The Gentlemen encrypt your whole network in one move

Peer Review

Gartner brand name text logo in white with registered trademark symbol.
5-star rating
4.8

Proven Trust

Dark blue circle with two overlapping checkmarks, one green and one light blue.
ISO 27001 text with a globe outline symbol on a black background.
2025 winner badge for Cyber Security Excellence Awards with gold and black design.

The Gentlemen split from Qilin and now encrypt entire domains at once. See its attack chain and how to stop it early.

Get Guide

Your firewall isn't the only edge device at risk

Success here means stopping the domain-wide push before GentleKiller blinds your security tooling, not cleaning up after every machine is already encrypted.

  • Exploits exposed FortiOS, FortiProxy and Cisco/Erlang SSH devices, or stolen domain credentials
  • Deploys GentleKiller, an in-house EDR-killer suite, to blind security tools before moving
  • Uses NETLOGON group policy abuse to encrypt every domain-joined system at once

Who This Guide is For

CISO / Head of Security

A 90/10 affiliate split is pulling talent from every other RaaS operation. This guide covers the edge-device and credential hardening that keeps you off their list.

SOC Manager / Security Operations Lead

By the time NETLOGON abuse starts, it's too late to react manually. This guide explains what detection needs to catch before mass propagation.

IT Director / Head of IT

Unpatched FortiGate and Cisco appliances are the way in. This guide sets out the patching and credential hygiene that closes that door.