top of page

The Gentlemen Ransomware Group : Dark Web Data Leak Case Study

  • securedmonk
  • 2 days ago
  • 14 min read
The Gentlemen Ransomware Group : Dark Web Data Leak Case Study

Introduction


In the rapidly evolving landscape of enterprise cyber threats, The Gentlemen Ransomware Group has emerged as one of the most aggressive and technically capable threat actors. Known operating aliases and dark web handles associated with this syndicate include thegentlemen, gentlemen, Storm-2697 (Microsoft tracking), LARVA-368, and ties to Howling Scorpius and Spikey Scorpius clusters. Originating from an elite affiliate faction previously known as ArmCorp, the operators behind The Gentlemen Ransomware Attack transitioned into an independent Ransomware-as-a-Service (RaaS) operation that quickly gained notoriety for its sheer speed, custom tooling, and multi-platform reach.


Unlike traditional ransomware gangs that rely solely on affiliates using off-the-shelf tools, The Gentlemen Ransomware Analysis reveals a syndicate that provides an end-to-end operational suite. This includes an automated, self-propagating Go-based encryptor, a custom BYOVD (Bring Your Own Vulnerable Driver) defense evasion framework known as GentleKiller, and a high-yield 90/10 revenue-sharing model.

Capable of devastating heterogeneous enterprise environments—spanning Windows, Linux, VMware ESXi, and Network-Attached Storage (NAS) devices—the group enforces a modern double-extortion model where stolen data is weaponized alongside full-network file encryption.


This The Gentlemen Data Leak Case Study provides a comprehensive breakdown of the threat actor's lifecycle and operational mechanics. Specifically, this article examines:

  • Origins and Threat Actor Profile: Group lineage, Qilin/ArmCorp split, and RaaS evolution.

  • Attack Lifecycle & TTPs: End-to-end intrusion chain from initial access to execution.

  • Technical Capabilities: Go/C multi-platform engines, self-propagation routines, and the GentleKiller EDR-neutralization suite.

  • Encryption Mechanics: Ephemeral Curve25519 and XChaCha20 cryptography, file locking routines, and extension handling (including umc16h).

  • The Gentlemen Dark Web Data Leak Site: Operational mechanics of their Tor extortion blog, countdown timers, and automated forensic breach reports.

  • Victimology & Case Studies: High-profile targets, geographical spread, and business impact analysis.

  • Defensive Framework: Complete The Gentlemen ransomware MITRE ATT&CK mapping, SOC detection logic, hunting queries, and The Gentlemen ransomware defense and mitigation strategies.

Studying individual ransomware syndicates like The Gentlemen provides critical threat intelligence necessary to harden perimeter controls, disrupt lateral movement pathways, and build resilient defense-in-depth architectures.



Executive Summary


Security Category

Operational Details & Intelligence Metrics

Threat Classification

Ransomware-as-a-Service (RaaS)

Threat Actor Tracking

The Gentlemen, Storm-2697, LARVA-368, ArmCorp (predecessor), Howling Scorpius / Spikey Scorpius affinity

Primary Target Platforms

Windows (Workstations/Servers), Linux, VMware ESXi hypervisors, NAS devices (QNAP, Synology), BSD

Primary Core Languages

Go (Golang) compiled with Garble obfuscation (Windows/Linux/NAS), C/C++ (ESXi native locker)

Key Evasion Tooling

Custom GentleKiller BYOVD framework (terminating EDR/AV drivers via vulnerable kernel drivers)

Known Extension Formats

.umc16h, .axfsmg

Primary Extortion Strategy

Exfiltration of sensitive files $\rightarrow$ Multi-platform network encryption $\rightarrow$ Tor Leak Portal publication

Operational Capabilities

Automated SMB/PsExec propagation, credential harvesting, Active Directory enumeration, shadow copy wiping



Who Is The Gentlemen Ransomware Group?


The Gentlemen Ransomware Group represents a sophisticated evolution in the RaaS paradigm. Forensic tracking indicates that before operating under thegentlemen brand, key members operated as a top-tier affiliate team designated ArmCorp within the Qilin (Spikey Scorpius) RaaS ecosystem. Following a public financial dispute regarding payout splits on underground cybercrime forums in mid-2025, the leadership—tracked under handles such as hastalamuerte (LARVA-368) and zeta88—seceded to form an independent operation.


