The Gentlemen ransomware hits LATAM
The Gentlemen grew into a double-extortion RaaS in 2026, targeting LATAM with Fortinet, RDP, and attacks in Colombia, Peru
The Gentlemen went from an emerging ransomware operation to one of 2026’s most prolific actors in less than a year. Consolidated reporting describes it as a human-operated ransomware-as-a-service group tracked by Microsoft Threat Intelligence as Storm-2697, which surfaced publicly in mid-2025 and opened its affiliate program in September of that year. Its expansion was rapid: multiple intelligence vendors placed it among the world’s most active groups in the second quarter of 2026, with a growing concentration of victims on its leak site and a double-extortion model built around data theft, file encryption, and pressure through publication threats.
The group’s intrusion chain was notably consistent. Initial access repeatedly relied on edge vulnerabilities, especially Fortinet FortiGate and FortiOS, though Citrix NetScaler ADC, SonicWall SSL VPN, and RMM platforms such as ConnectWise ScreenConnect also appeared. Stolen or purchased credentials, phishing with macros, and exposed RDP were added to the mix. Once inside, The Gentlemen showed multi-day persistence, network reconnaissance, defense tampering, shadow copy deletion, and exfiltration before encryption. On the technical side, the ransomware was written in Go, obfuscated with Garble, with variants for Windows, Linux, BSD, NAS, and ESXi, and the use of XChaCha20 and Curve25519 in several observed families. BYOVD drivers such as PoisonX and anticheatG13.sys also appeared, aimed at killing security processes before encryption began.
In Latin America, the most visible case was Ecopetrol in Colombia. The company detected irregular access on July 17, 2026, with information extracted from about 3,300 accounts and data stored in the cloud for 15 group companies. The Gentlemen claimed more than 1 TB and 65 million documents were exfiltrated, although the exact volume was not independently verified. Following the incident, ColCERT issued high-risk alerts and reinforced guidance on Fortinet FortiGate patching and multifactor authentication for remote access. Then came Oldelval in Argentina, the Municipality of San Luis in Peru, Advanced Marketing in Mexico, Grupo Minero Las Cenizas in Chile, and Intranet Gov Brasil, with varying levels of public confirmation, but all following the same operating pattern: perimeter intrusion, rapid exfiltration, leak threats, and negotiations under pressure.
The regional picture that emerges is of an operation that no longer depends only on victim volume, but on industrializing initial access and turning exposed appliances, leaked credentials, and poorly managed remote services into a scalable monetization path. The Gentlemen is now a case study in the convergence of ransomware, access brokering, and multi-stage extortion across government, energy, services, and manufacturing organizations in the region.
Executive summary
The Gentlemen became one of the most active ransomware operations in the criminal market in 2026, with metrics that consistently place it among the highest-volume actors in claimed victims. Consolidated reporting describes it as a human-operated ransomware-as-a-service operation, tracked by Microsoft Threat Intelligence as Storm-2697, with a formal shift to an affiliate model in September 2025. Through 2026, it went from a recent arrival to large-scale activity, with hundreds of victims listed on its leak site and a steady rise in published claims.
The most stable feature of the campaign is double extortion. In practice, The Gentlemen enters corporate networks, exfiltrates sensitive data, encrypts critical systems, and then threatens to publish the stolen information if payment is not made. Several analyses added that in some cases the group escalated pressure further, using countdown timers on its leak site, partial document releases, and, in some reports, DDoS threats. That puts it at a more aggressive operational tier than classic ransomware focused only on downtime.
The technical expansion was just as clear. The group used a Go-based encryptor obfuscated with Garble, with builds for Windows, Linux, BSD, NAS, and ESXi, and with algorithms such as XChaCha20 and Curve25519 in different related families. Around that core, the operation added evasion and defense-disruption techniques, including shadow copy deletion, PsExec and WMI abuse, antivirus disabling, and BYOVD-compatible mechanisms. In practical terms, this means an intrusion chain built around persistence, reconnaissance, and the removal of barriers before encryption.
Its target profile is also consistent. Sources cite sectors including manufacturing, healthcare, finance, construction, energy, retail, technology, education, insurance, and government. Geographically, the consolidated evidence shows claims across North America, South America, Europe, Africa, and Asia, with visible presence in Mexico, Colombia, Peru, Chile, Argentina, and Brazil. This is not just a global actor, but one that found a concrete opportunity surface in Latin America, especially where exposed services, weak credentials, unpatched VPNs, and low tolerance for disruption converge.
