CERT-AGID maps The Gentlemen's use of LLMs: 500 victims in under a year, negotiation platform built in three days, self-replicating worm capability.

On May 4, 2026, a leak exposed The Gentlemen's internal communications. The ransomware group, formerly known as ArmCorp, has been active since March 2025. Within days, the operators migrated to decentralized platforms and continued operations. According to CERT-AGID analysis, large language model adoption is no longer experimental; it acts as a force multiplier across four critical phases of the attack lifecycle. The result is roughly 500 global victims in under a year, a volume that rivals established gangs despite a leaner structure.

Key Takeaways
  • The victim negotiation platform was developed in three days using LLM-based coding assistants, versus the traditional weeks.
  • AI personalizes extortion emails and phone contacts by extracting victim data to identify psychological pressure points.
  • The group stole internal data from rival organizations such as Black Basta to fine-tune its own LLMs.
  • The Go variant of the ransomware includes a --spread parameter that converts the payload into a self-replicating worm with automated lateral movement.
  • The RaaS model offers affiliates 90% of the ransom; the panel counts 34 registered affiliates.

The Attack Lifecycle Redesigned by Language Models

CERT-AGID's dossier outlines a positive feedback loop. Initial access occurs primarily through the purchase of legitimate credentials stolen by infostealers. Absent those, the group falls back to scanning for known, unpatched vulnerabilities in Cisco and Fortinet appliances.

From there, the payload propagates in five variants: Windows, Linux, ESXi, and a Go version equipped with the --spread flag. The latter is the automation core. The parameter transforms the ransomware into a self-replicating worm capable of automating encryption across the entire corporate network by exploiting lateral movement without human intervention.

Reliance on skilled operators drops sharply: an affiliate with valid credentials and a single manual execution can delegate propagation to the code. The technical novelty is not the worm itself, which has appeared in other contexts, but its combination with systematic LLM use to optimize every post-infection phase.

Negotiation, traditionally the human bottleneck, is handled through a platform built in three days instead of weeks. Victim communications are structured by prompts fed with AI-extracted data that autonomously identifies psychological weak points to exploit.

"Parasitic Learning": Fine-Tuning on Competitor Leaks

The third LLM use case documented by CERT-AGID is the most unusual. The Gentlemen used confidential data and internal manuals stolen from other cybercrime groups, notably Black Basta, to fine-tune or provide context for their own models. This creates a form of criminal "organizational learning" without field experimentation: the group assimilates proven tactics from larger gangs, reworks them through language models, and redistributes them to affiliates.

The operational model is RaaS with a 90% revenue share to affiliates, also confirmed by FortiGuard. According to Prodaft, the affiliate panel counts 34 registered users. The data leak site lists over 200 victims across more than 50 countries and 20 industries, per FortiGuard; CERT-AGID puts total victims at roughly 500 in under a year. The discrepancy may reflect publication delays on the leak site or different counting methodologies between actual and public victims.

"AI adoption is no longer merely theoretical; it acts as a genuine force multiplier for the gang's activities" — CERT-AGID

Identity and Structure: From ArmCorp to The Gentlemen

According to Prodaft's report, based on HUMINT and underground sources, the group was originally known as ArmCorp from March 2025. The transition to The Gentlemen occurred in 2025. The administrator is identified as hastalamuerte/zeta88, tracked by Prodaft under the code LARVA-368. Sources describe the operator as Russian-speaking, with possible familiarity with Hispanic-Latin American culture; nationality is undetermined.

FortiGuard questions the nature of the model, characterizing The Gentlemen as a "small, highly coordinated team" rather than a traditional structured RaaS. Whatever the actual hierarchy, AI automation enables a compact core to compete numerically with historic gangs. The May 2026 leak, related to the provider 4VPS, triggered an immediate migration to decentralized platforms without operational interruption.

Why It Matters

The Gentlemen case demonstrates four concrete mechanisms transforming ransomware: development time compression (three days versus weeks), psychological personalization of extortion, accelerated learning from others' data, and autonomous payload propagation. For organizations, this means a single initial access via stolen credentials or an unpatched vulnerability can escalate to full network encryption without further human intervention.

CERT-AGID provides its IoC feed service for detecting compromise indicators associated with the group. Feed subscription requires accreditation via a dedicated form on the institutional portal. The figure of 500 victims in under a year, with 34 affiliates and a 90% revenue share, indicates AI automation is lowering the barrier to entry in ransomware-as-a-service: reduced technical skill requirements, high attack volume, accelerated collective learning.

Frequently Asked Questions

What makes The Gentlemen different from other ransomware groups?

The dossier highlights systematic LLM use not only to accelerate coding but for accelerated tactical learning from competitor data. Fine-tuning on Black Basta leaks represents a documented meta-tactic that distinguishes the group from those merely using generic models for scripting or phishing.

Does the --spread parameter work without human interaction?

Yes, according to CERT-AGID the Go version with --spread converts the payload into a self-replicating worm that automates lateral movement and encryption of the entire network. Initial execution is still required, likely via compromised credentials or an exploited vulnerability.

How reliable is the 500-victim count?

The figure comes from CERT-AGID's investigative analysis, not per-case forensic verification. FortiGuard confirms at least 200 published on the data leak site. The total may include victims not yet disclosed or counts with different margins.

Information is based on the cited advisory and current as of publication.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. cert-agid.gov.it
  2. catalyst.prodaft.com
  3. fortiguard.com