Classification: TLP:CLEAR | Publication Date: 2026-10-10 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
THEGENTLEMEN Ransomware Gang: 33 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules
Executive Summary
Security Arsenal's dark web monitoring of the THEGENTLEMEN ransomware gang's .onion leak site, aggregated via ransomware.live, shows 33 organizations listed in the gang's most recent 100 postings. The listings cluster heavily around the United States, with additional claimed victims in India, France, Taiwan, the Czech Republic, Canada, Australia, and Oman. Healthcare and Professional Services are the most represented sectors, followed by Hospitality, Manufacturing, Education, and Energy & Utilities.
Notable organizations the gang claims to have compromised and has listed on its leak site include Deloitte (Professional Services, US — listed 2026-10-09), North Philadelphia Health System (Healthcare, US — listed 2026-10-07), Majestic Holidays India Private Limited (Hospitality, IN), All Smiles Dental of Falls Church (Healthcare, US), The Law Office of James R Walsh (Professional Services, US), Potomac Animal Hospital (Healthcare, US), Alcoholics Anonymous (Healthcare, US), Ability Enterprise (TW), Machine sro (Manufacturing, CZ), Northwestern Polytechnic (Education, CA), Rag Electric (Energy & Utilities, US), and All Souls St Gabriels School (Education, AU), among others.
Every listing is an unverified accusation by a criminal actor. None of these postings has been corroborated by a second independent leak-site crawler, and no listing — corroborated or not — constitutes confirmation of a breach. Organizations named in this briefing, or those in the same sectors, should treat this as a prompt to verify their own exposure rather than as confirmation that any specific incident occurred.
Sourcing & Verification
- Of the 33 listings reviewed, 0 were independently observed by a second leak-site crawler; all 33 are single-source, meaning they appear on ransomware.live only. A single-source designation means we cannot even confirm the posting itself was independently witnessed, let alone that the underlying claim is true.
- Inclusion in this briefing reflects the threat actor's claim and is NOT confirmation of a breach. No corroboration tier in our data confirms a breach — only the affected organization or its regulator can do that.
- A named organization may dispute the listing. A denial is likewise not proof the claim is false: disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question.
- Security Arsenal will publish corrections to this briefing as warranted and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — THEGENTLEMEN
The following profile is based on open-source reporting and underground monitoring. Where firm attribution is uncertain, we say so.
- Aliases / branding: The group operates publicly under the name THEGENTLEMEN (also rendered "The Gentlemen" in some tracker listings). No definitively confirmed rebrand lineage to a prior crew has been established in public reporting; treat claimed pedigrees circulating on forums with skepticism.
- Operating model: Assessed as a Ransomware-as-a-Service (RaaS) operation or RaaS-adjacent crew based on victim diversity and posting cadence, though some analysts treat it as a closed group. The breadth of sectors and geographies in a single posting wave is consistent with multiple affiliates operating under one brand.
- Ransom demands: Observed demands against comparable mid-market victims in this gang's weight class typically range from the low six figures to low seven figures USD, scaled to victim revenue. Specific demand figures for the current wave are not confirmed.
- Initial access methods (assessed): Consistent with peer groups of this profile: spear-phishing with macro- or script-laden attachments, exploitation of internet-facing VPN and remote access gateways, exposed RDP (often via purchased access from initial access brokers), and abuse of remote monitoring & management (RMM) tooling. See the CVE section below for currently exploitable edge-device exposure.
- Extortion model: Double extortion — exfiltration first, encryption second, with a leak-site countdown to pressure payment. The leak site is the primary coercion mechanism, which is why leak-site monitoring (as in this briefing) provides early warning.
- Dwell time: Groups in this class typically dwell 1–3 weeks between initial access and detonation, using the interval for privilege escalation, lateral movement, and data staging. This dwell window is the defender's opportunity — the T-minus checklist below is built around it.