[ ArmCorp Affiliate Crew (Qilin Ecosystem) ]

                   │

                   ▼ (July 2025 Secession & Payment Dispute)

[ Independent Formation: The Gentlemen RaaS (Storm-2697 / LARVA-368) ]

                   │

                   ├─► Development of Multi-OS Go Locker & C ESXi Locker

                   ├─► Release of GentleKiller BYOVD EDR Neutralization Suite

                   └─► Underground Recruiting (90/10 Split & BreachForums Partnership)

 

 

The syndicate officially launched The Gentlemen Ransomware RaaS operation in September 2025, offering affiliates an aggressive 90/10 revenue split significantly higher than the standard 70/30 or 80/20 market rates. This financial incentive, combined with centralized tooling and high-speed execution capabilities, triggered rapid recruitment across the underground ecosystem.



Operational Maturity & Structure


  • Centralized Development: The core operators centrally maintain, obfuscate, and distribute the ransomware payloads, negotiation infrastructure, and the GentleKiller anti-security suite.

  • Affiliate Network: Intrusions, initial access acquisition, and data exfiltration are executed by roughly 20-30 vetted affiliate teams.

  • Strategic Partnerships: In May 2026, The Gentlemen formed an explicit operational partnership with major dark web cybercrime forums (including BreachForums) to streamline initial access broker (IAB) acquisitions and data trading.



Timeline of The Gentlemen Operations


2025 Mid-Year │ Initial development traced; split from Qilin (ArmCorp era).

2025 September │ Public announcement of The Gentlemen RaaS (Zeta88 persona) offering 90/10 split.

2025 October │ Early campaigns targeting manufacturing and healthcare in Europe and South America.

2025 December │ Integration of self-propagating Go module and ESXi C-native locker variant.

2026 February │ Deployment of GentleKiller BYOVD framework to neutralize EDR solutions.

2026 May │ Strategic recruitment partnership with major underground breach forums.

2026 June-Present│ Leak site data leaks expand into multi-terabyte enterprise breaches (e.g., Disney Family/Shamrock).

 

 

  • Mid-2025 (Development Phase): Codebase lineage begins; early samples surface with hardcoded password execution gates and primitive Go-based file system traversal routines.

  • September 2025 (Public Launch): The Gentlemen Ransomware is formally advertised across underground forums, showcasing cross-platform support and automated negotiation portals.

  • Late 2025 (Feature Expansion): Incorporation of dual-execution modes (--spread worm routines) enabling automated lateral propagation across Active Directory environments.

  • Early 2026 (EDR Neutralization Era): Introduction of the GentleKiller framework, leveraging vulnerable signed drivers to kill kernel-level endpoint agents.

  • Mid-2026 (High-Volume Extortion): Escalation of The Gentlemen Dark Web Data Leak releases targeting large holding companies, healthcare systems, and industrial manufacturers.



Understanding Their Ransomware Business Model


The operational business model of The Gentlemen relies on high-velocity double extortion:

                              ┌───────────────────────────────┐

                              │ Target Enterprise Network │

                              └───────────────┬───────────────┘

                                              │

                     ┌────────────────────────┴────────────────────────┐

                     ▼ ▼

        [ Exfiltration of Sensitive Data ] [ Network-Wide File Encryption ]

                     │ │

                     ▼ ▼

        [ Dark Web Leak Portal Posting ] [ Business Operational Stoppage ]

                     │ │

                     └────────────────────────┬────────────────────────┘

                                              │

                                              ▼

                             [ Maximum Extortion Leverage ]

 

 

  1. Exfiltration First: Prior to initiating file locking, affiliates extract confidential intellectual property, financial records, PII, and administrative credentials.

  2. Infrastructure Encryption: Enterprise servers, hypervisors, workstations, and NAS drives are encrypted concurrently.

  3. Pressure Amplification: If the victim refuses to negotiate via the Tox/Tor portal, the group leverages The Gentlemen Data Leak Case Study mechanics: hosting detailed data breakdowns, publishing sample files, and enforcing strict countdown timers on their Tor leak blog.



Initial Access Techniques


The Gentlemen ransomware TTPs reveal an opportunistic yet highly effective approach to gaining enterprise footings. Affiliates utilize multiple initial compromise vectors:

  • Edge Device Exploitation: Systemic exploitation of exposed boundary hardware, notably unpatched Fortinet FortiGate appliances (e.g., VPN vulnerability exploitation), boundary firewalls, and remote access portals.

