The Gentlemen Ransomware Gang Dominates Q2 2024 with Record Attacks
A recent analysis by cybersecurity firm ReliaQuest reveals that The Gentlemen ransomware gang emerged as the most active threat group between April and June 2024, responsible for 300 incidents surpassing long-standing leaders like Qilin, which recorded 289 attacks in the same period. The findings, published on July 16, highlight a shift in the ransomware landscape, with The Gentlemen displacing Qilin as the top operator after its dominance throughout 2023.
Over the three-month span, 11 ransomware groups claimed 1,368 victims across 99 countries, with The Gentlemen and Qilin significantly outpacing other major players. DragonForce, Akira, and LockBit followed, each linked to 100–150 incidents, though none matched the scale of the two leading groups.
ReliaQuest attributes The Gentlemen’s rapid rise to its aggressive affiliate recruitment and a pre-packaged intrusion kit that lowers the barrier to entry for new operators. The group provides affiliates with a detailed playbook, covering attack workflows, target selection (including edge devices), and tools like lightweight tunneling and SMB encryption for efficient deployment. Leaked chat logs also suggest The Gentlemen leverages AI tools to accelerate development, outpacing rivals in updating its malware and infrastructure.
Security analyst Tristano Di Liberto noted that The Gentlemen’s AI-driven build pipeline and proven affiliate throughput could entice operators from competing ransomware-as-a-service (RaaS) programs, potentially sustaining its dominance into Q3 2024. The group’s streamlined approach contrasts with the slower adaptation of established gangs, signaling a new phase in ransomware evolution.
Source: https://www.infosecurity-magazine.com/news/the-gentlemen-most-prolific/
DragonForce cybersecurity rating report: https://www.rankiteo.com/company/dragonforce
"id": "DRA1784283890",
"linkid": "dragonforce",
"type": "Ransomware",
"date": "4/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '1,368 victims',
'location': '99 countries'}],
'attack_vector': ['Affiliate recruitment',
'Pre-packaged intrusion kit',
'Edge devices',
'Lightweight tunneling',
'SMB encryption'],
'data_breach': {'data_encryption': 'Yes'},
'date_detected': '2024-04-01',
'date_publicly_disclosed': '2024-07-16',
'description': 'A recent analysis by cybersecurity firm ReliaQuest reveals '
'that The Gentlemen ransomware gang emerged as the most active '
'threat group between April and June 2024, responsible for 300 '
'incidents, surpassing long-standing leaders like Qilin. The '
"group's rapid rise is attributed to aggressive affiliate "
'recruitment and a pre-packaged intrusion kit that lowers the '
'barrier to entry for new operators.',
'investigation_status': 'Published analysis',
'lessons_learned': "The Gentlemen's rapid rise highlights the effectiveness "
'of aggressive affiliate recruitment, pre-packaged '
'intrusion kits, and AI-driven development in outpacing '
'competitors. Established ransomware groups may need to '
'adapt to maintain dominance.',
'motivation': ['Financial gain', 'Expansion of ransomware operations'],
'post_incident_analysis': {'root_causes': ['Aggressive affiliate recruitment',
'Pre-packaged intrusion kit',
'AI-driven development']},
'ransomware': {'data_encryption': 'Yes', 'ransomware_strain': 'The Gentlemen'},
'recommendations': ['Enhance monitoring for affiliate-based ransomware '
'operations',
'Implement AI-driven threat detection to counter evolving '
'ransomware tactics',
'Strengthen defenses around edge devices and SMB '
'encryption vulnerabilities'],
'references': [{'date_accessed': '2024-07-16', 'source': 'ReliaQuest'}],
'threat_actor': 'The Gentlemen ransomware gang',
'title': 'The Gentlemen Ransomware Gang Dominates Q2 2024 with Record Attacks',
'type': 'Ransomware'}