The Gentlemen Ransomware: India in the Crosshairs as 500+ Victims Fall and FortiGate Backdoors Enable Global Strikes
Four Indian companies breached. Fourteen thousand seven hundred compromised FortiGate devices sitting as silent backdoors across the globe. A ransomware-as-a-service group scaling faster than LockBit 3.0 ever did at the same age. The Gentlemen — a sophisticated splinter of the Qilin ransomware ecosystem — has claimed over 500 victims across 66 countries since emerging in mid-2025, and India is squarely in their sights. With attack volumes nearly doubling month over month in early 2026 and a primary entry vector tied to a critical FortiOS authentication bypass flaw that many organisations still have not patched, this is not a threat you can defer to next quarter’s risk register.
- The Gentlemen claimed 500+ victims in 66 countries since September 2025 — the fastest-scaling RaaS on record.
- Primary entry vector: CVE-2024-55591, a critical FortiOS/FortiProxy authentication bypass; operators maintain a pool of ~14,700 pre-compromised FortiGate devices.
- Four confirmed Indian victims: Tikona Infinet (telecom), All India Minerals (manufacturing), ETA Technology Pvt Ltd (Bangalore), and Indus Protech Solutions (Chennai supply chain).
- The group uses GentleKiller, a custom EDR-destruction framework with named drivers (HexKiller, ThrottleBlood, HavocKiller), making endpoint detection unreliable once inside.
- A May 2026 breach of the group’s own backend leaked internal playbooks, operator identities, and C2 procedures — but the operation did not slow down.
- The 90% affiliate revenue-share model — the highest in the underground — is accelerating recruitment of skilled initial-access brokers globally.
Who Are The Gentlemen? A Qilin Splinter Turned RaaS Juggernaut
The Gentlemen first appeared on VirusTotal on 17 July 2025, when a researcher flagged a novel Go-based ransomware sample with unusual build characteristics. Within two months, the group had begun openly marketing their ransomware-as-a-service affiliate programme on criminal forums, openly courting defectors from Qilin, LockBit, and RansomHub with one compelling differentiator: a 90 percent affiliate revenue split — the highest payout ever documented in underground ransomware markets.
The origin story matters. An affiliate known as hastalamuerte had previously operated under the Qilin umbrella and filed a payment dispute in July 2025 after allegedly being shorted approximately $48,000 in commissions. That dispute catalysed the fork. Hastalamuerte joined forces with operator zeta88 and seven other core members to build The Gentlemen from scratch, incorporating what the group describes as “cherry-picked” encryption routines, obfuscation layers, and EDR evasion methods reverse-engineered from Babuk, Qilin, LockBit 5.0, and Medusa. The result is a ransomware toolkit that is modular, cross-platform, and operationally mature from day one.
Growth has been staggering. The group recorded 48 attacks in January 2026, 91 in February — nearly doubling in a single month — and 89 in April 2026. By June 13, 2026, researchers at Ransomnews had tracked 483 distinct victims, while Halcyon’s Threat Actor Index places the figure above 500 as of this writing. That makes The Gentlemen the second most prolific ransomware brand of 2026, trailing only Qilin — the very organisation they splintered from. Cyber risk analysts at The Insurer designated them the most active threat actor in Q2 2026.
India in the Crosshairs: Four Confirmed Victims in 2026
While the group’s overall victim geography skews towards Thailand (their most-targeted country), the United States, Brazil, and France, India has emerged as a consistent and growing target. At least four Indian organisations have been publicly claimed as victims in 2026:
| Organisation | Sector | City/State | Date Claimed |
|---|---|---|---|
| All India Minerals | Manufacturing / Mining | India | 1 March 2026 |
| Tikona Infinet Pvt Ltd | Telecommunications / ISP | Pan-India | 23 July 2026 |
| ETA Technology Pvt Ltd | Engineering / Manufacturing | Bangalore, Karnataka | 30 July 2026 |
| Indus Protech Solutions | MRO / Supply Chain | Chennai, Tamil Nadu | 30 July 2026 |
The Tikona Infinet breach is particularly alarming for India’s digital infrastructure community. Tikona provides broadband and enterprise connectivity to tens of thousands of Indian businesses. A threat actor with access to a major ISP’s internal systems could potentially intercept traffic, harvest credentials from downstream customers, or map enterprise network topologies — intelligence that compounds the risk far beyond Tikona itself. The group posted a public leak warning on their dark-web site: “The full leak will be published soon, unless a company representative contacts us.”
