Skip to main content
Mallory
2 malware families

Storm-2697

Also known asstorm_2697

Storm-2697 is a financially motivated threat actor tracked by Microsoft Threat Intelligence as the operator behind the ransomware-as-a-service platform The Gentlemen. The group emerged around mid-2025 as a tightly closed ransomware network and later transitioned into a public RaaS ecosystem, offering access to affiliates by September 2025. Microsoft reported that the operators established an official partnership with BreachForums to recruit affiliates, including penetration testers and initial access brokers. Storm-2697/The Gentlemen uses a double-extortion model, encrypting victim systems while exfiltrating data and threatening public release of stolen corporate information. Microsoft observed victims across healthcare, transportation, education, and financial sectors, with activity spanning North America, South America, Europe, Africa, and Asia. The Gentlemen ransomware is written in Go and obfuscated with Garble. It uses a hybrid cryptographic scheme based on Curve25519 and XChaCha20, appends the .umc16h extension to encrypted files, and drops ransom notes named README-GENTLEMEN.txt. The malware disables Microsoft Defender protections, adds exclusions for its binary and the C:\ volume, deletes Volume Shadow Copies, clears event logs, deletes forensic artifacts including PowerShell history, and terminates or disables processes and services associated with virtualization, databases, backup software, EDR tools, SAP, Exchange, Office applications, browsers, remote access tools, and accounting software. It also establishes persistence via scheduled tasks named UpdateSystem and UpdateUser and Run registry values GupdateS and GupdateU. The ransomware supports multiple execution modes, including local, network-share, and SYSTEM-level encryption. When launched with spreading enabled, it gains worm-like propagation capabilities by staging itself over SMB, creating hidden shares, enumerating remote hosts and shares, weakening defenses on remote systems, and attempting numerous remote execution methods including PsExec, WMIC, scheduled tasks, services, PowerShell remoting, and PowerShell WMI. It can also overwrite free disk space using wipefile.tmp and self-delete after execution. Known alias in the provided content: The Gentlemen.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Health Care Equipment & Services
  • Transportation
  • Academia & Research
MITRE ATT&CK

Tradecraft

28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics35 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0002
Execution
3 techniques
T1047×2
Windows Management Instrumentation
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1059.003
Windows Command Shell
TA0003
Persistence
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1112
Modify Registry
TA0004
Privilege Escalation
1 technique
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
TA0005
Stealth
2 techniques
T1070
Indicator Removal
T1070.001×2
Clear Windows Event Logs
T1070.004×2
File Deletion
T1218
System Binary Proxy Execution
T1218.002
Control Panel
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0007
Discovery
7 techniques
T1007
System Service Discovery
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1057
Process Discovery
T1069
Permission Groups Discovery
T1083×2
File and Directory Discovery
T1135×2
Network Share Discovery
TA0008
Lateral Movement
2 techniques
T1021
Remote Services
T1021.002
SMB/Windows Admin Shares
T1021.006
Windows Remote Management
T1570
Lateral Tool Transfer
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
TA0040
Impact
5 techniques
T1486×2
Data Encrypted for Impact
T1489×2
Service Stop
T1490×2
Inhibit System Recovery
T1561
Disk Wipe
T1657
Financial Theft
IOCS

Observables

3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping28

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables3

Domains, IPs, and hashes tied to this actor, refreshed continuously.