Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical VMware Workstation and Fusion Flaws Let Attackers Execute Code
September 3, 2026
Critical Node.js Vulnerability CVE-2024-2798 Lets Attackers Deploy Malware
September 3, 2026
StreamRAT Android Trojan Grants Full Remote Control via VNC, Accessibility
September 3, 2026
Home/CyberSecurity News/Gentlemen Ransomware Disables EDR, Backups Before Network Encryption
CyberSecurity News

Gentlemen Ransomware Disables EDR, Backups Before Network Encryption

Key Takeaways The Gentlemen ransomware group is executing rapid, highly effective attacks, often achieving full network encryption in under 24 hours. The group employs a ransomware-as-a-service...

Sarah simpson
Sarah simpson
September 3, 2026 5 Min Read
3 0

Key Takeaways

  • The Gentlemen ransomware group is executing rapid, highly effective attacks, often achieving full network encryption in under 24 hours.
  • The group employs a ransomware-as-a-service model, utilizing affiliates to target organizations.
  • Initial access frequently exploits exposed firewall management interfaces, unpatched devices, or compromised VPN credentials.
  • Attackers prioritize disabling EDR and backup solutions before encrypting data, making recovery significantly more challenging.
  • Organizations must implement robust patching, MFA, and enhanced monitoring to counter these swift and destructive attacks.

Gentlemen Ransomware: A New Standard in Rapid Network Compromise

The Gentlemen ransomware operation is distinguishing itself through an aggressive and remarkably swift transition from initial network access to widespread data encryption. In numerous documented incidents, this threat actor has demonstrated the capability to neutralize an organization’s defenses and recovery infrastructure, then deploy ransomware across an entire enterprise network, all within a compressed timeframe of less than 24 hours.

Table Of Content

  • Key Takeaways
  • Gentlemen Ransomware: A New Standard in Rapid Network Compromise
  • The Sophisticated Playbook of GOLD SHERWOOD
  • Gentlemen Ransomware Affiliates Prioritize Disabling EDR
  • Rapid Encryption Playbook
  • What You Should Do
  • Indicators of Compromise (IoCs)

Operating under a ransomware-as-a-service (RaaS) model, the Gentlemen group empowers its affiliates to target a broad spectrum of organizations. Their methodology incorporates a double-extortion strategy: sensitive data is exfiltrated before encryption. This tactic not only disrupts business operations but also exposes victims to the severe risk of public data leaks, intensifying pressure on affected entities.

The Sophisticated Playbook of GOLD SHERWOOD

Security analysts at Sophos, who track the group under the designation GOLD SHERWOOD, meticulously investigated 15 distinct incidents. Their findings reveal a consistent and highly effective attack playbook. This research underscores how quickly a seemingly minor security event, such as a suspicious login, can escalate into a catastrophic, enterprise-wide outage.

According to Sophos in a report, initial compromise points commonly include internet-facing firewall management interfaces, systems with unpatched vulnerabilities, or stolen virtual private network (VPN) credentials. A notable example involved an intruder gaining a foothold via a Fortinet SSL VPN account lacking multi-factor authentication, highlighting the persistent danger posed by the FortiOS authentication bypass vulnerability to exposed infrastructure.

Gentlemen Ransomware Affiliates Prioritize Disabling EDR

Upon establishing an internal presence, affiliates navigate compromised systems using legitimate domain credentials and Remote Desktop Protocol (RDP). They strategically deploy their malicious tools within less-monitored, trusted Windows directories. This initial phase involves comprehensive reconnaissance, mapping critical systems, data repositories, and backup infrastructure before initiating the overt stages of the attack.

To deepen their control, attackers modify administrator passwords, add new accounts to privileged groups, and enable remote desktop access. In several instances, they configured firewall rules to permit external RDP connections, establishing a resilient fallback access route should the original VPN entry point be compromised or lost.

A critical step in their process involves systematically dismantling security measures. Attackers employ a combination of custom and publicly available utilities, including vulnerable drivers, to terminate antivirus and endpoint detection and response (EDR) processes. They also degrade Windows Defender’s effectiveness by implementing broad scan exclusions or altering policy settings. This aligns with broader trends where ransomware operators disabling EDR are increasingly common. In this campaign, the efforts to disable security and backup software are deliberate and multi-pronged, with attackers adapting their methods if one approach fails. Backup services are frequently disabled just moments before encryption begins.

The attackers specifically target recovery and backup agent services, deliberately complicating system restoration. In one observed incident, they went as far as clearing Application, System, and Security event logs, effectively erasing crucial forensic evidence needed for incident response teams to trace the breach.

Rapid Encryption Playbook

Before initiating encryption, the Gentlemen group exfiltrates specific files using legitimate data transfer tools. They typically focus on recently modified data and employ filters to minimize transfer volume, which helps to obscure outbound activity while still securing valuable data for extortion. The flexibility shown by affiliates in switching between different transfer utilities and object-storage methods highlights their adaptive nature, a trait also observed in other attacks leveraging compromised VPNs for ransomware deployment.

The median time from initial post-compromise activity to the deployment of ransomware was approximately two days. However, the shortest observed interval was under 24 hours, leaving very little time for manual investigation and response once an attacker breaches the network perimeter.

Ransomware deployment occurs locally, via network shares, or across the entire domain using centralized logon shares and remote execution. The malware encrypts files, appending a unique six-character extension, and places a ransom note in affected directories. While Windows was the primary target in the analyzed cases, related variants of the ransomware also support Linux and ESXi environments.