This pattern of targeting telecom, manufacturing, and supply-chain firms mirrors the group’s global playbook. They specifically hunt organisations where operational disruption is catastrophic — where ransom payment is often perceived as faster than recovery. Indian CISOs and IT directors in these verticals must treat this as a direct, active warning. This India-focused threat intelligence context aligns with what we covered in our analysis of Lazarus targeting Indian aerospace — adversaries are not ignoring India, they are specifically selecting it.
Technical Deep Dive: How The Gentlemen Break In and Spread
The group’s primary initial access vector is CVE-2024-55591 — a critical authentication bypass flaw in FortiOS and FortiProxy that allows an unauthenticated remote attacker to gain super-admin privileges via crafted requests to the Node.js websocket module. Fortinet disclosed and patched this in January 2024, yet Halcyon’s threat assessment documents that The Gentlemen maintain a standing pool of approximately 14,700 already-compromised FortiGate appliances globally — devices where the exploit succeeded months or years ago and persistent access has been quietly maintained, ready to activate for affiliate campaigns.
This is a chilling example of the “land and hibernate” technique: compromise the perimeter at scale, stay silent, then monetise when the affiliate pays up. For every Indian organisation running an unpatched or post-exploit-but-not-reimaged FortiGate, the clock is already ticking.
Post-access, the group’s kill chain is methodical:
- Lateral movement: AnyDesk, PsExec, PowerShell Remoting across the internal network
- Privilege escalation: PowerRun to achieve SYSTEM-level access; Active Directory Group Policy Object (GPO) hijacking for domain-wide deployment
- Defence evasion: Windows Defender disabled with path exclusions; Volume Shadow Copies and Recycle Bin deleted; backup, database, and virtualisation services terminated; event logs cleared; free disk wiped on Linux targets
- Data exfiltration: Sensitive files exfiltrated before encryption, enabling double-extortion leverage
- Encryption: Go-based encryptor deployed for Windows and Linux; a dedicated C-based locker handles ESXi hypervisors. Files ≤1 MB are fully encrypted; larger files use intermittent encryption for speed. Each file receives a unique ephemeral key, preventing bulk decryption even if the master key is partially obtained. Encrypted files receive a
.umc16hextension and a ransom note namedREADME-GENTLEMEN.txt.
GentleKiller: Purpose-Built EDR Destruction
What separates The Gentlemen from commodity ransomware operators is their investment in GentleKiller — a dedicated EDR-destruction framework that arrives before the encryptor. GentleKiller ships with named driver components including HexKiller, ThrottleBlood, and HavocKiller, each targeting specific endpoint security platforms. The group also leverages BYOVD (Bring Your Own Vulnerable Driver) techniques, weaponising publicly disclosed vulnerable driver proof-of-concepts within days of their release.
The practical consequence: by the time the encryptor runs, most standard endpoint detection and response tools are already blind. This is why threat intelligence briefings from multiple vendors consistently flag that organisations relying solely on EDR for ransomware defence are dangerously under-protected against this threat actor.
This is a known risk pattern — as we’ve seen with other advanced ransomware operators like DeadLock’s blockchain-based C2 evasion, modern ransomware groups invest heavily in defeating the defensive tools organisations trust most.
The May 2026 Breach: A Rare Window Into Operations
In an extraordinary development in May 2026, an unknown party compromised The Gentlemen’s own internal backend infrastructure. On 4 May 2026, the breach was confirmed; by the following day, internal data was being advertised for sale at $10,000 in Bitcoin, with proof files posted publicly.
What leaked was operationally significant: nine internal accounts including administrator zeta88 and IAB hastalamuerte; server credentials and password hashes; shared VPN and Synology accounts; real-time intrusion coordination logs spanning November 2025 to April 2026; C2 infrastructure setup procedures; and payout tracking across campaigns. The leaked chats revealed the group had studied the Black Basta February 2025 leak as an operational template, and were actively using uncensored AI models (specifically cited Qwen variants) to assist with operations planning.
Despite this exposure, the group did not pause operations. Their attack volume in May and June 2026 remained consistent with prior months — a sign of deep operational resilience and compartmentalisation that security researchers found alarming. The playbook being used against Indian firms today was documented in that leak.