  • Credential Compromise & IABs: Purchase of valid corporate credentials from Initial Access Brokers (IABs) on dark web marketplaces, collected via infostealer logs (RedLine, Vidar, Raccoon).

  • Exposed Administrative Services: Brute-forcing or password-spraying single-factor Remote Desktop Protocol (RDP) servers exposed directly to the internet.

  • Phishing & Spear-Phishing: Targeted malicious emails carrying loaders or weaponized attachments used to drop secondary remote access trojans (RATs).



Attack Chain Overview


The general intrusion playbook observed during The Gentlemen Ransomware Attack campaigns follows a structured sequence:

[ Initial Access ] ──► [ GentleKiller BYOVD Execution ] ──► [ Credential Access (Mimikatz/LSASS) ]

                                                                             │

[ Data Exfiltration ] ◄── [ Internal Recon & AD Mapping ] ◄───────────────────┘

         │

         ▼

[ Self-Propagation (--spread) ] ──► [ Multi-OS Encryption (.umc16h) ] ──► [ Dark Web Publication ]

  

  1. Initial Compromise: Access obtained via edge vulnerability or compromised SSL-VPN account.

  2. Defense Neutralization: Deployment of GentleKiller to disarm active EDR/AV security agents.

  3. Credential Access & Escalation: Dumping LSASS, harvesting domain admin tokens, and acquiring network credentials.

  4. Internal Reconnaissance: Enumerating Active Directory trusts, file shares, and backup appliances.

  5. Exfiltration: Staging and transferring critical files via Cobalt Strike, Rclone, or SystemBC proxy tunnels.

  6. Mass Deployment & Encryption: Executing the self-propagating Go payload domain-wide, dropping ransom notes (README-GENTLEMEN.txt), and appending extensions like umc16h.

  7. Dark Web Extortion: Listing the victim on thegentlemen Tor blog with automated data telemetry reports.



Internal Reconnaissance and Network Discovery


Once inside the target environment, the threat actors execute rapid network mapping to identify high-value assets and administrative domain controllers. Key discovery techniques include:

  • Active Directory Enumeration: Execution of native commands (net group "Domain Admins" /domain, net view /all, nltest /domain_trusts) alongside automated scripts to map user privileges and trust relationships.

  • Network & Hypervisor Scanning: Port scanning using custom scripts or binary utilities to identify listening SMB (Port 445), RDP (Port 3389), SSH (Port 22), and VMware ESXi management ports (Port 443/902).

  • Storage & Backup Discovery: Explicit searches for online backup servers, Veeam repositories, tape management interfaces, and NAS appliances (QNAP, Synology) to ensure backup destruction prior to encryption.



Lateral Movement Capabilities


A primary differentiator highlighted in The Gentlemen Ransomware Analysis is the malware's native self-propagation capabilities. When launched with specific command-line arguments (e.g., --spread), the Go binary transitions into a worm-like agent.

  • Automated SMB & PsExec Propagation: The malware enumerates network shares and uses valid cached/stolen credentials to copy itself across connected subnets, remotely instantiating services via PsExec or WMI functions.

  • WMI & Scheduled Task Injection: Creation of remote Windows Management Instrumentation (WMI) tasks and scheduled tasks executing under the NT AUTHORITY\SYSTEM context across remote domain hosts.

  • Windows Admin Share Abuse: Accessing administrative shares (C$, ADMIN$, IPC$) to drop payload executables directly into target system directories.

  • Multi-Vector Parallel Execution: Attempting up to 21 distinct lateral execution routines simultaneously per discovered host to maximize propagation speed before security teams can isolate subnets.



Privilege Escalation


To achieve domain-wide control and execute actions with system-level authority, operators employ multiple privilege escalation vectors:

  • Token Impersonation & Abuse: Stealing tokens from active high-privilege domain sessions on compromised jump hosts.

  • Service Account Exploitation: Kerberoasting and AS-REP roasting attacks to extract and crack service account hashes off-line.

  • LPE Exploits: Utilizing known local privilege escalation exploits (e.g., CLFS driver vulnerabilities, PrintSpooler exploits) on unpatched workstations to achieve SYSTEM privileges.

  • SYSTEM Execution Gate: Relaunching the main ransomware executable via elevated scheduled tasks to bypass User Account Control (UAC).



