A new ransomware-as-a-service platform called Gentlemen's RaaS has recently appeared on underground hacking forums, offering malicious users a sophisticated cross-platform.

The service, promoted by malicious user zeta88, represents a significant expansion in ransomware distribution models, targeting critical infrastructure across multiple operating systems. This development signals an intensified threat landscape, where organized cybercriminals are offering “partner-based ransomware operations” to lower-level attackers, facilitating access to encryption malware.
See also: Phishing: Distribution of PureHVNC RAT via court documents
The service leverages an attractive business model that distributes 90% of ransomware revenue to partners, while retaining only 10% for the administrator. This generous revenue sharing structure has proven to be particularly attractive to potential partners within the cybercriminal ecosystem. By offering these financial incentives, the platform encourages widespread adoption and rapid growth across global organizations.
The architecture reflects a deliberate strategy to scale ransomware operations efficiently, while maintaining operational control through a centralized decryption infrastructure.

KrakenLabs researchers identified the malware after a detailed analysis of promotional materials circulating on hacking forums.
The platform features sophisticated technical construction with separate lockers designed for specific platforms.
See also: Gunra ransomware attacks Windows and Linux
Gentlemen's RaaS: Lateral movement
The most notable technical elements include the malware's persistence and lateral movement mechanisms
Gentlemen's RaaS is developing a Go-based locker targeting Windows, Linux, NAS, and BSD, while using a separate C-coded ESXi locker, about 32 kilobytes in size. The encryption is implemented using XChaCha20 in combination with Curve25519 cryptography and per-file temporary keys.
Particularly concerning is the ability to self-propagate via WMI, WMIC, SCHTASKS, SC, and PowerShell Remoting commands, allowing rapid network traversal.
See also: GhostCall & GhostHire: BlueNoroff's new campaigns

The malware establishes persistence via schtasks registry modifications and run-on-boot routines, ensuring survival across system reboots and administrative interventions. Additionally, the platform supports shared network discovery and automatic encryption, allowing the ransomware to locate and compromise adjacent systems without any problems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
