Kaspersky flags The Gentlemen ransomware group's cross-sector spread
Kaspersky's Global Research and Analysis Team (GReAT) has published new findings on The Gentlemen, a Ransomware-as-a-Service (RaaS) group that has moved from obscurity to multi-sector threat actor in under a year. The research identifies two new custom-built tools: a Go-written backdoor deployed the day before ransomware execution, and a separate Windows-focused ransomware variant written in C. Together, they signal a group that is actively expanding its technical arsenal rather than licensing off-the-shelf malware.
The group, believed to have emerged around mid-2025, has already targeted organisations across manufacturing, IT services, healthcare, financial services, construction, and logistics. Initial access typically comes through exploitation of internet-facing services or compromised credentials. Kaspersky also found evidence suggesting The Gentlemen may be acquiring footholds from Initial Access Brokers (IABs), third-party actors who sell pre-compromised network entry to ransomware affiliates, effectively outsourcing the hardest part of an intrusion and accelerating the group's operational tempo.
Custom tooling raises the threat ceiling
The newly identified backdoor gathers host and network intelligence, conceals its console window to evade detection, and maintains bidirectional communications with attacker-controlled infrastructure. It gives operators a reconnaissance window before ransomware is ever dropped, reducing the risk of premature detection and maximising the damage radius when encryption does begin.
The C-based ransomware variant is a departure from the group's primary Go implant, which was designed for cross-platform deployment. The Windows-specific build suggests targeted testing in live victim environments, a tactic consistent with a group iterating toward a more stable, scalable attack chain. Kaspersky also noted that the attackers attempted to remove Kaspersky's own security product using a legitimate removal utility; the attempt was blocked and flagged as malicious.
Regional exposure data from Kaspersky's Security Network adds geographic texture to the threat picture. Latin America recorded the highest proportion of organisations with detected ransomware attacks in 2025, at 8.13%, followed by Asia-Pacific at 7.89% and Africa at 7.62%. Europe, at 3.82%, sits at the lower end, though the figure reflects detection rates rather than total impact. High-value European targets in financial services and critical infrastructure remain a structural draw for RaaS affiliates seeking large ransom payouts.
"Despite being a relatively recent entrant to the ransomware threat landscape, The Gentlemen group is rapidly gaining a reputation among threat actors, attracting affiliates and executing high-profile attacks," said Fatih Sensoy, security expert at Kaspersky GReAT. "The testing of the new C-based ransomware variants suggests that the group is actively refining its capabilities, which may translate into more stable and scalable attack chains in the near future."
Convergence implications: when cybersecurity becomes a cross-sector capital question
The broader significance of The Gentlemen's emergence sits at the intersection of cybersecurity and industrial resilience. RaaS groups targeting manufacturing and logistics are no longer merely an IT problem; they are a supply-chain risk that directly affects inventory flows, insurance underwriting, and in some cases sovereign-level critical infrastructure. The healthcare vertical adds a further dimension, where a ransomware-induced system outage carries patient-safety implications that regulators in the EU and UK are increasingly treating as a matter of national security rather than data protection compliance alone.
For capital allocators, the trajectory is unambiguous. Cybersecurity spending among industrial and healthcare operators is being driven upward by threat actor sophistication rather than voluntary investment cycles. Extended Detection and Response (EDR) platforms, threat-intelligence subscriptions, and offline backup infrastructure are shifting from discretionary line items to non-negotiable operating costs. Investors across private equity and growth equity with exposure to industrials and healthcare IT should treat the maturation of groups like The Gentlemen as a forward-looking input into both risk-adjusted returns and portfolio company due-diligence frameworks. The convergence of advanced persistent threat tactics with commoditised RaaS distribution is compressing the window between a group's first appearance and its capacity to inflict enterprise-grade damage.