On the defensive side, the most repeated signal is that The Gentlemen does not depend on a single vector. It combines edge exploitation, purchased access, phishing, exposed RDP, and abuse of remote administration tools. That mix, combined with the speed of pre-encryption exfiltration, makes detection based only on the moment ransomware detonates arrive too late. The real hunting window comes earlier, in VPN telemetry, bursts of mass file reads, unusual admin sessions, and the appearance of reconnaissance and defense-manipulation tools.
Context and background
The Gentlemen appears in the material as an operation that emerged in mid-2025, with early references ranging between July and August of that year. ManageEngine, FortiGuard, Mallory.ai, DysruptionHub, BlackFog, Halcyon, Ransomware.live, and other profiles agree that it is a RaaS operation, with a gradual shift from a closed phase to a more public affiliate model. Some reports place that formal opening in September 2025. Others note that its origin may lie in the evolution of ArmCorp, a former Qilin affiliate, reinforcing the reading of an ecosystem under fragmentation and of operators with prior experience moving between groups.
That background matters for two reasons. First, it explains how quickly the group was able to scale. Second, it helps explain why its playbook mixes traditional ransomware tactics with more sophisticated exfiltration, C2, and evasion infrastructure. Rather than a static toolkit, the material shows an operation that adapts its chain to each victim’s exposed surface, but always around the same business logic: monetize access, leak data, and force negotiations.
The material also shows that the group did not rely on a single malware family. There are references to a Go-based encryptor obfuscated with Garble, a multiplatform toolkit for Windows, Linux, ESXi, BSD, and NAS, additional lockers, self-propagating variants, and evasion modules using malicious drivers. Among the most consistent observations are the use of GentleKiller, PoisonX3.sys, PoisonX4.sys, and anticheatG13.sys, all designed to weaken security solutions before encryption is executed.
Key facts table
| Date | Event | Source | Confidence |
|---|---|---|---|
| 2025-07 to 2025-09 | The Gentlemen emerges as a RaaS operation and shifts to affiliates | ManageEngine, BlackFog, Halcyon, DysruptionHub | Confirmed |
| 2026-03 | From mid-March, IntelFusions begins tracking the group’s leak site | IntelFusions | Confirmed |
| 2026-04 | BlackFog and BankInfoSecurity report hundreds of named victims on leak sites | BlackFog, BankInfoSecurity | Confirmed |
| 2026-06 | Check Point and other firms place the group among the quarter’s most prolific actors | Check Point Research, The Insurer, Mallory.ai | Confirmed |
| 2026-07-09 | Attack on Ecopetrol, with exfiltration and irregular access to cloud environments | Ransomware.live, Infobae, DataEnforce | Confirmed |
| 2026-07-16 | Peak activity, with 17 posts attributed to The Gentlemen in a single day | Scrutex | Confirmed |
| 2026-07-18 | Ecopetrol is added to the leak site and ColCERT issues a public alert | Scrutex, El Colombiano, IntelFusions | Confirmed |
| 2026-07-23 | Oldelval is listed by The Gentlemen | GalaxyWarden, Ransomware.live | Confirmed |
| 2026-07-24 | Advanced Marketing appears in the group’s public postings | GalaxyWarden, Dexpose, HackerFeeds | Confirmed |
| 2026-07-31 | San Luis municipality and Grupo Minero Las Cenizas appear on the leak site | GalaxyWarden, Dexpose, Hookphish | Confirmed / Unconfirmed claim depending on the case |
| 2026-08-04 | Mallory.ai and others report new victims in the United States and elsewhere | Mallory.ai | Confirmed |
| 2026-08-07 | Intranet Gov Brasil is added to the leak site, without official confirmation | GalaxyWarden, RecentBreaches | Unconfirmed claim |
| 2026-08-10 to 2026-08-17 | Multiple reports consolidate The Gentlemen as a hyper-prolific actor and publish IoCs | Security Arsenal, Ransomware.live, Halcyon, RST Cloud | Confirmed |
Operation timeline
| Date | Event | Actor/vector | Verified source |
|---|---|---|---|
| 2025-07 | First public appearance of the actor | Operation begins | BlackFog |
| 2025-08 | Halcyon places the group’s appearance in August 2025 | Multiplatform toolkit | Halcyon |
| 2025-09 | Formal move to an affiliate model | RaaS with partner program | ManageEngine, DysruptionHub |
| 2026-03-15 approx. | IntelFusions begins public tracking of the leak site | Leak site and victimology | IntelFusions |
| 2026-04 | More than 320 victims listed in public counts | Leak site, cumulative metrics | DysruptionHub, BlackFog |
| 2026-06 | The group rises to among the most active of the quarter | Victim postings | Check Point Research, The Insurer, Mallory.ai |
| 2026-07-09 | Intrusion at Ecopetrol | Irregular access, exfiltration | Infobae, Ransomware.live, DataEnforce |
| 2026-07-16 | Peak of 41 posts on leak sites, 17 attributed to The Gentlemen | Leak site, double extortion | Scrutex |
| 2026-07-18 | Ecopetrol enters the leak site, ColCERT issues an alert | Public extortion | Scrutex, El Colombiano |
| 2026-07-23 | Oldelval is posted by the group | Leak site, leak threat | GalaxyWarden, Dexpose |
| 2026-07-24 to 2026-07-25 | Advanced Marketing is listed and publicly claimed | Phishing or RDP, rapid exfiltration | GalaxyWarden, Dexpose, HackerFeeds |
| 2026-07-31 | San Luis municipality, Las Cenizas, and other claims join the leak site | Public extortion, unconfirmed claims | GalaxyWarden, Hookphish, Ransomware.live |
| 2026-08-04 | New victims in the United States and other markets | Expanding campaign | Mallory.ai |
| 2026-08-06 | Peaks of 14 victims in 24 hours | Mass leak site operation | Security Arsenal |
| 2026-08-07 | Intranet Gov Brasil appears as an unconfirmed claim | Actor leak site | GalaxyWarden, RecentBreaches |
| 2026-08-10 to 2026-08-17 | Publication of IoCs, drivers, hashes, and telemetry | Defense and detection | Halcyon, Ransomware.live, Cynet, RST Cloud |
Attack chain and TTPs
The operational pattern that emerges from the research is consistent and not improvised. Initial access usually comes through the perimeter, not through an isolated endpoint. Cyware identifies three recurring vectors, Citrix NetScaler ADC (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766), and Fortinet FortiOS (CVE-2024-55591). Security Arsenal broadens the picture with Check Point and Cisco Secure Firewall, plus ConnectWise ScreenConnect (CVE-2024-1708). Added to that are stolen or purchased credentials, exposed RDP, phishing campaigns with macro-enabled documents, and abuse of remote administration services such as ScreenConnect or RMM-style tools.
Once inside, the operation aims for persistence and reconnaissance. Intel471 describes the playbook as entry through Internet-exposed services, network mapping, identification of domain admin accounts, disabling of security tools, and payload distribution through NETLOGON. DataEnforce, meanwhile, points to mass document reading or downloading from a single account, lateral access to repositories across multiple subsidiaries, anomalous VPN authentications, and sustained transfers to unknown cloud endpoints. That suggests a clear focus on the pre-encryption stage, when containment is still possible.
Defense disruption is another key trait. Cynet documented the use of PoisonX3.sys and PoisonX4.sys, installed as services under HKLM\SYSTEM\CurrentControlSet\Services\PoisonX, to manipulate processes, network, files, and memory in order to terminate security services. Cybersecurity News adds anticheatG13.sys, a kernel driver used to terminate almost 180 security-related processes. Security Arsenal mentions shadow copy deletion with vssadmin or wmic, disabling backups and antivirus, and behavior consistent with BYOVD. That set is not incidental, it is central to opening the path to encryption.
The ransomware itself is also well characterized. ManageEngine, DataEnforce, Infobae, Mallory.ai, and DEFOnline agree on the use of Go and Garble obfuscation. According to the sources, the encryptor has builds for Windows, Linux, BSD, NAS, ESXi, and virtualized environments, and in some cases requires a specific password to run. That limits uncontrolled spread and complicates sandbox analysis. RST Cloud and Mallory.ai add the use of XChaCha20 and Curve25519, while DEFOnline highlights aggressive self-propagation capabilities inside the compromised network.
Exfiltration usually precedes encryption by 48 to 72 hours, according to Security Arsenal, and total dwell time in the network ranges from 4 to 14 days before detonation. That window is especially important for detection and response, because the pre-encryption activity is where the most exploitable patterns appear, such as service enumeration, mass reads, lateral movement, and log wiping. The model is not built around an instant strike. It is built around progressively degrading defenses so that the extortion phase begins with as much control and as much stolen data as possible.
| TTP | Description | Source |
|---|---|---|
| T1190 | Exploitation of exposed applications, such as VPNs and firewalls | Cyware, Security Arsenal, MITRE ATT&CK |
| Initial access via RDP | Use of exposed remote services | Security Arsenal, GalaxyWarden |
| Phishing with macros | Initial delivery through malicious documents | Security Arsenal, GalaxyWarden |
| Stolen or purchased credentials | Access through valid accounts | DataEnforce, Security Arsenal |
| Compromised RMM | Abuse of ScreenConnect and similar tools | Security Arsenal |
| Internal reconnaissance | Nmap, Advanced IP Scanner, and network enumeration | DataEnforce |
| Defense disruption | BYOVD, PoisonX, anticheatG13.sys, GentleKiller | Cynet, Cybersecurity News, Mallory.ai |
| Shadow copy deletion | vssadmin, wmic | Security Arsenal |
| Pre-encryption exfiltration | Data theft before encryption | DataEnforce, Security Arsenal, Mallory.ai |
| Encryption for impact | Windows, Linux, BSD, NAS, ESXi | ManageEngine, Ransomware.live, Halcyon |
Regional impact
Regional overview
The regional footprint of The Gentlemen is broad and well documented in the material. This is not an actor focused on a single geography, but an operation that found fertile ground in multiple markets at once. Aggregated sources place it with victims in North America, South America, Europe, Africa, and Asia. Within that map, Latin America stands out as a particularly exposed zone, both because of specific victims and because of tactics that exploit surface areas common in the region, such as Fortinet FortiGate, exposed RDP, unpatched VPNs, and overly privileged administrative accounts.
The Latin American pattern is not uniform. In some cases, such as Ecopetrol, there is partial corporate confirmation and subsequent regulatory alerts. In others, such as Oldelval, the incident was operationally contained but remained a public claim by the group. In Peru, the Municipality of San Luis appears in several records as a leak-site listing, but without official breach confirmation. In Chile, Grupo Minero Las Cenizas was marked as an unconfirmed claim. In Brazil, Intranet Gov Brasil appears as a leak-site post still lacking confirmation from authorities. Mexico, meanwhile, was exposed through an intrusion against Advanced Marketing, also without all technical details released.
Colombia
Ecopetrol is the most relevant regional case and also the most difficult to verify fully. On July 17, 2026, the company detected irregular access that led to unauthorized downloads of data linked to roughly 3,300 user accounts and cloud environments belonging to 15 group companies. Available reporting agrees that there was no mass encryption or direct impact on production operations, but there was data exfiltration and a later public extortion attempt.
The Gentlemen claimed on its site to have exfiltrated more than 1 TB and 65 million documents. That figure, however, was not independently validated and should be treated as the actor’s claim. What matters from a regional defense perspective is that the case confirmed the combination of irregular access, extortion pressure, and information publication, and prompted official responses. ColCERT issued a high-risk alert for Colombia’s business sector on July 18, 2026, and reinforced recommendations for urgent patching of Fortinet FortiGate devices, other VPNs, and mandatory two-factor authentication.
The case also helped cement the public association between The Gentlemen and a perimeter-focused intrusion model. DataEnforce described the incident as an intrusion publicly attributed in reporting to the group and recalled that ColCERT had already linked The Gentlemen to more than 200 attacks in 50 countries by April 2026. In narrative terms, Ecopetrol became a trigger for greater regional visibility for an operation that was already expanding.
Argentina
Oldelval appears as the strongest Argentine case in the material. The company was listed by The Gentlemen on July 23, 2026, with a reference to the exfiltration of internal files during a ransomware attack. Public reports indicate that the company did not issue a detailed breach notice and that the number of affected individuals and the volume of compromised data remained unknown. Even so, the company’s communication to the National Securities Commission described an impact limited to administrative systems, while crude oil transport continued without interruption and the incident was declared fully contained.
On the technical side, DEFOnline describes the associated malware as developed in Go, obfuscated with Garble, and capable of aggressive self-propagation inside the network, with fast hybrid encryption based on Curve25519 and XChaCha20. The Rio Times and FalconFeeds added the context of a public claim by the group, but without official attribution confirmation. The analytical value of the case is that it shows a scenario where operational continuity is preserved, but the administrative surface is exposed and pressure from the leak site remains active.
Chile
Chile appears in the material as a geography with several claims, but little public confirmation. Security Chu mentioned alleged confirmed attacks against La Cámara Seguros, the INDH, and Corporación Colina, though without technical details or independent validation. The most concrete case is Grupo Minero Las Cenizas, listed by The Gentlemen on July 31, 2026, with an assertion of internal file exfiltration. GalaxyWarden specified that the entry did not detail the number of records or the types of information stolen and that the incident remained unconfirmed because the company had not issued a breach notification.
Chile’s value in this corpus is methodological. It shows how leak sites can include corporate or institutional names that then circulate through media and aggregators without official confirmation. For an intelligence team, that requires separating actor claims, media mentions, and validated facts immediately.
