Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gentlemen Ransomware Hits 478, Spreads Like a Worm

Gentlemen Ransomware Hits 478, Spreads Like a Worm

Posted on June 13, 2026 By CWS

A recent in-depth analysis of The Gentlemen ransomware reveals that the group has targeted 478 victims. Initially working as an affiliate under various ransomware-as-a-service (RaaS) programs such as LockBit and Medusa, the group has evolved significantly in its operations.

Origins and Leadership

According to PRODAFT, a cybersecurity firm, the group known as Phantom Mantis is spearheaded by a Russian-speaking cybercriminal identified as LARVA-368. This individual, using multiple aliases, initiated The Gentlemen as an independent entity in July 2025, breaking away from any RaaS dependencies. Notably, artificial intelligence plays a critical role in their operations, from ransomware development to post-exploitation strategies.

Before establishing The Gentlemen, LARVA-368 was a part of another ransomware group called Embargo. However, a dispute over payments with Qilin led to the formation of The Gentlemen, following allegations of deceit and financial misconduct by the RaaS provider.

Ransomware Operations

Reports from cybersecurity teams, like Cybereason, describe The Gentlemen as a swift and adaptive operation, utilizing a blend of mature ransomware techniques and affiliate support systems. The group’s activities accounted for 10% of ransomware incidents in April 2026, with attacks primarily focusing on enterprises through vulnerable services or stolen credentials.

Geographically, The Gentlemen’s impact is felt mostly outside the U.S., with major targets in Thailand, the U.K., Brazil, Germany, and India. They employ sophisticated methods such as encryption bypass techniques and command-and-control (C2) tools, ensuring a high degree of adaptability during attacks.

Technical Tactics and Tools

The Gentlemen’s arsenal includes a variety of tools designed for reconnaissance, privilege escalation, and defense evasion. The group uses a hybrid encryption scheme, leveraging advanced cryptographic methods, and their ransomware is reportedly written in the Go programming language, allowing it to spread like a worm across networks.

Microsoft has identified them under the name Storm-2697, noting their malware’s capability to propagate autonomously. Additionally, recent leaks from an internal database provide insights into the group’s structure and use of known vulnerabilities in major software systems.

Future Implications

The Gentlemen continues to be a formidable force in the cyber threat landscape, refining their tactics and expanding their reach. As they target more organizations globally, understanding their methodologies becomes crucial for potential victims to bolster defenses and mitigate risks.

The Hacker News Tags:cyber attacks, cyber threats, Cybercrime, Cybersecurity, data breaches, Gentlemen group, LARVA-368, Phantom Mantis, Ransomware, ransomware-as-a-service

Post navigation

Previous Post: GreatXML Exploit Circumvents Windows BitLocker Security
Next Post: Cybersecurity Stars Awards 2026: 95 Winners Revealed

Related Posts

Massive Android Fraud Operations Uncovered: IconAds, Kaleidoscope, SMS Malware, NFC Scams Massive Android Fraud Operations Uncovered: IconAds, Kaleidoscope, SMS Malware, NFC Scams The Hacker News
Developer Workstations Integral to Software Supply Chain Security Developer Workstations Integral to Software Supply Chain Security The Hacker News
EtherRAT Uses GitHub Facades to Target Admin Accounts EtherRAT Uses GitHub Facades to Target Admin Accounts The Hacker News
Enhancing Windows Security: Tackling MFA and Credential Risks Enhancing Windows Security: Tackling MFA and Credential Risks The Hacker News
Alert Fatigue, Data Overload, and the Fall of Traditional SIEMs Alert Fatigue, Data Overload, and the Fall of Traditional SIEMs The Hacker News
U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark