The Gentlemen Ransomware: A Rapidly Scaling RaaS Threat Targeting Bangladesh
Published on 09-Aug-2026 15:00:00
Executive Summary
BGD e-GOV CIRT is issuing this advisory to raise awareness of The Gentlemen, a Ransomware-as-a-Service (RaaS) operation that has scaled rapidly since it surfaced in mid-2025 and has since become one of the most active ransomware programs globally by claimed victim count.
This threat has direct relevance to Bangladesh; public reporting indicates that a large, Bangladesh-headquartered non-governmental development organization was listed on the group’s extortion site in July 2026, with the operators threatening to publish exfiltrated data unless a ransom is paid.
The group operates a cross-platform, self-propagating encryptor that can independently spread across Windows, Linux, NAS, BSD, and VMware ESXi systems within a compromised network, and it is capable of encrypting an entire domain-joined environment within minutes once a Domain Controller is compromised. Affiliates are offered an unusually generous 90 percent share of ransom proceeds, which has attracted a large pool of experienced operators and fuelled a sharp rise in the group’s attack volume through 2026.
Given the group’s reliance on exploitable edge devices (firewalls, VPN gateways, backup software, and hypervisor management interfaces), weak or reused credentials, and Active Directory misconfigurations, organizations in Bangladesh across the NGO/development, banking and financial services, ready-made garment (RMG) and manufacturing, telecommunications, healthcare, and education sectors should treat this as an immediate risk requiring urgent review of internet-facing infrastructure and backup resilience.
Threat Overview
The Gentlemen is a financially motivated, double-extortion ransomware operation believed to be run by a small, disciplined core team of roughly 20 individuals operating out of a Russian-speaking region. The group’s targeting rules explicitly exclude organizations located in Russia and other Commonwealth of Independent States (CIS) countries, a pattern consistent with many Russian-speaking cybercriminal operations.
The operation formally began offering its ransomware platform to external affiliates in September 2025, though development activity and early intrusions have been traced back to at least mid-2025. Unlike traditional RaaS programs that offer affiliates 70-80 percent of ransom proceeds, The Gentlemen offers a 90 percent share, together with full control over victim negotiations. This unusually generous split has attracted experienced operators away from competing ransomware brands and has been a key driver of the group’s explosive growth.
Victim counts tracked from the group’s dark-web leak site have grown from roughly 30 claimed victims in autumn 2025 to several hundred by mid-2026, spanning more than 70 countries and over 20 industry verticals, including manufacturing, technology, healthcare, financial services, education, transportation, retail, energy, and non-governmental organizations. Independent telemetry recovered from a compromised command-and-control server tied to the group’s proxy infrastructure suggests the true number of affected organizations, including those never listed publicly, may be substantially higher than the leak-site count alone.
The group supplies affiliates with a Go-based encryptor (obfuscated with the Garble toolchain) capable of targeting Windows, Linux, NAS, and BSD systems, along with a dedicated C-based variant built specifically for VMware ESXi hypervisors. This multi-OS capability allows a single affiliate to encrypt an organization’s workstations, servers, network-attached storage, and virtualization layer in a single coordinated operation.
![]()