ThreatCluster

Ransomware Groups The Gentlemen and Gunra Intensify RaaS Operations in 2026

First seen 15 May 2026, 16:27 UTC CybersecuritynewsGbhackers 77% similarity 67

Article Content

Browse articles
ThreatCluster

The Gentlemen, a ransomware-as-a-service (RaaS) group, has emerged as a significant threat since its inception in mid-2025, with 332 reported victims in the first five months of 2026. They leverage Fortinet and Cisco edge devices for initial access. Similarly, Gunra ransomware, which transitioned from the Conti group, has expanded its operations, targeting numerous organizations and employing a business-like model that includes selling access and leaking stolen files. Both groups represent a growing concern in the cybersecurity landscape, with their operations indicating a shift towards more organized and sophisticated cybercrime. The current status of these threats is active, with ongoing attacks and recruitment efforts by both groups.

Key Points: • The Gentlemen RaaS has claimed 332 victims in 2026 alone, highlighting its rapid growth. • Gunra ransomware has expanded its operations, adopting a business-like model for cybercrime. • Both groups utilize advanced tactics, including exploiting edge devices from major vendors.

ThreatCluster AI

Timeline

2025-05-15
The Gentlemen ransomware group surfaces
The Gentlemen emerges as a new RaaS operation, quickly gaining notoriety in the cyber threat landscape.
Cybersecuritynews
2026-01-01
332 victims reported by The Gentlemen
The Gentlemen ransomware group has reportedly targeted 332 victims in the first five months of 2026.
Cybersecuritynews
2026-05-15
Gunra ransomware expands operations
Gunra ransomware has rapidly evolved from a new threat to a significant global issue, targeting numerous organizations.
Cybersecuritynews

Community

Browse all →