GOLD SHERWOOD is the threat group operating The Gentlemen ransomware-as-a-service (RaaS) operation, active since mid-2025. The Gentlemen uses a double-extortion model: affiliates steal data, impair victim recovery and security controls, encrypt systems, and threaten publication through a dedicated leak site. The operation recruits affiliates and provides proprietary ransomware variants for Windows, Linux, and ESXi; observed intrusions deployed the Go-based Windows variant. The Gentlemen affiliates opportunistically target organizations across sectors. Initial access has involved exploitation of internet-exposed Fortinet appliances, including CVE-2024-55591, and use of compromised Fortinet SSL VPN credentials where multifactor authentication was absent. Post-compromise activity includes network reconnaissance, credential dumping, manipulation of local and domain accounts and groups, RDP-based lateral movement, and deployment of remote-access tooling for persistence. Affiliates exfiltrate victim data using tools such as Rclone, MEGAsync, FileZilla, Restic, and MinIO Client. The operation employs substantial defense evasion before encryption, including disabling or weakening Microsoft Defender, using EDR-killing tools and bring-your-own-vulnerable-driver techniques, disabling backup and replication services, and clearing Windows event logs. Ransomware has been deployed locally, through PsExec, and at domain scale through network-based execution. Observed intrusions progressed rapidly, with a median interval of approximately two days from identified post-compromise activity to ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
37 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates the The Gentlemen RaaS operation through affiliates conducting opportunistic, cross-sector double-extortion ransomware attacks. Affiliates obtain access through exposed/vulnerable firewall management interfaces and compromised VPN credentials, then perform lateral movement, credential theft, data exfiltration, defense evasion, and domain-wide encryption.
The named activity cluster to which the Gentlemen ransomware-as-a-service operation is attributed.
GOLD SHERWOOD operates The Gentlemen RaaS as an opportunistic double-extortion operation. Its affiliates gain access through exposed FortiGate devices and compromised VPN credentials, move laterally using valid credentials and RDP, steal data, disable security and backup capabilities, and deploy ransomware—sometimes within 24 hours.
Operates The Gentlemen ransomware-as-a-service scheme as a double-extortion operation. Affiliates opportunistically compromise organizations, exfiltrate data, disable defenses and backups, and deploy ransomware, sometimes in under 24 hours.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.