Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gentlemen Ransomware Hits 478, Spreads Like a Worm

Gentlemen Ransomware Hits 478, Spreads Like a Worm

Posted on June 13, 2026 By CWS

A recent in-depth analysis of The Gentlemen ransomware reveals that the group has targeted 478 victims. Initially working as an affiliate under various ransomware-as-a-service (RaaS) programs such as LockBit and Medusa, the group has evolved significantly in its operations.

Origins and Leadership

According to PRODAFT, a cybersecurity firm, the group known as Phantom Mantis is spearheaded by a Russian-speaking cybercriminal identified as LARVA-368. This individual, using multiple aliases, initiated The Gentlemen as an independent entity in July 2025, breaking away from any RaaS dependencies. Notably, artificial intelligence plays a critical role in their operations, from ransomware development to post-exploitation strategies.

Before establishing The Gentlemen, LARVA-368 was a part of another ransomware group called Embargo. However, a dispute over payments with Qilin led to the formation of The Gentlemen, following allegations of deceit and financial misconduct by the RaaS provider.

Ransomware Operations

Reports from cybersecurity teams, like Cybereason, describe The Gentlemen as a swift and adaptive operation, utilizing a blend of mature ransomware techniques and affiliate support systems. The group’s activities accounted for 10% of ransomware incidents in April 2026, with attacks primarily focusing on enterprises through vulnerable services or stolen credentials.

Geographically, The Gentlemen’s impact is felt mostly outside the U.S., with major targets in Thailand, the U.K., Brazil, Germany, and India. They employ sophisticated methods such as encryption bypass techniques and command-and-control (C2) tools, ensuring a high degree of adaptability during attacks.

Technical Tactics and Tools

The Gentlemen’s arsenal includes a variety of tools designed for reconnaissance, privilege escalation, and defense evasion. The group uses a hybrid encryption scheme, leveraging advanced cryptographic methods, and their ransomware is reportedly written in the Go programming language, allowing it to spread like a worm across networks.

Microsoft has identified them under the name Storm-2697, noting their malware’s capability to propagate autonomously. Additionally, recent leaks from an internal database provide insights into the group’s structure and use of known vulnerabilities in major software systems.

Future Implications

The Gentlemen continues to be a formidable force in the cyber threat landscape, refining their tactics and expanding their reach. As they target more organizations globally, understanding their methodologies becomes crucial for potential victims to bolster defenses and mitigate risks.

The Hacker News Tags:cyber attacks, cyber threats, Cybercrime, Cybersecurity, data breaches, Gentlemen group, LARVA-368, Phantom Mantis, Ransomware, ransomware-as-a-service

Post navigation

Previous Post: GreatXML Exploit Circumvents Windows BitLocker Security
Next Post: Cybersecurity Stars Awards 2026: 95 Winners Revealed

Related Posts

Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access The Hacker News
FlutterShell Backdoor: New Threat on macOS via Ads FlutterShell Backdoor: New Threat on macOS via Ads The Hacker News
Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit The Hacker News
SolarWinds Fixes Major Flaws in Serv-U Software SolarWinds Fixes Major Flaws in Serv-U Software The Hacker News
CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution The Hacker News
Docker Patches Critical AI Vulnerability in Ask Gordon Docker Patches Critical AI Vulnerability in Ask Gordon The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Tengu Botnet Enhances IoT Device Resilience
  • Frenos Secures $1.52M to Enhance OT Security Innovations
  • Nimbus Manticore Targets Critical Sectors with New Malware
  • Chinese Firm Allegedly Builds Network for PLA Cyber Ops
  • Microsoft Launches MAI-Cyber-1-Flash for Enhanced Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Tengu Botnet Enhances IoT Device Resilience
  • Frenos Secures $1.52M to Enhance OT Security Innovations
  • Nimbus Manticore Targets Critical Sectors with New Malware
  • Chinese Firm Allegedly Builds Network for PLA Cyber Ops
  • Microsoft Launches MAI-Cyber-1-Flash for Enhanced Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark