惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Jina AI
Jina AI
The Cloudflare Blog
V
Visual Studio Blog
博客园_首页
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
爱范儿
爱范儿
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
博客园 - 司徒正美
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
V
V2EX
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
博客园 - Franky

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog
The Gentlemen RaaS Is Surging in 2026
rohann@check · 2026-04-20 · via Check Point Blog
Key Findings 
  • The Gentlemen ransomware-as-a-service (RaaS) operation has claimed over 320 victims since mid-2025, with 240 attacks occurring in 2026 alone, making it the #2 most active ransomware group by victim count so far this year 
  • Check Point Research gained rare access to a live command-and-control server linked to a Gentlemen affiliate, revealing a botnet of over 1,570 likely corporate victims, surpassing the group’s own publicly claimed numbers. 
  • The group deliberately targets internet-facing devices (VPNs, firewalls) as their entry point, and once inside, moves quickly to encrypt entire networks within hours 
  • Manufacturing and technology are the most frequently targeted sectors, with healthcare a growing third target — a sign the group is not observing the informal limits that some ransomware operators apply to critical services 
  • A 90/10 affiliate revenue split — compared to the industry standard of 80/20 — is accelerating the group’s growth by attracting experienced operators from competing programs 
A New Group That Isn’t Acting Like One 

Most ransomware groups that emerge with fanfare are gone within months. The Gentlemen are not following that script. 

Since surfacing in mid-2025, the group has grown at a pace that rivals the early years of LockBit 3, a program widely considered the gold standard of ransomware operations. By April 2026, The Gentlemen have publicly listed over 320 victims on their data leak site, with 240 of those occurring in the first months of 2026 alone. That figure only reflects organizations that refused to pay; the actual number of victims is almost certainly higher. 

Check Point Research (CPR) has been tracking this group since its emergence, and their latest analysis, including findings from an active incident response engagement and access to a live attacker-controlled server, reveals why this operation is scaling so quickly, and what it means for enterprise security teams. 

For the full technical breakdown, read the CPR deep-dive report. 

Why They’re Growing: Better Economics for Criminals 

Understanding why The Gentlemen are attracting affiliates so quickly requires understanding how the RaaS business model works. Ransomware operators build the tools and infrastructure; affiliates carry out the attacks and share the ransom proceeds with the operator. 

The Gentlemen are offering affiliates a 90% share of every ransom paid, versus the 80% that most competing programs offer. In a criminal ecosystem driven by financial incentive, that 10% difference matters. It is pulling experienced operators away from established brands and into The Gentlemen’s program, bringing their skills, their access to corporate networks, and their track record with them. 

The result is rapid scaling. The group is not growing because they invented a fundamentally new attack. Most of their techniques are actually well-established. They are growing because their business model is more attractive, and because they have built a program capable of supporting a large and expanding affiliate base across Windows, Linux, and ESXi environments. 

Who Is Getting Hit 

The Gentlemen’s attacks are largely opportunistic rather than targeted. They look for organizations with exposed, vulnerable internet-facing infrastructure (think: VPNs, remote access gateways, firewall management portals) and use those as their entry points. 

Manufacturing and technology companies make up the largest share of victims, which is consistent with the broader ransomware landscape. More notable is the presence of healthcare as the third most frequently targeted sector. Some ransomware groups, as a matter of informal policy or self-preservation, avoid attacking hospitals. The Gentlemen show no indication of observing that limit. 

Geographically, the USA accounts for the largest number of victims, with the UK and Germany also heavily represented. CPR confirmed this pattern from the group’s public leak site and from independent telemetry obtained from an affiliated attacker’s server. 

What CPR Found Inside an Attacker’s Server 

During an incident response engagement, Check Point Research investigators discovered that a Gentlemen affiliate had deployed infrastructure connected to a much larger operation than a single incident would suggest. By gaining access to the command-and-control server in question, the researcher was able to observe a botnet of over 1,570 likely corporate victims. These were organizations whose systems had been quietly compromised and were awaiting further action. 

That number is significant for two reasons. First, it exceeds the group’s own publicly claimed victim count, suggesting the true scale of their activity is larger than what appears on their leak site. Second, the profile of the victims (enterprise systems, domain-joined machines, corporate credentials) confirms this is not opportunistic consumer targeting. These are organizations, and their data was likely already staged for exfiltration. 

Speed Is the Defining Characteristic 

In the incident CPR responded to, the attacker arrived with domain-level administrative access already established. From that point, the intrusion escalated rapidly: credential validation across the environment, lateral movement to dozens of hosts, disabled security tools, and ultimately a domain-wide ransomware deployment triggered through Group Policy, hitting every connected machine simultaneously. 

The speed and coordination of this attack reflects a group that has refined its playbook. Affiliates are not improvising; they are executing a documented, tested process designed to maximize impact before defenders can respond. 

What Security Leaders Should Do 

The Gentlemen are not exploiting novel zero-days or bypassing security through exotic means. Their initial access relies overwhelmingly on unpatched or misconfigured internet-facing devices. These are the same vulnerabilities that defenders have been advised to prioritize for years. 

The fundamentals remain the most important defensive investments: 

  • Patch internet-facing infrastructure first: VPNs, firewalls, and remote access gateways are the primary entry point. These devices must be treated with the same urgency as public-facing web applications 
  • Assume credential compromise: The Gentlemen affiliates move quickly from initial access to domain-level control. Multi-factor authentication and privileged access controls are non-negotiable 
  • Test your backup and recovery capability: A functioning, isolated backup is the single most effective tool for limiting ransomware impact. Many organizations discover their backup strategy is inadequate during an incident, not before 
  • Monitor for lateral movement, not just perimeter breach: By the time ransomware detonates, the attacker has typically been present for some time. Detection at the lateral movement stage provides the best opportunity to interrupt an attack in progress 
  • Segment your network: Domain-wide encryption via Group Policy is only possible when an attacker has domain controller access and can reach every endpoint. Network segmentation limits both the attacker’s reach and the blast radius of a successful intrusion 
The Bigger Picture 

The Gentlemen’s rise illustrates a structural challenge in the ransomware landscape: the barrier to standing up a professional RaaS operation has fallen considerably. A compelling revenue split, a capable locker, and a leak site are enough to attract affiliates who bring their own access and expertise. The operation does not need to be technically groundbreaking to be damaging at scale. 

CPR will continue monitoring this group as it evolves. For the complete technical analysis, including the full attack timeline from our incident response engagement, detailed malware behavior, and indicators of compromise, read the full report. 

Check Point customers are protected from this threat via Threat Emulation and Harmony Endpoint.