A recent research report from Kaspersky has revealed that The Gentlemen ransomware group is expanding its operations with new custom-built tools to bypass security defenses.

The group has developed a custom backdoor and a new executable file to control compromised systems. These tools allow the attackers to gather information before deploying their payload.

Global Ransomware Attack Trends

According to data from the Kaspersky Security Network, ransomware attacks remain a significant threat globally. In 2025, Latin America recorded the highest share of targeted organizations at 8.13%, followed by the Asia-Pacific region at 7.89%.

Meanwhile, the Middle East recorded a rate of 7.27%, while Europe had the lowest share at 3.82%. These attacks target various industries, including manufacturing, healthcare, and financial services.

Tactics of The Gentlemen ransomware

The Gentlemen ransomware operation, which emerged around mid-2025, functions as a Ransomware-as-a-Service model. The group primarily gains initial access by exploiting internet-facing services and using compromised credentials.

Notably, Kaspersky found that some systems were accessed long before the actual infection occurred. Consequently, researchers suggest the group may be collaborating with initial access brokers to acquire entry points.

Technical Analysis of New Malware

The attackers deployed a previously unknown backdoor written in Go one day before executing the ransomware. This implant gathers host and network information while hiding its console window to avoid detection.

In addition, the backdoor enables bidirectional communications and server-controlled command execution. The group also developed a new variant written in C, which targets Windows systems.

During recent attacks, the group attempted to remove Kaspersky security software using a specific removal tool. However, the security solution remained active and successfully blocked the malicious attempt.

“The testing of the new C-based ransomware variants suggests that the group is actively refining its capabilities, which may translate into more stable and scalable attack chains in the near future.”

Fatih Sensoy, security expert at Kaspersky GReAT

Recommended Security Measures

To protect networks, organizations should update all apps and software regularly to prevent vulnerability exploitation. Furthermore, defense strategies should focus on detecting lateral movements and data exfiltration.

Organizations can also deploy advanced threat detection solutions to investigate and remediate incidents quickly. Finally, organizations must prepare for further activity from The Gentlemen ransomware group by prioritizing vulnerability management.