CVE Tools
Back to feed
Exploited in the wild The Gentlemen ransomware zero-day

No Manners Here: The Ruthless Rise of The Gentlemen Ransomware

Palo Alto Unit 42·By Matt Brady··5 min read
CVE Tools coverage

Palo Alto Networks' Unit 42 reports that The Gentlemen, a Ransomware-as-a-Service (RaaS) group, has surpassed 580 claimed victims globally since its emergence in late 2025. Operating under the alias Storm-2697, the group uses custom tools and exploits several known vulnerabilities, including CVE-2024-55591 and CVE-2025-32433, to infiltrate networks. With a generous 90% affiliate payout model and partnerships with BreachForums, The Gentlemen has rapidly grown into one of the most active ransomware groups in 2026. Security experts recommend urgent patching and monitoring for signs of compromise.

Executive Summary

The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius. Their ransomware variants are written in both C and Go programming languages, enabling the threat actors to spread their encryptors across different operating systems and virtual infrastructure. Figure 1 below illustrates the desktop wallpaper used by the ransomware after deployment.…

Continue reading on Palo Alto Unit 42