Peru
The Municipality of San Luis, in Lima, was listed by The Gentlemen on July 31, 2026. GalaxyWarden, Dexpose, Hookphish, Ransomware.live, RecentBreaches, and BreachSense agree that this was an actor claim with a threat to publish sensitive data, but without official breach confirmation from the municipality. Ransomware.live recorded 38 compromised users, though there is still no publicly verifiable detail on the scope of the leak.
What makes the case interesting is the convergence between what was reported in the media and what appeared in the group’s narrative. There was also an earlier post on X that mentioned a hack of the municipality’s computer systems on July 24, with temporary impact on online queries and payments and the activation of recovery protocols. That does not confirm attribution, but it does reinforce the idea that local service platforms are a frequent pressure point.
IntelFusions also said that between July 30 and 31, The Gentlemen posted new victims, including municipal governments in Brazil and Peru, amid a spike in activity. In regional terms, Peru therefore sits in an environment where the operation combines leak-site claims with low official visibility and possible exposure of municipal infrastructure.
Brazil
Brazil is another recurring focus in the material. The Intranet Gov Brasil case, listed on August 7, 2026, was presented by The Gentlemen as an intrusion into the internal network and digital portal used by the Brazilian federal government. GalaxyWarden and Ransomware.live clarified that, at the time of publication, there was no public confirmation from the government or from Serpro or Dataprev, and classified the case as an unconfirmed claim.
The value of this record lies in the combination of institutional sensitivity and lack of validation. It is a clear example of how a leak site can try to amplify the impact of a claim in government environments to force media attention, even when the available evidence is limited to the actor’s own announcement. IntelFusions also noted that during July 30 and 31 the group posted municipal governments in Brazil and Peru during a wider activity spike, suggesting the region was being pushed more aggressively at that point.
Mexico
Mexico appears through Advanced Marketing, a books distribution and publishing company with the domain advmkt.com.mx, listed by The Gentlemen on July 25, 2026. GalaxyWarden, Dexpose, and HackerFeeds agree that there was a direct claim by the group, with a threat to leak sensitive data if negotiations did not begin. Some aggregators classified the case as medium severity, but by late July no ransom amount, data volume, or detailed technical indicators had been published.
The relevance of the incident is tactical. GalaxyWarden notes that The Gentlemen often targets mid-sized companies in Latin America and Europe through phishing or exploited RDP services, followed by rapid exfiltration of sensitive files before encryption. That approach fits many mid-market Mexican organizations, where exposed perimeter services and remote access management remain high-yield entry points for ransomware operators.
United States
The United States appears in multiple sources as both a priority market and a source of specific victims. Mallory.ai identified Control Concepts Technology, based in Texas, as a ransomware victim attributed to The Gentlemen, and TopMark Funding, based in California, as another data breach linked to the group. It also reported Kenaitze Indian Tribe in Alaska as a victim dated July 31, 2026, along with other U.S. organizations such as Promatrix.
Security Arsenal said that within a batch of 25 new victims, Germany and the United States were the group’s primary markets, with entities ranging from 50 to 500 employees. BankInfoSecurity and S-RM also placed The Gentlemen among the prolific operations before it suffered its own internal leak. Although the focus of this investigation is Latin America, the United States serves as an operational reference for the actor’s maturity and scale.
Countries without enough verifiable coverage
No additional verifiable facts were identified in the research for Paraguay, Bolivia, or Uruguay, and Mexico did not provide a second case beyond Advanced Marketing.
Technical indicators
The Gentlemen has an unusually rich public technical footprint for a relatively young RaaS operation. Halcyon publishes locker hashes, the leak site URL, and behavioral patterns for the Go binary. Ransomware.live documents 42 IoCs associated with the operation. Cynet provided hashes for the PoisonX3.sys and PoisonX4.sys drivers. Gurucul and Hunt.io added affiliate infrastructure with domains, IPs, and EtherRAT components. Cyfar.ca expanded the set with hashes, IPs, and command-line fragments.
