Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Vulnerabilities

Gentlemen RaaS deploys multi-tool EDR evasion suite

A ransomware-as-a-service group maintains custom and third-party tools to disable endpoint defenses before encryption.

Gentlemen RaaS deploys multi-tool EDR evasion suite
Akingbola Opeyemi · Pexels

The Gentlemen ransomware-as-a-service (RaaS) operation has built a modular toolkit to disable endpoint detection and response (EDR) systems before launching encryption or data-theft attacks. Security researchers report that the group’s primary utility, dubbed GentleKiller, now exists in at least eight variants, each impersonating legitimate software and exploiting vulnerable drivers to gain kernel-level access on target machines.

How the toolkit works

GentleKiller variants share a common codebase and obfuscation methods but swap out the vulnerable driver used to escalate privileges. This design allows the group to quickly incorporate newly disclosed driver flaws without rewriting the core logic. Once elevated, the tool targets over 400 processes linked to approximately 48 security vendors, including Microsoft Defender, CrowdStrike Falcon, SentinelOne, Palo Alto Cortex, and ESET itself. The binaries are protected by commercial packers Enigma and Themida, and some samples carry invalid digital signatures stolen from legitimate applications.

In addition to GentleKiller, the Gentlemen RaaS toolkit includes at least three third-party EDR killers: HexKiller, ThrottleBlood, and HavocKiller. Researchers suggest these may provide redundancy, complicate attribution, or address scenarios where GentleKiller’s effectiveness is limited. A separate Rust-based credential-stealer, OxideHarvest, is also deployed, likely sourced externally given its programming language.

Background

Background: Endpoint detection and response (EDR) systems monitor and block suspicious activity on endpoints such as laptops, servers, and virtual machines. Ransomware groups routinely disable these defenses early in an attack to prevent alerts and allow unobstructed encryption or data exfiltration.

Target selection and recent activity

The group appears to prioritize organizations running FortiGate VPN endpoints, possibly leveraging credentials exposed in the FortiBleed leak of nearly 74,000 FortiGate VPN logins. While the timing of the leak is not specified in recent reports, the Gentlemen RaaS previously breached Romanian energy provider Oltenia. The operation has also been linked to a SystemBC proxy malware botnet comprising over 1,570 corporate hosts, which may serve as a command-and-control or data-exfiltration channel.

For professionals

For professionals: Security teams should audit driver allow-lists and monitor for unexpected kernel-level process termination. Regular breach-and-attack simulation can identify gaps in EDR and SIEM rules before attackers exploit them.

What to watch

The modular design of GentleKiller suggests the group will continue to weaponize newly disclosed driver vulnerabilities. Security vendors may also see increased use of stolen or forged digital signatures to bypass code-signing checks. Organizations running FortiGate appliances should rotate VPN credentials and review patch levels, particularly if credentials were exposed in the FortiBleed incident.

Discussion · coming soon

Be the first to join the thread when community discussion launches.