Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts
August 5, 2026
Microsoft Awards Record $20M to 562 Researchers in Biggest Bug Bounty Year
August 5, 2026
Critical VS Code Evil Twin Extensions Expose Git and CI Data
August 5, 2026
Home/Threats/Ransomware Uses SYSTEM Scheduled Task to Encrypt Local Drives
Threats

Ransomware Uses SYSTEM Scheduled Task to Encrypt Local Drives

Key Takeaways A new ransomware variant, “The Gentlemen,” is actively targeting organizations across multiple sectors globally. The malware utilizes a SYSTEM-level scheduled task to gain...

David kimber
David kimber
May 29, 2026 4 Min Read
69 0

Key Takeaways

  • A new ransomware variant, “The Gentlemen,” is actively targeting organizations across multiple sectors globally.
  • The malware utilizes a SYSTEM-level scheduled task to gain elevated privileges, enabling comprehensive encryption of local drives and evasion of security controls.
  • Operating as a Ransomware-as-a-Service (RaaS) model, The Gentlemen employs double extortion tactics and exhibits advanced self-propagation capabilities across networks.
  • Organizations in education, healthcare, transportation, and finance are particularly affected.

The cybersecurity landscape faces a new and formidable threat: “The Gentlemen” ransomware. This recently identified strain distinguishes itself through a sophisticated approach to data encryption, leveraging SYSTEM-level scheduled tasks to achieve the highest possible privileges on compromised Windows machines. Security researchers have detailed its advanced capabilities, which include being built in the Go programming language and obfuscated with Garble, allowing for powerful per-file encryption and silent, autonomous spread across networks.

Table Of Content

  • Key Takeaways
  • The Gentlemen’s Operational Model and Evolution
  • Ransomware Uses SYSTEM Scheduled Task for Elevated Privileges
  • Self-Propagation Across the Network
  • What You Should Do

The Gentlemen ransomware has already inflicted significant damage across various critical sectors, including education, healthcare, transportation, and finance. Its reach extends globally, with confirmed impacts in North America, South America, Europe, Africa, and Asia.

The Gentlemen’s Operational Model and Evolution

Functioning as a Ransomware-as-a-Service (RaaS) platform, The Gentlemen allows its core developers to lease access to the malware to other cybercriminals, known as affiliates. This model significantly broadens its attack surface and operational capacity.

Initially emerging as a clandestine group around mid-2025, The Gentlemen expanded its operations by opening its platform to affiliates in September 2025. More recently, its operators formalized a partnership with BreachForums, a prominent cybercriminal marketplace. This alliance is actively recruiting skilled penetration testers and initial access brokers to escalate and execute attacks on their behalf.

Microsoft Threat Intelligence, which tracks this group under the designation Storm-2697, confirms that the operators employ double extortion tactics. This involves not only encrypting a victim’s data but also exfiltrating sensitive files. Attackers then threaten to publicly release the stolen information if the ransom demands are not met. Microsoft’s report, shared with Cyber Security News (CSN), highlights the ransomware’s widespread adoption and warns that the new partnership with BreachForums could attract an even larger pool of malicious actors, intensifying the threat.

What truly distinguishes The Gentlemen is its multi-faceted attack strategy. Before initiating encryption, the ransomware systematically disables antivirus tools, deletes backups, clears system logs, and wipes forensic traces, making detection and recovery exceedingly difficult. Once activated, it possesses the ability to propagate autonomously across network environments, infecting other machines without human intervention. This self-propagation significantly complicates containment efforts for incident responders and security teams.

The ransomware’s operators maintain granular control over its behavior through various command-line arguments, requiring a build-specific password for execution. These customizable options allow attackers to dictate encryption speed, enable network spreading, and configure persistence mechanisms after system reboots. This high degree of operational flexibility makes The Gentlemen an unusually adaptable and potent tool for large-scale criminal deployments.

Ransomware Uses SYSTEM Scheduled Task for Elevated Privileges

A key technical characteristic of The Gentlemen is its method for escalating privileges to the highest possible level on a Windows system before encrypting local drives. When the malware receives a specific command-line instruction, it creates a Windows scheduled task named gentlemen_system. This task is configured to run the ransomware executable under the SYSTEM account, which grants the malware unparalleled access and control over the operating system.

To ensure a clean and effective privilege escalation, the ransomware first removes any existing scheduled task with the same name. It then registers and immediately triggers a new task. Once operating in this elevated context, the malware sets an internal environment variable, LOCKER_BACKGROUND=1, signaling that it is performing background encryption with full SYSTEM privileges. This design allows The Gentlemen to access and encrypt files and directories that would typically be protected or inaccessible to standard user-level accounts.

Self-Propagation Across the Network

The Gentlemen ransomware is not confined to a single compromised machine. When its self-propagation feature is enabled, it transforms into a highly effective worm, capable of deploying itself to every reachable system on the local network. It achieves this by staging its binary in a shared folder, copying it across administrative network shares, and then attempting execution on remote hosts using a combination of eight different methods simultaneously.

These propagation methods include commonly exploited administrative tools and services such as PsExec, Windows Management Instrumentation (WMI), scheduled tasks (both user and SYSTEM contexts), Windows services, and PowerShell remoting. The malware executes up to 21 distinct remote execution operations per target host. This redundancy is a critical component of its strategy; even if most propagation attempts are blocked, a single successful execution on a new host is sufficient to restart the entire infection cycle, ensuring widespread compromise.

What You Should Do

  • Enable Controlled Folder Access: Implement controlled folder access features on endpoints to prevent unauthorized applications, including ransomware, from modifying protected directories.
  • Activate Cloud-Delivered Antivirus Protection: Ensure your antivirus solutions leverage cloud intelligence for real-time threat detection and rapid response to emerging malware.
  • Implement Attack Surface Reduction (ASR) Rules: Configure ASR rules to block process creations originating from tools like PsExec and WMI commands, which The Gentlemen uses for lateral movement.
  • Run Endpoint Detection and Response (EDR) in Block Mode: Deploy EDR solutions in a blocking configuration to automatically quarantine or terminate malicious activity before it can spread or cause significant damage.
  • Configure Automatic Attack Disruption: Utilize security features that automatically detect and disrupt active attacks, helping to contain threats and prevent widespread compromise across your environment.
  • Regularly Back Up Data: Maintain regular, off-site, and immutable backups of critical data to facilitate recovery in the event of a successful ransomware attack.
  • Educate Employees: Conduct security awareness training to help users identify and avoid phishing attempts and other initial compromise vectors.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCybersecurityMalwareransomwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Malicious NuGet Package Masquerades as Sicoob SDK to Steal Banking Passwords

Next Post

JINX-00164 Threat Actor Uses LinkedIn to Deploy macOS Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical OVSwrap Linux Vulnerability (CVE-2024-3094) Lets Attackers Gain Root
August 5, 2026
Django Patches Four High-Severity Vulnerabilities in Versions 6.0.8 and 5.2.17
August 5, 2026
Critical ConnectWise ScreenConnect vulnerability allows macOS/Windows hijack
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us