216.73.217.22

License to Encrypt: Make Their Move

· Published 19/11/2025 08:48 · Modified 19/11/2025 09:54

Export JSON

Essential information

Published
19/11/2025 08:48
Modified
19/11/2025 09:54
Tags
2025-11-19 dual-extortion encryption esxi linux persistence raas ransomware the gentlemen windows
Related entities
1 intrusion sets (apt), 17 techniques (mitre), 1 malware

Description

'' group emerged in July 2025, employing advanced tactics. They encrypt data and exfiltrate sensitive information, threatening to release it unless a ransom is paid. The group developed their own -as-a-Service () platform after experimenting with various affiliate models. Their latest update introduces automatic self-restart, run-on-boot functionality, and flexible speeds. The targets both local disks and network-shared drives, supporting , , and platforms. Key features include reliable using XChaCha20 and Curve25519, configurable attack methods, and persistent access capabilities. The group has published 47 victims on their dark web leak site within two months of operation.

External references