March 2025, they target global organizations, focusing on VMware infrastructure. The group employs aggressive profit-sharing and sophisticated intrusion tactics, leveraging vulnerabilities in major software platforms.
The Gentlemen operation, a financially motivated threat group, initially functioned as an affiliate conducting double extortion attacks utilizing resources from various ransomware-as-a-service (RaaS) schemes such as LockBit, Qilin, and Medusa. According to a report by PRODAFT, this group, tracked as Phantom Mantis, is led by a Russian-speaking cybercriminal known as LARVA-368. The group has been active since March 2025 and has claimed 478 victims to date, as per Ransomware.Live data.
In July 2025, Phantom Mantis evolved into The Gentlemen, an independent partnership program, no longer reliant on other RaaS groups. LARVA-368 heavily employs artificial intelligence for developing and maintaining ransomware and tools, as well as for post-exploitation procedures. Before launching The Gentlemen, LARVA-368 was part of the Embargo ransomware group, later rebranding their operation from ArmCorp to The Gentlemen.
Cybersecurity journalist Brian Krebs identified LARVA-368 as Alexander Andreevich Yapaev from Izhevsk, Russia. PRODAFT corroborated this identification with high confidence. The transition to The Gentlemen coincided with a payment dispute between LARVA-368 and Qilin, where LARVA-368 accused Qilin of an exit scam, defrauding them of $48,000. This dispute highlighted tensions within the ransomware community.
Phantom Mantis was a highly active affiliate group, with over 20 targets registered in less than 30 days. However, LARVA-368 and a former member, LARVA-367, accused Pestilent Mantis of scamming affiliates and claimed there was a backdoor within its affiliate panel victim chats. Although these claims remain unconfirmed, there is speculation that LARVA-368 and LARVA-367 spread disinformation to recruit affiliates from Pestilent Mantis.
The Gentlemen group has been observed enhancing their visibility on underground forums by paying for Premium accounts. Their communication and technical support are managed by a separate Russian-speaking persona named The Gentlemen Data. The group employs a highly adaptive ransomware operation, combining mature ransomware techniques with RaaS features, double extortion, and cross-platform lockers.
The Gentlemen has emerged as a significant threat actor, responsible for 10% of ransomware activity in April 2026. Their operations focus on enterprise targets, utilizing vulnerable internet-facing services or stolen credentials for initial access. The group adapts tactics during attacks, manipulating GPOs, compromising privileged accounts, and using custom methods to bypass endpoint protections.
LARVA-368 uses The Gentlemen IM app accounts to support affiliates, providing tools like EDR killers to bypass security solutions. Affiliates must provide at least 1GB of exfiltrated data to gain access to the affiliate panel, preventing unauthorized access by researchers or law enforcement. The group offers five versions of ransomware for different systems and employs a profit-sharing model favoring affiliates.
The Gentlemen's attacks involve sophisticated techniques, including using red team utilities for Active Directory discovery and privilege escalation, as well as tools for evading security programs. Microsoft tracks the group under Storm-2697, noting their use of a hybrid cryptographic scheme and self-propagating worm capabilities. The group runs a multi-channel extortion operation, combining ransomware attacks with email and phone-based pressure tactics. Recent leaks have provided insights into their operations, revealing a well-organized criminal enterprise with clear roles and responsibilities.


