Microsoft Threat Intelligence
Based on leak site data tracked by Microsoft Threat Intelligence, The Gentlemen ransomware has claimed one of the highest victim counts among ransomware-as-a-service (RaaS) operations over the past three months, while Microsoft Defender detections on active ransomware offerings show it is the fourth most impactful payload after Akira, Qilin, and LockBit. https://msft.it/6017aHAXl Microsoft tracks the operators of The Gentlemen ransomware as Storm-2697, a financially motivated threat actor that manages the RaaS platform while affiliates carry out attacks. The ransomware combines strong per-file encryption with self-propagation capabilities, which could enable affiliates to expand access across compromised environments and increase the scale of an intrusion. Organizations can reduce risk by hardening identities, limiting privileged access, and leveraging EDR capabilities to identify ransomware activity early.