Gentlemen RaaS Targets Windows, Linux, and ESXi with New C Locker
Article Content
- •Gentlemen RaaS targets Windows, Linux, NAS, BSD, and ESXi systems.
- •Over 320 victims reported, with more than 240 attacks in early 2026.
- •The ransomware features strong defense-evasion capabilities and is written in C.
The Gentlemen ransomware-as-a-service (RaaS) operation has emerged as a significant threat to corporate networks, targeting multiple platforms including Windows, Linux, NAS, BSD, and VMware ESXi. This group has rapidly expanded since its inception around mid-2025, claiming over 320 victims, with more than 240 attacks reported in early 2026 alone. The ransomware is designed with strong defense-evasion capabilities, making it particularly dangerous for organizations. The new locker, written in C, is specifically aimed at hypervisor environments, enhancing its impact. The Gentlemen RaaS has built a well-organized affiliate ecosystem, contributing to its swift growth and increasing threat level. As of now, the operation continues to pose a high risk to various sectors worldwide.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Gentlemen RaaS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…