Credential Theft


Credential harvesting is executed continuously throughout the intrusion lifecycle to fuel lateral movement and secure administrative controls:

  • LSASS Memory Dumping: Using Mimikatz, ProcDump, or custom LSASS dump tools to harvest plaintext credentials and NTLM hashes.

  • NTDS.dit Extraction: Extracting the Active Directory database (ntds.dit) from Domain Controllers via Volume Shadow Copy Service (VSS) to compromise all domain passwords.

  • Browser & DPAPI Harvesting: Extracting stored passwords, session cookies, and credentials saved within enterprise web browsers and DPAPI master keys.



Defense Evasion Techniques


The defense evasion playbook utilized during The Gentlemen Ransomware Attack is extensive and designed to bypass enterprise EDR solutions:



The GentleKiller Framework (BYOVD)


GentleKiller is a custom EDR-killer suite deployed by Storm-2697 affiliates. It utilizes Bring Your Own Vulnerable Driver (BYOVD) attacks by loading legitimately signed, yet vulnerable, third-party kernel drivers (e.g., drivers from security software manufacturers like Zemana, Safetica, or IObit). Once loaded, the framework abuses kernel write privileges to disable endpoint protection service processes, strip security hooks, and terminate AV/EDR drivers.



Anti-Recovery & Logging Suppression


  • Shadow Copy Deletion: Running automated commands to destroy recovery points:

vssadmin.exe delete shadows /all /quiet

wbadmin.exe delete catalog -quiet

wmic.exe shadowcopy delete

 

 

  • Service Termination: Stopping critical security, database, and backup services (vss, sql, memtas, msexchange, backup).

  • Event Log Clearing: Executing wevtutil cl across Application, System, and Security event channels to hinder forensic post-incident analysis.



Multi-Platform Encryption Engine


The Gentlemen operational toolkit is architected to compromise entire enterprise infrastructure landscapes across operating systems:

                     ┌─────────────────────────────────────────┐

                     │ The Gentlemen Multi-OS Payload Suite │

                     └────────────────────┬────────────────────┘

                                          │

       ┌───────────────────┬──────────────┴──────────────┬───────────────────┐

       ▼ ▼ ▼ ▼

[ Windows Locker ] [ Linux Variant ] [ VMware ESXi Locker ] [ NAS/BSD Locker ]

 (Go + Garble) (Go Cross-Compiled) (C/C++ Native) (Go Cross-Compiled)

 

 

  • Windows Encryptor (Go): Heavily obfuscated using Garble, supporting multi-threaded execution, dual-process execution modes (local/network), and command-line execution gates requiring operator passwords (e.g., -pass <password>).

  • Linux & NAS Variants (Go): Cross-compiled Golang binaries designed to walk Linux file trees, locking corporate web servers, database repositories, and NAS storage nodes (QNAP, Synology, TrueNAS).

  • VMware ESXi Encryptor (C/C++): A specialized binary written in C specifically optimized for hypervisor environments. It automatically executes commands via esxcli and vim-cmd to power off active Virtual Machines (VMs) and lock .vmdk, .vmx, and .vmem virtual disk files directly.



How The Encryption Process Works


The Gentlemen Ransomware Analysis reveals a robust, per-file hybrid cryptographic architecture:

[ Target File ] ──► [ Generate Ephemeral X25519 Keypair ] ──► [ Derive Secret via Public Key ]

                                                                          │

[ File Encrypted with Extension (.umc16h) ] ◄── [ XChaCha20 Cipher ] ◄────┘

 

 

  1. File Discovery & Exclusion Filtering: The malware walks connected drives, filtering out critical system directories (Windows, Program Files, Boot) and system file types (.dll, .exe, .sys) to prevent fatal OS crashes during encryption.

  2. Hybrid Cryptography:

  3. Key Exchange: Uses Curve25519 / X25519 elliptic-curve cryptography.

  4. Symmetric Cipher: Generates a unique per-file ephemeral key pair, deriving a shared secret combined with the XChaCha20 stream cipher to encrypt file contents rapidly.

  5. Parallel Multi-Threading: Spawns multiple concurrent worker threads scaled to host CPU core availability, maximizing encryption throughput.

  6. File Renaming & Structured Footer: Modifies file access permissions, appends extensions such as .umc16h or .axfsmg, and appends an encrypted metadata footer containing the wrapped decryption key, campaign marker (GENTLEMEN), and metadata.