Current Campaign Analysis
Sector Targeting
From the last 100 postings (33 with sector tags in our dataset):
| Sector | Example listings (claimed, unverified) |
|---|---|
| Healthcare | North Philadelphia Health System, All Smiles Dental of Falls Church, Potomac Animal Hospital, Alcoholics Anonymous |
| Professional Services | Deloitte, The Law Office of James R Walsh |
| Hospitality | Majestic Holidays India Private Limited |
| Manufacturing | Machine sro (CZ) |
| Education | Northwestern Polytechnic (CA), All Souls St Gabriels School (AU) |
| Energy & Utilities | Rag Electric (US) |
| Other / Not Found | Mabris (FR), Ability Enterprise (TW), Polishing Proz, Maverick Desk |
The skew toward healthcare and professional services is notable: both hold high-density regulated data (PHI, client-privileged legal/financial records) that maximizes extortion leverage, and both contain many mid-sized organizations with weaker SOC coverage than their data sensitivity warrants.
Geographic Concentration
The United States dominates the wave, with secondary listings in India, France, Taiwan, Czech Republic, Canada, Australia, and Oman. This spread — 8 countries across a short posting window — is consistent with an affiliate model rather than a geographically focused crew.
Victim Profile
The named organizations span a wide size range: from small local entities (a dental practice, a solo law office, a regional electric contractor) to a Big Four professional services firm (Deloitte — again, a claim, not a confirmed breach). The bulk of the wave fits the classic ransomware mid-market sweet spot: organizations large enough to pay, small enough to lack 24/7 detection. Estimated revenue range across the wave: roughly $1M to enterprise-scale, with the median likely in the $5M–$100M band based on sector norms.
Posting Frequency & Escalation
A concentrated batch of 14+ listings published on 2026-10-06 alone, followed by additional postings on 2026-10-07 and 2026-10-09, suggests either a batch-dump of intrusions executed over prior weeks or a deliberate cadence to maximize attention. Batch posting of this kind often precedes a negotiation-deadline escalation cycle.
CVE Exposure — Hypothesis, Not Attribution
We have no evidence linking any specific named listing to any specific CVE. However, the gang's assessed initial-access profile (edge devices, remote access, management plane) overlaps heavily with currently exploited vulnerabilities in the CISA KEV catalog, all confirmed as ransomware-exploited:
- CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Direct VPN-edge initial access. Patch/mitigate immediately if your gateway is exposed.
- CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Management-plane compromise enables policy tampering and lateral movement.
- CVE-2026-59310 — VMware vCenter path traversal. Post-foothold pivot to the virtualization layer — catastrophic in ransomware scenarios because it enables mass VM encryption.
- CVE-2026-63077 — JetBrains TeamCity deserialization. Build-server compromise enables supply-chain-style payload distribution and credential theft.
- CVE-2026-48027 — Nx Console embedded malicious code. Developer-workstation supply chain exposure.
Defensive framing: if your organization matches this gang's sector profile (healthcare, professional services, education, manufacturing, energy) and runs any of the above products unpatched, you are in the probable targeting envelope. Patch on KEV timelines, not change-window timelines.
Detection Engineering
The following detections target the TTP cluster associated with this gang's assessed playbook: edge/VPN initial access, phishing macro execution, RDP abuse, PsExec/WMI lateral movement, and pre-encryption data staging.
---
title: THEGENTLEMEN - PsExec-Style Remote Service Creation for Lateral Movement
id: 8f3a1b22-7c4d-4e91-a510-tg0001
status: production
description: Detects creation of remote services with names/paths consistent with PsExec-style tooling used for lateral movement and ransomware mass-deployment by THEGENTLEMEN-class actors.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection:
selection_cmd:
CommandLine|contains:
- ' \\127.0.0.1\ADMIN$'
- ' \\localhost\ADMIN$'
selection_svc:
Image|endswith:
- '\PSEXESVC.exe'
- '\RemComSvc.exe'
- '\paexec.exe'
- '\csexec.exe'
condition: selection_cmd or selection_svc
falsepositives:
- Legitimate admin tooling — baseline approved deployment tools
level: high
tags:
- attack.lateral_movement
- attack.t1569.002
date: 2026/10/10
---
title: THEGENTLEMEN - Office Macro Spawning Script or LOLBin Child Process
id: 8f3a1b22-7c4d-4e91-a510-tg0002
status: production
description: Detects Office applications spawning script interpreters or LOLBins, consistent with phishing-macro initial access chains.
