Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Эксперты «Лаборатории Касперского» изучили недавние атаки группы Gentlemen и обнаружили в арсенале хакеров ранее неизвестный Go-бэкдор, а также новый шифровальщик для Windows, написанный на C.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
However, processing large databases completely would require excessive time. Therefore, the malware encrypts three distinct chunks distributed across the target asset. Operators can customize this speed dynamically using command-line arguments like --fast or --ultrafast. | The threat actors consistently deploy destructive double extortion tactics against their targets. First, the malware systematically encrypts critical production assets to halt local business operations.
Next, the payload terminates an extensive directory of active corporate services and applications. The targeted processes encompass enterprise databases, virtualization modules, and email management software.
To prevent file restoration, the threat systematically eliminates local system recovery markers. For example, it forcibly deletes Volume Shadow Copies via administrative command utilities.
Upon execution, the payload aggressively executes PowerShell commands to disable Microsoft Defender real-time monitoring. Furthermore, the malware adds its own binary to the localized exclusion list. It then excludes the entire local C:\ volume from future security scans.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS-associated malware set used by the Gentlemen group, including a previously unknown Go backdoor and a primary cross-platform Go ransomware encryptor. The backdoor collects host metadata, maintains C2 connectivity, executes operator commands, and provides a SOCKS proxy. The ransomware encryptor uses Curve25519 and XChaCha20, can stop Hyper-V VMs, terminate processes/services, delete shadow copies and event logs, and attempts to disable security tools via BYOVD. A newer Windows variant written in C uses AES-256-GCM and RSA and appears to still be under testing.
Ransomware that employs double extortion tactics and BYOVD (Bring Your Own Vulnerable Driver) evasion techniques, targeting victims across 17 countries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.