| Type | Value | Source |
|---|---|---|
| SHA-256 hash | 4948e89b532804590490aaae41f4b582a89592c931e557b6ddfff0b8d6ee8cf5 | Cynet |
| SHA-256 hash | 83DB6A37D9EC9923CA2AA677B4F4D8B67C8B2468046D21136A57FFE92EBA6CAC | Cynet |
| Domain | itemrange.com | Gurucul |
| Domain | wiselystarting.com | Gurucul |
| Domain | simultaneouslypower.com | Gurucul |
| Domain | resumeacceptable.com | Gurucul |
| Domain | publisherresolution.com | Gurucul |
| IP | 193.233.202[.]17 | Hunt.io, CyberPress |
| IP | 146.103.127[.]44 | Gurucul |
| IP | 77.110.126[.]46 | Gurucul |
| IP | 77.110.122[.]58 | Gurucul |
| Hash | anticheatG13.sys | Cybersecurity News |
| File | PoisonX3.sys | Cynet |
| File | PoisonX4.sys | Cynet |
| Session ID | Session associated with Ransomware.live | Ransomware.live |
| Tox ID | 3 published Tox identifiers | Ransomware.live |
The absence of some complete values, such as the exact leak site URL in all sources or the full hashes of every published sample, does not reduce the utility of the set. For defense, there are already enough infrastructure and behavior indicators to strengthen detection rules in DNS, proxy, EDR, and exposed-service monitoring.
Analysis for security teams
The defensive priority against The Gentlemen is not the moment of encryption, but the hours and days before it. The material shows that the actor often remains in the network for 4 to 14 days before detonation and begins exfiltration 48 to 72 hours before encryption. That means any reconnaissance, lateral access, or mass-read behavior appearing on administrative accounts or unusual VPN connections should be treated as high-value signal.
The first mitigation block should focus on the access surface. The research is very clear about Fortinet FortiGate, FortiOS, FortiProxy, Citrix NetScaler ADC, and SonicWall SSL VPN. ConnectWise ScreenConnect, compromised RMM tools, and exposed RDP also appear. In practical terms, that means patching with high priority, reviewing public exposure of remote consoles, cutting unnecessary access, and checking multifactor authentication on every entry point. The Colombian case shows that edge-appliance exploitation remains a high-return door for the actor.
The second block is behavioral detection. DataEnforce lists highly actionable signals, such as mass reading or downloading by a single account, access to repositories across multiple subsidiaries, anomalous VPN authentications, Advanced IP Scanner or Nmap execution from administrative contexts, sustained outbound transfers to unknown cloud endpoints, and attempts to disable endpoint protection or delete logs. Add to that vssadmin, wmic, PsExec, WMI, NETLOGON, strange service creation, unusual or unsigned kernel drivers, and any BYOVD pattern. If the organization has well-tuned EDR telemetry, The Gentlemen leaves a fairly recognizable sequence before encryption.
The third block is impact containment. The use of a Go payload with a specific password suggests an operator trying to avoid uncontrolled spread, while still pointing to deliberate deployment across multiple hosts. Privileged access should be segmented, cross-repository read access reduced, excessive cloud permissions reviewed, and backup access hardened. Security Arsenal and Cynet show that shadow copy deletion and security-tool tampering are part of the chain, so backup protection must be treated as a primary attacker target, not an auxiliary asset.
The fourth block is active hunting for affiliate infrastructure. Gurucul, Hunt.io, and CyberPress show that The Gentlemen does not operate only with the encryptor, but with staging, reverse shell, C2, and exfiltration tools supported by specific domains and IPs. The EtherRAT case, moreover, introduces a C2 component via Ethereum smart contracts, which complicates purely perimeter-based blocking. For SOC teams, that means DNS, proxy, and egress telemetry matter just as much as endpoint data.
The tactical priority, then, is this order, patch edge surfaces, enforce MFA on remote access, monitor exfiltration and administrative behavior, harden privileges, protect backups, and hunt for abnormal drivers or services. In Latin America, where many of the actor’s intrusions rely on exposed perimeters and reused credentials, that order is more useful than any generic ransomware rule.
Limitations of the material
The available corpus allows for a fairly detailed reconstruction of the operation, victimology, and several TTPs, but it does not support a definitive technical attribution beyond the designations cited by each vendor. Some sources present victim claims that were not confirmed by the affected organizations or by authorities. That applies in particular to leak-site entries on Intranet Gov Brasil, Grupo Minero Las Cenizas, Mercado Libre, and certain Chile cases.
There are also discrepancies in victim counts. Some sources speak of 135, 144, 269, 300, 320, 340, 456, 483, or 580 organizations, depending on the time cut and methodology. Those numbers reflect leak-site claims, vendor estimates, or third-party datasets, not a single verifiable total of confirmed incidents. For that reason, this report kept the distinction between confirmed facts and unconfirmed claims or attributions.
It was not possible, from the material provided, to independently verify the full technical detail of some Latin American intrusions, such as exact data volumes, number of affected people, compromised credentials, or definitive initial vectors in each case. In Ecopetrol and Oldelval, for example, there are solid descriptions of impact and the actor’s narrative, but not all claimed figures were publicly validated.