What You Should Do Now: Sanjay Seth’s Expert Defence Checklist
The Gentlemen’s success rests on three foundational failures at target organisations: unpatched edge devices, flat Active Directory architectures, and missing offline backups. Address these and you deny the group their entire kill chain. Here is the prioritised action list for Indian IT and security teams:
- Audit all FortiGate and FortiProxy devices immediately. Patch to firmware versions not affected by CVE-2024-55591. But patching alone is insufficient — if a device was exposed before patching, assume it may be compromised. Re-image affected appliances from clean firmware, reset all admin credentials, and rotate all certificates and VPN pre-shared keys. Check for rogue admin accounts and unexpected firewall policy changes.
- Hunt for persistence indicators. Search for the scheduled task named
gentlemen_system, the.umc16hfile extension, and processes invoking--systemor--sharescommand-line arguments. Scan for AnyDesk installations not authorised by your IT team. - Segment and tier your Active Directory. The group’s GPO hijacking technique succeeds against flat AD designs. Implement AD tiering: separate Tier 0 (domain controllers), Tier 1 (servers), and Tier 2 (workstations). Restrict NETLOGON and SYSVOL write access. Monitor for unauthorised GPO and scheduled task creation with real-time alerting.
- Deploy phishing-resistant MFA everywhere. The group leverages infostealer-sourced credentials and session cookies to bypass standard MFA. Use FIDO2/hardware tokens for privileged accounts, VPN gateways, and Outlook Web Access. This is especially relevant given their documented use of compromised OWA mailboxes as an alternate initial access path.
- Implement immutable, air-gapped backups. The group deletes VSCs and terminates backup services before encrypting. Ensure you maintain at least one backup that is offline or immutable (e.g., WORM storage) and test restoration quarterly. Follow the 3-2-1-1 rule: three copies, two media types, one off-site, one air-gapped.
- Consider a Zero Trust review of your edge posture. If your organisation is running Fortinet, Cisco, or Citrix edge devices — all targeted by various 2026 campaigns — it is time for a professional assessment of your perimeter security posture before you become the next entry in a ransomware group’s victim table.
Frequently Asked Questions
Is CVE-2024-55591 still dangerous if I patched my FortiGate in 2024?
Patching closes the vulnerability but does not undo a prior exploitation. The Gentlemen’s model involves compromising devices and quietly maintaining access for months before activating. If your FortiGate was exposed to the internet while unpatched at any point after January 2024, you should conduct a forensic review of configuration changes, admin account activity, and outbound traffic anomalies — even if the firmware is now current.
Why are Indian manufacturing and telecom firms being targeted specifically?
Ransomware groups target organisations where operational downtime is most painful and where ransom payment is perceived as faster than recovery. Manufacturing firms cannot afford production halts; telecom providers face SLA penalties and regulatory scrutiny. India’s growing industrial and digital economy makes it an attractive target, and the relatively lower cybersecurity maturity compared to US or European peers means attackers often face less resistance. The Gentlemen’s Southeast Asian affiliate base may also provide linguistic and cultural familiarity with Indian targets.
The group’s backend was hacked in May 2026 — does that mean the threat is diminished?
Unfortunately, no. Despite the breach of their own infrastructure, The Gentlemen continued operating at full pace through June and July 2026. The Indian attacks on Tikona Infinet and others occurred after the backend compromise. The leak exposed their playbook but not their operational capacity. Threat intelligence teams can use the leaked data to improve detection signatures, but organisations should not conclude that the group is weakened.
What should I do if I suspect my organisation has already been compromised by The Gentlemen?
Do not attempt to remediate without professional support. Immediately isolate affected systems from the network, preserve forensic evidence (do not wipe machines), and engage a specialist incident response team. Check for the gentlemen_system scheduled task and .umc16h extensions. Alert your data protection officer — under India’s DPDP Act and applicable CERT-In requirements, breach notification obligations may apply. Crucially, do not pay the ransom without legal counsel: there are sanctions implications and no guarantee of data deletion.
The Gentlemen ransomware group is not a future threat — it is a present one, actively targeting Indian organisations right now. The window to act before a breach is shorter than most IT leaders realise. A compromised FortiGate appliance you patched last year may already be a doorway an affiliate purchased last month.
If you need an expert eye on your edge device posture, Active Directory architecture, or incident response readiness, reach out to Sanjay Seth for a security assessment. With 30 years in cybersecurity, specialising in zero-trust architecture and enterprise network defence across India and the NCR region, Sanjay’s team can help you close the gaps before a ransomware affiliate does.