author: Security Arsenal Threat Intelligence
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\outlook.exe'
- '\mspub.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\cmd.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\regsvr32.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate macro workflows — tune by parent/child hash and signer
level: high
tags:
- attack.initial_access
- attack.t1566.001
- attack.t1059
date: 2026/10/10
---
title: THEGENTLEMEN - Pre-Encryption Staging - Mass Archive Creation Followed by Shadow Copy Deletion
id: 8f3a1b22-7c4d-4e91-a510-tg0003
status: production
description: Detects the classic pre-ransomware sequence of bulk archive creation (exfil staging) combined with Volume Shadow Copy deletion (anti-recovery), observed in double-extortion playbooks.
author: Security Arsenal Threat Intelligence
logsource:
category: process_creation
product: windows
detection:
selection_archive:
- Image|endswith:
- '\rar.exe'
- '\7z.exe'
- '\winrar.exe'
- CommandLine|contains:
- ' a -r '
- ' a -hp'
selection_vss:
CommandLine|contains:
- 'vssadmin delete shadows'
- 'vssadmin Delete Shadows'
- 'wmic shadowcopy delete'
- 'bcdedit'
- 'recoveryenabled no'
- 'wbadmin delete catalog'
condition: 1 of selection_archive or 1 of selection_vss
timeframe: 30m
falsepositives:
- Backup administrators — alert on conjunction across hosts, tune known backup accounts
level: critical
tags:
- attack.impact
- attack.t1490
- attack.t1560.001
- attack.exfiltration
date: 2026/10/10
// THEGENTLEMEN hunt: lateral movement + pre-encryption staging (Microsoft Sentinel)
// Looks for: suspicious service installs, SMB admin-share writes, archive staging,
// and shadow copy tampering correlated per device within a 24h window.
let lookback = 7d;
let StagingHosts =
DeviceProcessEvents
| where Timestamp > ago(lookback)
| where ProcessCommandLine has_any ("vssadmin delete shadows", "wmic shadowcopy delete",
"bcdedit", "recoveryenabled no", "wbadmin delete catalog")
or (FileName in~ ("rar.exe","7z.exe","winrar.exe") and ProcessCommandLine has_any (" a -r", " -hp"))
| summarize StagingEvents=count(), FirstSeen=min(Timestamp) by DeviceName;
let LateralHosts =
union
(DeviceEvents
| where Timestamp > ago(lookback)
| where ActionType == "ServiceInstalled"
| extend ServiceName = tostring(parse_json(AdditionalFields).ServiceName)
| where ServiceName has_any ("PSEXESVC","RemCom","paexec") or ServiceName matches regex "^[A-Za-z0-9]{6,10}$"
| project DeviceName, Timestamp, ServiceName),
(DeviceNetworkEvents
| where Timestamp > ago(lookback)
| where RemotePort == 445 and ActionType == "ConnectionSuccess"
| summarize SMBConnections=dcount(RemoteIP) by DeviceName
| where SMBConnections > 15
| project DeviceName, SMBConnections);