What You Should Do

  • Patch and Update: Immediately apply patches to all internet-facing firewalls and VPN appliances. Review and address any Fortinet security update guidance, especially concerning authentication bypass vulnerabilities.
  • Implement MFA: Enforce multi-factor authentication (MFA) for all remote access accounts, including VPNs, RDP, and administrative logins.
  • Restrict RDP Exposure: Limit RDP exposure to the internet. If external RDP access is necessary, secure it with VPNs and strong authentication policies.
  • Monitor Privileged Accounts: Closely monitor the creation of new privileged accounts and any changes to existing ones. Alert on unusual activity from these accounts.
  • Enhance Monitoring: Configure alerts for unusual activity in system staging folders, the use of unfamiliar data-transfer utilities, Windows Defender exclusions, disabled backup services, cleared event logs, and attempts to load vulnerable drivers.
  • Secure Backups: Implement immutable backups and ensure they are logically and physically separated from the main network, beyond the control of ordinary administrator accounts. Regularly test backup recovery plans to ensure effectiveness.

Indicators of Compromise (IoCs)

Type Indicator Description
MD5 622b2ca08552535bc142cb815ff9ec16 Sophos-listed threat indicator
SHA-1 f0bc50d2d2838c5294e21cd9bce2f09bf581e508 Sophos-listed threat indicator
SHA-256 a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c Sophos-listed threat indicator
MD5 4741a4976c6abfb3c80c170104518b6e Sophos-listed threat indicator
SHA-1 be8c52474ab79a52af31e3cb2f71638299a0de1d Sophos-listed threat indicator
SHA-256 ddba5b4e7a7ada77d56477e9d41c008f93e81d9a33ed09e77cb2af624f Sophos-listed threat indicator
MD5 738df7ae0097f6bef93d65be5d4a2a26 Sophos-listed threat indicator
SHA-1 c96baab9b7e7ef661921d44d7900f165c794ed25 Sophos-listed threat indicator
SHA-256 1a9291ec869155336bf185d221d655d11c77a55ea0c8ecc0274202f74a9 Sophos-listed threat indicator
MD5 d8691ef15eea27cfefafeeb485286080 Sophos-listed threat indicator
SHA-1 8bca55b3c9bfbdf68c9b6c72a7b1bf1dd6d5e3b2 Sophos-listed threat indicator
SHA-256 3c71537b64487bbf4d1793f72c75d332650d09a77b71e4d884ff15c266a Sophos-listed threat indicator
MD5 b23b653541bd95bdc4da07a0b07b57bf Sophos-listed threat indicator
SHA-1 f0537cbb773ae12100b36731e7c39f5a9d852b14 Sophos-listed threat indicator
SHA-256 50f2cdf16f05da9253fa2d6eb60d5a42da14c02c551c0874c9e953d4119 Sophos-listed threat indicator
SHA-256 bf7a2fb7f7256809dc690213b85f747cef8db7b909caf9783cac181912fb Sophos-listed threat indicator
SHA-256 761ce72420edf5e5531cdbad0e93397d7520cdead825886ca7f75cef76 Sophos-listed threat indicator
MD5 002417da707b93bf5ce3cb26d28005f6 Sophos-listed threat indicator
SHA-1 8732c1ff565828a0bdef514b5dc0dfea40c1d1f2 Sophos-listed threat indicator
SHA-256 81053c2c3be8b7dbf7d5087dba05c940b3ee4fd95524272651c816b72c Sophos-listed threat indicator
SHA-256 7a37acb031cddaa39ad20db0961baa5423ec53f318c49c9275c982507d Sophos-listed threat indicator
MD5 bc4a8d7bbbeb941265dfc954539326c0 Sophos-listed threat indicator
SHA-1 b7cea81e6de895d01d01d20bd6dcfd347940b57f Sophos-listed threat indicator
SHA-256 3a31ec3bf9b7eac6593a723145381f5d0f4ede076c4c8818d949a08f559 Sophos-listed threat indicator
SHA-256 68031d549de399a44bb00614b910106baccef5996623b2f1102352a52a Sophos-listed threat indicator
SHA-1 058c3ff21e79770e4a60937c27b1ede227709248 Sophos-listed threat indicator
SHA-1 9c0b05eb75f971cc25ee979e49b227b86b19e833 Sophos-listed threat indicator
SHA-1 a438ba2122a814320f47a056f04122f81c2ae6c5 Sophos-listed threat indicator
SHA-1 a8ba89e67297642dcc1ae77433ab84e1f27d1792 Sophos-listed threat indicator
MD5 8ea97d01cbf459b94d134d05c54cd33e Sophos-listed threat indicator
SHA-1 5c9bf6b7e4c7dc9b9227ce86e2d271d624c35147 Sophos-listed threat indicator
SHA-256 0be8f415a485b11747bcfd71c9cd

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerPatchransomwareSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Microsoft Teams, Outlook Crash on ARM After August Updates

Next Post

StreamRAT Android Trojan Grants Full Remote Control via VNC, Accessibility

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Sangoma Switchvox RCE Vulnerability Actively Exploited
September 3, 2026
Critical WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection
September 3, 2026
Critical Apache HTTP Server Vulnerability Lets Attackers Phish Users
September 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us