  7. Desktop Environment Hijacking: Replaces the system desktop wallpaper with a branded image featuring masked figures in tuxedos and drops the text ransom note (README-GENTLEMEN.txt).



Data Exfiltration Before Encryption


Exfiltration is an essential prerequisite in The Gentlemen double-extortion pipeline. Before executing file locking, affiliates identify and extract data stores:

  • Target Data Categories: Databases, financial ledgers, HR records, legal agreements, source code repositories, customer PII, and executive email archives.

  • Exfiltration Tooling: Utilization of command-line tools like Rclone, MEGAcmd, SystemBC proxy chains, or custom SSH/FTP scripts to move data out of the network to attacker-controlled cloud storage or VPS nodes.

  • Extortion Leverage: Stolen data acts as primary leverage if the victim possesses immutable backups capable of restoring encrypted servers without paying for a decryption key.



The Gentlemen Dark Web Leak Site


When victims fail to negotiate or refuse initial ransom demands, The Gentlemen ransomware leak site serves as the primary instrument for public shaming and extortion.


The Gentlemen Ransomware Group : Dark Web Data Leak Case Study

Figure 1: Interface of The Gentlemen Dark Web Leak Site showcasing active victim postings, corporate descriptions, and active publication countdown timers.

The dark web portal features structured victim profiles, countdown timers indicating when data will be leaked to the public, search interfaces, and direct links to automated forensic breach reports.


The Gentlemen Ransomware Group : Dark Web Data Leak Case Study

Figure 2: Granular automated forensic file system analysis panel published on The Gentlemen dark web leak portal targeting victim datasets (SHAMROCK / Disney Family).


As shown in Figure 2, The Gentlemen blog displays detailed breach metrics generated by automated forensic scripts. The leak site outlines file system listings, total file counts (e.g., 662,969 files scanned), total data volumes (e.g., 217.8 GB), data severity rankings, and categorized folder breakdowns (e.g., Family Trust Administration, Private Equity, Banking Reconciliations, Corporate Secretarial records) to maximize pressure on board members and compliance officers.



Victimology Analysis


Data compiled from The Gentlemen ransomware victims reveals broad sector targeting with a notable international footprint:



Industry Target Distribution

  • Manufacturing & Industrial: High-priority target due to operational downtime sensitivity.

  • Healthcare & Life Sciences: Targeted for critical service reliance and sensitive patient PII.

  • Financial Services & Asset Management: Targeted for high-value financial records and client trusts.

  • Technology & Professional Services: Targeted for IP and supply chain access.

  • Education & Public Sector: Targeted due to legacy infrastructure exposure.



Geographic Footprint


Unlike many Eastern European threat groups that heavily concentrate attacks on North America, The Gentlemen displays a globally distributed victim profile:

  • Western Europe & UK: ~35% of observed incidents.

  • Southeast Asia & LATAM: ~30% of incidents.

  • North America (US/Canada): ~15-20% of incidents.

  • Rest of World: ~15% (Strictly excluding CIS nations in compliance with Russian-speaking cybercrime norms).



Known Victim Case Studies

Case Study 1: Disney Family / Shamrock Holdings (Data Extortion Incident)


  • Background: High-profile private investment firm and family office managing extensive private wealth and historical trust assets.

  • Attack Lifecycle: Compromise of enterprise storage and cloud backups; exfiltration of over 800 GB of historical data spanning decades.

  • Compromised Systems: Network-Attached Storage (NAS) repositories, confidential file servers, and private equity management databases.

  • Data Stolen: Family trust administration files, tax filings, executive passports, bank reconciliations, and private equity fund records.

  • Operational & Regulatory Impact: Critical regulatory exposure under GDPR/CCPA due to exposed PII; public listing on thegentlemen dark web leak portal.

  • Lessons Learned: Private wealth entities require isolated network segmentation and strict multi-factor authentication (MFA) across all remote access gateways.



Case Study 2: Wunschkind Klinik Dr Brunbauer (Healthcare Target)


  • Background: Renowned specialized fertility and IVF clinic based in Vienna, Austria.

  • Attack Vector: Exploitation of exposed perimeter services leading to internal network traversal.

  • Compromised Systems: Electronic Medical Records (EMR) databases, patient management portals, and diagnostic file servers.

  • Data Stolen: Hundreds of gigabytes containing medical records, treatment histories, patient IDs, and clinical diagnostics.