There is also not enough verifiable material to develop specific blocks for Paraguay, Bolivia, or Uruguay, or to build a single technical attribution about the group’s human leadership beyond what each source attributes or suggests. The report therefore limits itself to consolidating facts cited by the research and keeping uncertainty explicit where appropriate.
Sources
- Ransomware roundup: July 2026comparitech.com· Comparitech
- July 2026 Ransomware Wrap-Upzerofox.com· ZeroFox
- Las Cenizas Listed by thegentlemen Ransomware Groupgalaxywarden.com· GalaxyWarden
- Intranet Gov Brasil — THEGENTLEMEN Ransomware Attackbreach.house· Breach House
- The State of Ransomware Q2 2026research.checkpoint.com· Check Point Research
- Municipalidad de San Luisbreachsense.com· BreachSense
- Ecopetrol Data Breach (2026) — What Leaked & Am I Affected?recentbreaches.com· RecentBreaches
- The Gentlemen are knocking: custom backdoors and evolving tacticscyfar.ca· Cyfar.ca
- Cuando el ransomware deja de filtrar: el caso The Gentlemensecurity-chu.com· Security Chu
- July 2026 Ransomware Report: 811 Victims, 66 Groupsbreachsense.com· BreachSense
- Advanced Marketing Listed by thegentlemen Ransomware Groupgalaxywarden.com· GalaxyWarden
- Ransomware Group thegentlemen Hits: Municipalidad de San Luishookphish.com· Hookphish
- Municipalidad de San Luis Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· RecentBreaches
- Ecopetrol Listed by thegentlemen Ransomware Groupgalaxywarden.com· GalaxyWarden
- The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2community.gurucul.com· Gurucul
- Argentina's Main Oil Pipeline Was Hacked. The Oil Kept Movingriotimesonline.com· The Rio Times
- Victim: Intranet Gov Brasil – thegentlemenransomware.live· Ransomware.live
- Ciberataque a Oldelval: el incidente en Vaca Muerta que revela falenciasdefonline.com.ar· DEFOnline
- The Gentlemen Ransomware Kills Nearly 180 Security Processes Before Encryptioncybersecuritynews.com· Cybersecurity News
- Intranet Gov Brasil Listed by thegentlemen Ransomware Groupgalaxywarden.com· GalaxyWarden
- Ransomware Threats In The Americas H1 2026: Deep Divecyble.com· Cyble
- Victim: Municipalidad de San Luis – thegentlemenransomware.live· Ransomware.live
- “The Gentlemen”, el grupo que hackeó a Ecopetrol: dice haber extraído un tera (1 TB, 65 millones de documentos), no datos de 3.300 cuentashalconesypalomas.com· Halcones y Palomas
- Threat report summary on The Gentlemen ransomwarex.com· RST Cloud
- The Gentlemen and Qilin Drive a More Fragmented ...mallory.ai· Mallory.ai
- The Gentlemenicsstrive.com· ICSStrive
- Exploit Public-Facing Application (T1190)attack.mitre.org· MITRE ATT&CK
- Ransomware in 2026: Same Business, New Rulesgroup-ib.com· Group-IB
- Intranet Gov Brasil Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· RecentBreaches
- BYOVD Attacks: A CyOps Perspective on Gentlemen Ransomware and PoisonXcynet.com· Cynet
- The Gentlemen Ransomware Tops Qilin: 94 Victims [2026]tech-insider.org· Tech Insider
- Ransomware Attacks Double Year Over Year as July 2026 ...cybersecurityasia.net· CybersecurityAsia
- Intranet Gov Brasil Data Breach in 2026breachsense.com· BreachSense
- Tables Turned: Gentlemen Ransomware Group Suffers Data Leakbankinfosecurity.com· BankInfoSecurity
- Ransomware Surges in July After Q2 Lullinfosecurity-magazine.com· Infosecurity Magazine
- Victim: Ecopetrol – thegentlemenpro.ransomware.live· Ransomware.live
- The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2hunt.io· Hunt.io
- Group: thegentlemenpro.ransomware.live· Ransomware.live
- Data Encrypted for Impact (T1486)attack.mitre.org· MITRE ATT&CK
- TheGentlemen Ransomware Group Strikes Oldelval Oleoductos del Valledexpose.io· Dexpose
- Gentlemen - Mallory.aimallory.ai· Mallory.ai
- 26 CSIRTs / CERTs in Peru PEpro.ransomware.live· Ransomware.live