StagingHosts
| join kind=inner (LateralHosts | summarize by DeviceName) on DeviceName
| project DeviceName, FirstSeen, StagingEvents
| order by FirstSeen asc
# THEGENTLEMEN Rapid Triage — run on suspect hosts or fleet-wide via your RMM/EDR
# Checks: exposed RDP, scheduled tasks created in last 7 days, shadow copy state,
# suspicious recently-created services, and admin-share reachable files.
$Report = @()
$cutoff = (Get-Date).AddDays(-7)
# 1. RDP exposure
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
$rdpEnabled = ($rdp.fDenyTSConnections -eq 0)
$rdpListeners = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
$Report += [pscustomobject]@{Check='RDP Enabled'; Result=$rdpEnabled; Detail=($rdpListeners | Measure-Object).Count}
# 2. Scheduled tasks created in last 7 days (persistence / mass-deploy staging)
$tasks = Get-ScheduledTask | Where-Object { $_.Date -gt $cutoff -and $_.TaskPath -notlike '\Microsoft*' }
$Report += [pscustomobject]@{Check='New Scheduled Tasks (7d)'; Result=($tasks | Measure-Object).Count; Detail=($tasks.TaskName -join '; ')}
# 3. Shadow copies present? (deletion = anti-recovery behavior)
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
$Report += [pscustomobject]@{Check='Shadow Copies Present'; Result=($shadows | Measure-Object).Count; Detail='0 may indicate vssadmin deletion'}
# 4. Suspicious services installed recently
$svcs = Get-CimInstance Win32_Service | Where-Object { $_.PathName -match 'ADMIN\$|PSEXESVC|RemCom|paexec|AppData|Temp' }
$Report += [pscustomobject]@{Check='Suspicious Services'; Result=($svcs | Measure-Object).Count; Detail=($svcs.Name -join '; ')}
# 5. Recent mass-modified files in user dirs (staging or early encryption)
$recent = Get-ChildItem 'C:\Users' -Recurse -File -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddHours(-24) } |
Group-Object Extension | Sort-Object Count -Descending | Select-Object -First 5
$Report += [pscustomobject]@{Check='Top Modified Extensions (24h)'; Result=($recent | Measure-Object).Count; Detail=($recent | ForEach-Object { "$($_.Name):$($_.Count)" }) -join ' '}
$Report | Format-Table -AutoSize
# Escalate immediately if: new tasks + 0 shadow copies + suspicious services all fire on one host.
Incident Response Priorities
T-Minus Detection Checklist (Before Encryption Fires)
- New local/domain admin accounts created outside change windows — the gang's assessed playbook uses elevated accounts for mass deployment.
- SMB admin-share write storms — one host writing executables to
\\*\ADMIN$across dozens of machines is the classic pre-detonation signal. - Bulk archive processes (rar/7z) on file servers, especially with password flags.
- Unusual outbound volume to cloud storage, MEGA/paste-style services, or unknown VPS endpoints from servers that don't normally egress.
- vssadmin / bcdedit / wbadmin execution anywhere in the fleet — treat as near-certain precursor.
- EDR tampering events — sensor disables, exclusions added, or
Set-MpPreferencechanges. - GPO modifications pushing new scripts or scheduled tasks domain-wide.
Assets Historically Prioritized for Exfiltration (this gang's sector profile)
- PHI/PII databases (healthcare listings dominate this wave)
- Client-privileged documents and matter files (legal/professional services)
- Financial records, payroll, tax filings
- Email archives of executives and legal counsel
- Backup catalogs and backup admin credentials (to enable destruction)
Containment Actions — Ordered by Urgency
- Isolate confirmed-staging hosts at the network layer (EDR isolate / switch ACL), do not power off — preserve memory.
- Disable suspicious accounts and force enterprise-wide credential reset for any account seen on a staging host; assume krbtgt/DA compromise if a DC was touched.
- Block egress to identified exfil destinations at the proxy/firewall.
- Snapshot/preserve forensic evidence before remediation; capture the deployer binary if found.
- Verify backup integrity and offline copies before adversary reaches them; rotate backup credentials.
- Engage IR retainer and counsel early — leak-site posting means a public-pressure clock is already running, even if the claim is unverified.
Hardening Recommendations
Immediate (24 hours)
- Patch or mitigate all CISA KEV entries above if present: CVE-2026-50751 (Check Point), CVE-2026-20316 (Cisco FMC), CVE-2026-59316 → vCenter path traversal (CVE-2026-59310), CVE-2026-63077 (TeamCity), CVE-2026-48027 (Nx Console).
- Disable RDP from the internet entirely; require VPN + MFA for any remote administration. Audit 3389 exposure externally today.
- Enforce phishing-resistant MFA on all remote access, VPN, and email.
- Block Office macros from internet-sourced documents (Mark of the Web policy).
- Alert on
vssadmin delete shadows,bcdedit, and PsExec-style service creation fleet-wide (rules above). - Verify offline/immutable backups exist and restore-tested.
Short-Term (2 weeks)
- Segment the network: isolate backup infrastructure, restrict server-to-server SMB, and place healthcare/PHI and legal-data stores behind dedicated zones with egress filtering.
- Deploy application allow-listing on servers to blunt unauthorized encryptor and staging binaries.
- Implement tiered administration; remove standing Domain Admin usage; deploy LAPS.
- Egress data-loss monitoring with volume-based anomaly detection on file servers and database hosts.
- Establish leak-site monitoring (or retainer-based dark web monitoring) so a listing naming your organization is detected within hours, not weeks.
- Tabletop the double-extortion scenario with legal, comms, and executives — the leak-site decision tree should be rehearsed before it's real.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.