Ransomware Hackers Disable Security Tools and Backups Before Encrypting Entire Networks | #ransomware | #cybercrime


Researchers have uncovered a fast and highly destructive ransomware playbook used by The Gentlemen ransomware-as-a-service (RaaS) operation.

The group, tracked as GOLD SHERWOOD, steals data, disables security tools and backup services, then encrypts systems across victim networks.

The attacks can move from initial access to ransomware deployment in less than 24 hours. Researchers found a median time of about two days between the first post-compromise activity and encryption.

The Gentlemen emerged in mid-2025 and operates a double-extortion model. Affiliates first steal sensitive files and threaten to publish them if victims refuse to pay.

They then deploy ransomware to lock files and disrupt operations. The gang’s leak site had listed 683 victims by the end of July 2026, including 169 added during July alone.

Researchers said the group targets organizations opportunistically across many industries. Affiliates appear to gain access by exploiting exposed firewall vulnerabilities or using stolen VPN credentials.

In one incident, attackers logged in to a Fortinet SSL VPN with compromised credentials where multi-factor authentication was not enabled.

Ransomware Disables Defenses

After entering a network, affiliates use legitimate credentials and common administrative tools to avoid raising alarms. They move laterally through Remote Desktop Protocol (RDP), targeting file servers and domain controllers.

Attackers often store their tools in C:\PerfLogs, a legitimate Windows directory that may receive less attention from administrators. These tools can include network scanners, data theft utilities, EDR-killing programs, and backup-related software.

Number of victims listed on The Gentlemen leak site each month from September 2025 through July 2026 (Source: sophos)

The actors use tools such as Advanced IP Scanner and SoftPerfect Network Scanner to identify important systems, backup servers, and data repositories.

They also seek access to high-value accounts, sometimes changing administrator passwords or adding accounts to local Administrators and Domain Admins groups.

For persistence, the group has enabled RDP through Windows Registry changes and opened firewall port 3389.

In another case, attackers installed Cloudflared as a Windows service, creating a hidden remote-access channel that could continue working even if the original VPN access was removed.

Before encryption, affiliates steal selected files using Rclone, their preferred exfiltration tool. They also use Restic, FileZilla, MEGAsync, and MinIO Client depending on the victim environment.

Proportion of listed The Gentlemen ransomware victims by sector (Source: sophos)
Proportion of listed The Gentlemen ransomware victims by sector (Source: sophos)

The activity shows that the group adapts its tools when data size, transfer speed, or network restrictions become obstacles. A key part of The Gentlemen attacks is defense evasion.

Affiliates attempt to terminate antivirus and endpoint detection and response (EDR) tools before launching ransomware.

They use custom tools known as GentleKiller, as well as publicly available utilities, to abuse vulnerable drivers through the Bring Your Own Vulnerable Driver technique, sophos said.

Indicators of Compromise

IndicatorTypeAssociated File / ToolContext
622b2ca08552535bc142cb815ff9ec16MD5acronis.exeHavoc EDR-killer variant
f0bc50d2d2838c5294e21cd9bce2f09bf581e508SHA1acroni

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN



Click Here For The Original Source.

——————————————————–

..........

.

.