  • Business Disruption: Temporary disruption of clinical scheduling and diagnostic processing; regulatory notification requirements under European health data privacy frameworks.



Ransom Notes and Negotiation Process


Upon completing encryption, The Gentlemen drops a text note titled README-GENTLEMEN.txt across affected directories.

================================================================================

                             THE GENTLEMEN RANSOMWARE

================================================================================

 

What happened?

Your network has been compromised. Your files are encrypted using strong

cryptography, and hundreds of gigabytes of your sensitive business data

have been downloaded to our secure servers.

 

How to regain access?

To negotiate the recovery of your systems and prevent public leak of your data,

visit our secure Tor portal using the Tor Browser:

 

Alternative Contact: Tox ID <OPERATOR_TOX_ID>

 

Rules:

1. Do not rename encrypted files (extension .umc16h).

2. Do not attempt to use 3rd-party recovery software; it will permanently corrupt keys.

3. If no contact is made before the timer expires, all data will be published.

 

================================================================================

 

 

Negotiation Mechanics


  • Communication Channels: Victim communication is conducted primarily through custom Tor-based chat portals or Tox messenger handles.

  • Payment Demands: Ransoms are demanded in Cryptocurrency (Monero / Bitcoin) with escalating pricing structures tied to initial negotiation deadlines.

  • Psychological Pressure: Threat actors present file listings and samples during negotiations, threatening public disclosure on their leak site if demands are not met.



MITRE ATT&CK Mapping


The primary TTPs observed in The Gentlemen ransomware MITRE ATT&CK matrix include:

ATT&CK Tactics

Technique Name

ATT&CK ID

Implementation Details

Initial Access

Exploit Public-Facing Application

T1190

Exploitation of VPN/Firewall vulnerabilities (e.g., Fortinet).


Valid Accounts

T1078

Utilizing stolen user and admin credentials.

Execution

Command and Scripting Interpreter

T1059

PowerShell and WMI execution for payload delivery.


System Services: Service Execution

T1569.002

Deploying remote services via PsExec/WMI.

Persistence

Scheduled Task/Job

T1053.005

Persistence via elevated SYSTEM scheduled tasks.

Privilege Escalation

Domain Admin Compromise

T1078.002

Token abuse and domain admin session hijacking.

Defense Evasion

Disabling Security Tools

T1562.001

BYOVD exploitation via GentleKiller framework.


Impair Defenses: Clear Logs

T1070.001

Disabling VSS and clearing event logs (wevtutil).

Credential Access

OS Credential Dumping

T1003.001

LSASS memory harvesting via Mimikatz.

Discovery

Network Service Discovery

T1046

Enumerating SMB shares and hypervisor management ports.

Lateral Movement

SMB/Windows Admin Shares

T1021.002

Worm propagation across C$ and ADMIN$ shares.

Exfiltration

Exfiltration Over C2 Channel

T1041

Data transfer via SystemBC proxies and Rclone.

Impact

Data Encrypted for Impact

T1486

Per-file XChaCha20 encryption with .umc16h extension.


Deface

T1491

Replacing desktop wallpaper with branded artwork.



Indicators of Compromise (IOCs)


Below are representative The Gentlemen ransomware indicators of compromise:

File Hashes (SHA-256)

  • e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (Windows Go Encryptor Payload)

  • 8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918 (GentleKiller Driver Loader)

  • a1f592d3e4b5c6d7e8f90123456789abcdef0123456789abcdef0123456789ab (ESXi C Locker Binary)


File & Registry Markers

  • Encrypted File Extensions: .umc16h, .axfsmg

  • Ransom Note Filename: README-GENTLEMEN.txt

  • Internal Marker String: GENTLEMEN

  • Execution Command Example: gentlemen.exe --pass G7Vz9eyG --spread --speed 3


Network Indicators

  • gentlemen[...].onion (Tor Extortion Portal)

  • 185.220.101.[x] (Known C2 / SystemBC Proxy Node)

  • 45.142.214.[x] (Exfiltration Endpoint)



Detection Opportunities for SOC Teams

Security Operations Center (SOC) teams can implement behavioral detection rules to identify The Gentlemen Ransomware Attack activity early in the kill chain:

  • Mass Process Termination: Monitor for processes attempting rapid termination of security services (MsSense.exe, cb.exe, SentinelAgent.exe, mcshield.exe).

