The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth
Threat Actor Meta
Summary
Hide ▲
Show ▼
The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as the second most active ransomware gang by victim count, with 332 published victims since mid-2025 and more than 240 in 2026. Its operators focus on Internet-facing VPNs and firewalls and can encrypt whole networks within hours. Identity work also links the administrator to the Zeta88/Hastalamuerte handles, reinforcing the picture of a centralized ransomware business built for scale.
Related Happenings
GodDamn ransomware PoisonX BYOVD activity
Malware Activity
H score14
First: 09.07.2026 13:43
Last: 09.07.2026 13:43
Sources 1
About this happening:
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
GodDamn ransomware PoisonX BYOVD activity
Malware ActivityAbout this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
Qilin consolidates into dominant RaaS position as ransomware market reconcentrates
Threat Actor Meta
H score39
First: 03.07.2026 16:00
Last: 03.07.2026 16:00
Sources 1
About this happening:
Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...
Qilin consolidates into dominant RaaS position as ransomware market reconcentrates
Threat Actor MetaAbout this happening: Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor Meta
H score67
First: 03.07.2026 14:30
Last: 03.07.2026 14:30
Sources 1
About this happening:
Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor MetaAbout this happening: Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
INC ransomware group’s RaaS expansion and victim growth in 2026
Threat Actor Meta
H score45
First: 18.06.2026 17:12
Last: 18.06.2026 17:12
Sources 1
About this happening:
INC has grown from a RaaS startup into one of 2026’s most prolific ransomware groups, with 830+ victims since August 2023. The expansion followed affiliate migrati...
INC ransomware group’s RaaS expansion and victim growth in 2026
Threat Actor MetaAbout this happening: INC has grown from a RaaS startup into one of 2026’s most prolific ransomware groups, with 830+ victims since August 2023. The expansion followed affiliate migrati...
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score69
First: 12.06.2026 21:59
Last: 12.06.2026 21:59
Sources 1
About this happening:
The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Timeline
-
10.06.2026 17:03 2 articles · 1mo ago
The Gentlemen ransomware group scales with a 90/10 affiliate split
Campaign Scope UpdateThe Gentlemen ransomware group has become the second most active ransomware gang by victim count, with at least 332 published victims since its mid-2025 inception and more than 240 in 2026 alone. Check Point says the group uses a 90/10 RaaS affiliate split, targets Internet-facing VPNs and firewalls, can encrypt entire networks within hours, and that backend access tied the administrator to the Zeta88 and Hastalamuerte handles.
Show sources
- Who Runs the Ransomware Group ‘The Gentlemen?’ — krebsonsecurity.com — 10.06.2026 17:03
- Who Runs the Ransomware Group ‘The Gentlemen?’ — krebsonsecurity.com — 10.06.2026 17:03