Researchers have uncovered a fast and highly destructive ransomware playbook used by The Gentlemen ransomware-as-a-service (RaaS) operation.
The group, tracked as GOLD SHERWOOD, steals data, disables security tools and backup services, then encrypts systems across victim networks.
The attacks can move from initial access to ransomware deployment in less than 24 hours. Researchers found a median time of about two days between the first post-compromise activity and encryption.
The Gentlemen emerged in mid-2025 and operates a double-extortion model. Affiliates first steal sensitive files and threaten to publish them if victims refuse to pay.
They then deploy ransomware to lock files and disrupt operations. The gang’s leak site had listed 683 victims by the end of July 2026, including 169 added during July alone.
Researchers said the group targets organizations opportunistically across many industries. Affiliates appear to gain access by exploiting exposed firewall vulnerabilities or using stolen VPN credentials.
In one incident, attackers logged in to a Fortinet SSL VPN with compromised credentials where multi-factor authentication was not enabled.
Ransomware Disables Defenses
After entering a network, affiliates use legitimate credentials and common administrative tools to avoid raising alarms. They move laterally through Remote Desktop Protocol (RDP), targeting file servers and domain controllers.
Attackers often store their tools in C:\PerfLogs, a legitimate Windows directory that may receive less attention from administrators. These tools can include network scanners, data theft utilities, EDR-killing programs, and backup-related software.
The actors use tools such as Advanced IP Scanner and SoftPerfect Network Scanner to identify important systems, backup servers, and data repositories.
They also seek access to high-value accounts, sometimes changing administrator passwords or adding accounts to local Administrators and Domain Admins groups.
For persistence, the group has enabled RDP through Windows Registry changes and opened firewall port 3389.
In another case, attackers installed Cloudflared as a Windows service, creating a hidden remote-access channel that could continue working even if the original VPN access was removed.
Before encryption, affiliates steal selected files using Rclone, their preferred exfiltration tool. They also use Restic, FileZilla, MEGAsync, and MinIO Client depending on the victim environment.

The activity shows that the group adapts its tools when data size, transfer speed, or network restrictions become obstacles. A key part of The Gentlemen attacks is defense evasion.
Affiliates attempt to terminate antivirus and endpoint detection and response (EDR) tools before launching ransomware.
They use custom tools known as GentleKiller, as well as publicly available utilities, to abuse vulnerable drivers through the Bring Your Own Vulnerable Driver technique, sophos said.
Indicators of Compromise
| Indicator | Type | Associated File / Tool | Context |
|---|---|---|---|
622b2ca08552535bc142cb815ff9ec16 | MD5 | acronis.exe | Havoc EDR-killer variant |
f0bc50d2d2838c5294e21cd9bce2f09bf581e508 | SHA1 | acroni |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN
Click Here For The Original Source.