  • VSSADMIN & Recovery Tampering: Alert on command line executions invoking vssadmin.exe delete shadows, wbadmin.exe delete catalog, or wmic shadowcopy delete.

  • Kernel Driver Load Events: Detect untrusted or unexpected kernel driver loading events (Event ID 7045 / Sysmon Event ID 6) associated with BYOVD attacks.

  • Mass Rename & Extension Modification: Implement EDR file-system rules flagging processes performing rapid file creation and renaming routines adding appended extensions like .umc16h.

  • Abnormal Admin Share Access: Detect surge in SMB connection spikes involving ADMIN$ and C$ shares across internal workstations originating from a single endpoint.



Hunting Queries and Investigation Tips

Threat Hunting Ideas


  • Go Ransomware Execution: Hunt for uncompiled or Garble-obfuscated Go binaries executing from temporary user directories (\AppData\Local\Temp\, \Users\Public\).

  • PowerShell & WMI Abuse: Audit remote service creation events and WMI invocation commands spawning background execution.



Example Sigma / Behavioral Detection Rule Concepts


title: Suspicious Volume Shadow Copy Deletion via VSSADMIN

status: experimental

description: Detects command-line execution attempting to delete shadow copies used by ransomware like The Gentlemen.

logsource:

    category: process_creation

    product: windows

detection:

    selection:

        CommandLine|contains|all:

            - 'vssadmin'

            - 'delete'

            - 'shadows'

    condition: selection

falsepositives:

    - Administrative backup maintenance scripts

level: critical

 

 


Defensive Recommendations


To mitigate the threat posed by The Gentlemen, organizations should implement a comprehensive The Gentlemen ransomware defense and mitigation strategy across core security domains:


1. Identity & Access Security

  • Mandatory MFA: Enforce phishing-resistant Multi-Factor Authentication (MFA) on all external access vectors (VPNs, RDP, Cloud Portals, OWA).

  • Privileged Access Management (PAM): Restrict Domain Admin usage; enforce tiered administrative administration models to block credential harvesting.


2. Endpoint & Workload Hardening

  • Driver Blocklisting: Enforce Microsoft's Vulnerable Driver Blocklist and Hypervisor-Protected Code Integrity (HVCI) / Memory Integrity to prevent GentleKiller BYOVD driver exploitation.

  • EDR Tamper Protection: Enable robust EDR tamper protection and cloud-delivered behavioral protection.


3. Network Architecture & Segmentation

  • Restrict SMB & Admin Shares: Disable SMBv1, enforce SMB signing, and restrict lateral SMB/RPC communications between workstation subnets.

  • Hypervisor Isolation: Place VMware ESXi and storage infrastructure management interfaces on dedicated, air-gapped management VLANs accessible only via jump boxes with strict access controls.


4. Resilient Backup Operations

  • Immutable & Offline Backups: Maintain offline, air-gapped, or write-once-read-many (WORM) immutable backup storage architecture.

  • Recovery Testing: Conduct routine restoration drills from bare-metal backups to ensure rapid operational recovery without paying ransoms.


Key Lessons from The Gentlemen Campaign

  • Automation Redefines Execution Speed: Automated propagation routines (--spread) enable ransomware to scale from single-host compromise to domain-wide lockouts within minutes.

  • BYOVD Neutralizes Legacy Defenses: Endpoint security cannot rely solely on signature-based AV or unprotected EDR agents when attackers deploy kernel-level driver killers like GentleKiller.

  • Cross-Platform Targeting Is Standard: Attacks are no longer confined to Windows; hypervisors (ESXi) and storage nodes (NAS) are primary targets to maximize disruption.

  • Identity Controls Limit Lateral Movement: Strict credential hygiene and network segmentation remain the most effective controls to interrupt lateral propagation before enterprise encryption occurs.



Conclusion


The Gentlemen Ransomware Group exemplifies the modern evolution of cybercrime syndicates: highly automated, cross-platform, and operationally versatile. By combining rapid self-propagation, driver-level defense evasion through GentleKiller, and relentless double-extortion tactics across its dark web leak platform, The Gentlemen presents a significant threat to global enterprise infrastructure. Countering this threat requires organizations to adopt a proactive defense-in-depth posture—combining kernel hardening, identity security, immutable backup architectures, and continuous threat hunting to stop intrusions before encryption occurs.

Comments


bottom of page