Gentlemen is a financially motivated ransomware operation that emerged in 2025 and evolved into a ransomware-as-a-service ecosystem. It is tracked as Storm-2697 by Microsoft and GOLD SHERWOOD by Sophos. The operation conducts double-extortion attacks: affiliates exfiltrate selected corporate data, impair recovery and security controls, encrypt systems, and threaten disclosure of stolen data to pressure victims.
Observed intrusions have used stolen remote-access credentials, including VPN accounts, and exploitation of exposed or unpatched perimeter devices for initial access. Operators conduct reconnaissance of domain infrastructure, data stores, backup systems, virtualization platforms, network-attached storage, and critical servers. They use legitimate credentials and remote administration mechanisms for lateral movement, elevate privileges, modify domain policy, create or alter privileged accounts, and can deploy the locker broadly through centralized domain infrastructure and network shares.
The locker is primarily Go-based and supports Windows and Linux environments, with a separate ESXi-focused variant. It can target local storage, network shares, and virtualized infrastructure; the ESXi variant can stop virtual machines before encrypting their disks. Encryption uses X25519/Curve25519 key agreement and XChaCha20, with per-file key material and partial encryption of large files to accelerate enterprise-wide impact. Execution requires an operator-supplied password, which also hinders automated analysis.
Before encryption, Gentlemen activity has disabled or weakened endpoint protections, stopped database, backup, virtualization, and monitoring services, deleted shadow copies, and cleared event logs. Affiliates have used vulnerable drivers to terminate security processes and may overwrite free space and remove the ransomware executable after execution. Victims have included medium and large organizations across healthcare, manufacturing, insurance, transportation, education, energy, and other sectors in multiple countries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Gentlemen ransomware operation is moving from access to full network encryption at striking speed... Its double-extortion approach adds pressure: files are stolen first, then encrypted.
Microsoft Threat Intelligence recently uncovered a dangerous global cyber security operation. Specifically, security researchers are tracking the rapidly growing Gentlemen ransomware threat across multiple continents. This sophisticated platform functions as a ransomware-as-a-service model for financially motivated cybercriminals.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A double-extortion ransomware operation whose affiliates obtain access through exposed or unpatched remote infrastructure and stolen VPN credentials, disable EDR/antivirus and backup services, exfiltrate selected data, and rapidly encrypt Windows environments. The locker can be deployed locally, via network shares, or domain-wide through centralized logon shares and remote execution; related builds support Linux and ESXi.
A Go-based ransomware-as-a-service operation employing a double-extortion model. Affiliates obtain access through stolen VPN credentials and vulnerable firewalls, then use RDP, Cloudflared tunnels, credential dumping, Rclone exfiltration, BYOVD-based EDR-disabling tooling, and backup tampering before encrypting victim environments.
A ransomware operation that disables security software prior to encryption, reportedly using a kernel-level driver to terminate nearly 180 security-related processes and evade defenses before locking files.
A ransomware operation that disables security software before encrypting files, reportedly using a kernel-level driver to terminate nearly 180 security-related processes and evade defenses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.