Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Эксперты «Лаборатории Касперского» изучили недавние атаки группы Gentlemen и обнаружили в арсенале хакеров ранее неизвестный Go-бэкдор, а также новый шифровальщик для Windows, написанный на C.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The affiliates moved across systems using legitimate domain credentials and Remote Desktop Protocol.
The affiliates moved across systems using legitimate domain credentials and Remote Desktop Protocol.
In one intrusion, they also cleared Application, System, and Security event logs, obscuring the evidence responders need to trace the breach.
They placed their toolkit in a trusted Windows location that is often overlooked, then mapped systems, data stores, and backup infrastructure before the visible stage of the attack began.
The worm systematically attempts 21 distinct remote execution operations against each discovered network host. It relies on diverse utilities including PsExec, WMIC, and remote PowerShell commands.
The locker was deployed locally, through network shares, or across the domain using centralized logon shares and remote execution. It encrypted files, assigned a six-character extension, and left a ransom note in affected directories.
Next, the payload terminates an extensive directory of active corporate services and applications. The targeted processes encompass enterprise databases, virtualization modules, and email management software.
Backup services were then disabled, often immediately before encryption. They targeted recovery and backup-agent services, making it harder for teams to restore systems.
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS-associated malware set used by the Gentlemen group, including a previously unknown Go backdoor and a primary cross-platform Go ransomware encryptor. The backdoor collects host metadata, maintains C2 connectivity, executes operator commands, and provides a SOCKS proxy. The ransomware encryptor uses Curve25519 and XChaCha20, can stop Hyper-V VMs, terminate processes/services, delete shadow copies and event logs, and attempts to disable security tools via BYOVD. A newer Windows variant written in C uses AES-256-GCM and RSA and appears to still be under testing.
Ransomware that employs double extortion tactics and BYOVD (Bring Your Own Vulnerable Driver) evasion techniques, targeting victims across 17 countries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.