- The Gentlemen ransomware expands victim list and uses ...mallory.ai· Mallory.ai
- The Gentlemen Ransomware Affiliate Deploys EtherRAT via Exposed Directorycyberpress.org· CyberPress
- Threat Hunting Case Study: The Gentlemenintel471.com· Intel471
- The Gentlemen - Malware Familymallory.ai· Mallory.ai
- The Gentlemen Ransomwareblackpointcyber.com· Blackpoint Cyber
- Municipalidad de San Luis Listed by thegentlemen Ransomware Groupgalaxywarden.com· GalaxyWarden
- The Gentlemen and Qilin continue a ransomware dominance battle in July 2026cyberhappenings.com· CyberHappenings
- Ecopetrol data breach — Thegentlemen ransomware leak (2026)darkfield.orizon.one· Darkfield
- Emergence and Operations of The Gentlemen Ransomwaremallory.ai· Mallory.ai
- The Gentlemen Ransomware Attack on Advanced Marketingdexpose.io· Dexpose
- thegentlemen - Group Overviewransomware.live· Ransomware.live
- TheGentlemen Threat Group Profilehalcyon.ai· Halcyon
- The Gentlemen ransomware group emerges as most active threat actor in Q2theinsurer.com· The InsurerUnverified URL
- TheGentlemen Ransomware Targets Municipalidad de San Luisdexpose.io· Dexpose
- Cyware Daily Threat Intelligence - July 27, 2026cyware.com· Cyware
- La sofisticación de "The Gentlemen": Kaspersky alerta sobre ransomware con backdoors a medida que impacta Latamtecknow.news· Tecknow News
- Alert on Ecopetrol S.A. ransomware incidentx.com· FalconFeeds.io
- Alert on Oldelval ransomware incidentsx.com· FalconFeeds.io
- Gentlemen Ransomware Reference | Malware Protectionmanageengine.com· ManageEngine
- Q2 Ransomware Surge Driven by Qilin, The Gentlemen, and DragonForcemallory.ai· Mallory.ai
- Weekly Ransomware Intelligence Report, July 19, 2026scrutex.ai· Scrutex
- Así funciona The Gentlemen, el grupo de 'ransomware' que robó los datos de Ecopetrolinfobae.com· Infobae
- Mercat Lliure, afectada per un atac de ransomwareanc.ad· ANC.ad
- Así opera "The Gentlemen", el ransomware que se infiltra antes de atacariworld.com.mx· iWorld México
- Ransomware group thegentlemen hits Advanced Marketinghackerfeeds.com· HackerFeeds
- The Gentlemen has published data stolen from Ecopetrolx.com· VenariX
- ¿Quién es The Gentlemen, la 'mafia digital' que hackeó a Ecopetrol?elcolombiano.com· El Colombiano
- Hace 6 días (24 de julio) la Municipalidad Distrital de San ...x.com· X
- THEGENTLEMEN Ransomware: Aggressive Multi-Vector Campaign Exploiting Perimeter & RMM Flawssecurityarsenal.com· SecurityArsenal
- The Gentlemen Ransomware - Threat Actorfortiguard.com· Fortinet FortiGuard Labs
- Gentlemen ransomware ends Qilin's 13-month reign on topintelfusions.com· IntelFusions
- The Gentlemen: How GentleKiller Clears the Path to Encryptionblackfog.com· BlackFog
- [Intel MX] 2026-07-27 Dos empresas de servicios en México en listas de extorsión: Qilin y TheGentlemenransomware.mx· Ransomware.mx
- Oldelval Oleoductos del Valle Listed by thegentlemen Ransomware Groupgalaxywarden.com· GalaxyWarden
- The Gentlemen — Threat Actor Profiledysruptionhub.com· DysruptionHub
- Gentlemen | Mallory.ai (actor profile)mallory.ai· Mallory.ai
- TheGentlemen - Actor Profilemallory.ai· Mallory.ai
- Ecopetrol Ransomware Attack, July 2026dataenforce.com· DataEnforce
- THEGENTLEMEN Ransomware Gang: 25 New Victims Posted, Sector Targeting Analysis and Detection Rulessecurityarsenal.com· Security Arsenal
- Advanced Marketing Data Breach in 2026breachsense.com· BreachSense
- Victim: Oldelval Oleoductos del Valle – thegentlemenpro.ransomware.live· Ransomware.live
- When a ransomware gang gets ransomware'd: what The Gentlemen's leak reveals about the RaaS economy- 232infosources.ghost.io· Infosources
- Check Point June 2026: The Gentlemen Ransomware Picks Victims ...cloudswitched.com· CloudSwitched
- The Gentlemen ransomware : Le ransomware à surveillertoutsurlacyber.fr· Toutsurlacyber.fr



