Gentlemen Ransomware Disables EDR, Backups Before Network Encryption
Key Takeaways The Gentlemen ransomware group is executing rapid, highly effective attacks, often achieving full network encryption in under 24 hours. The group employs a ransomware-as-a-service...
Key Takeaways
- The Gentlemen ransomware group is executing rapid, highly effective attacks, often achieving full network encryption in under 24 hours.
- The group employs a ransomware-as-a-service model, utilizing affiliates to target organizations.
- Initial access frequently exploits exposed firewall management interfaces, unpatched devices, or compromised VPN credentials.
- Attackers prioritize disabling EDR and backup solutions before encrypting data, making recovery significantly more challenging.
- Organizations must implement robust patching, MFA, and enhanced monitoring to counter these swift and destructive attacks.
Gentlemen Ransomware: A New Standard in Rapid Network Compromise
The Gentlemen ransomware operation is distinguishing itself through an aggressive and remarkably swift transition from initial network access to widespread data encryption. In numerous documented incidents, this threat actor has demonstrated the capability to neutralize an organization’s defenses and recovery infrastructure, then deploy ransomware across an entire enterprise network, all within a compressed timeframe of less than 24 hours.
Table Of Content
Operating under a ransomware-as-a-service (RaaS) model, the Gentlemen group empowers its affiliates to target a broad spectrum of organizations. Their methodology incorporates a double-extortion strategy: sensitive data is exfiltrated before encryption. This tactic not only disrupts business operations but also exposes victims to the severe risk of public data leaks, intensifying pressure on affected entities.
The Sophisticated Playbook of GOLD SHERWOOD
Security analysts at Sophos, who track the group under the designation GOLD SHERWOOD, meticulously investigated 15 distinct incidents. Their findings reveal a consistent and highly effective attack playbook. This research underscores how quickly a seemingly minor security event, such as a suspicious login, can escalate into a catastrophic, enterprise-wide outage.
According to Sophos in a report, initial compromise points commonly include internet-facing firewall management interfaces, systems with unpatched vulnerabilities, or stolen virtual private network (VPN) credentials. A notable example involved an intruder gaining a foothold via a Fortinet SSL VPN account lacking multi-factor authentication, highlighting the persistent danger posed by the FortiOS authentication bypass vulnerability to exposed infrastructure.
Gentlemen Ransomware Affiliates Prioritize Disabling EDR
Upon establishing an internal presence, affiliates navigate compromised systems using legitimate domain credentials and Remote Desktop Protocol (RDP). They strategically deploy their malicious tools within less-monitored, trusted Windows directories. This initial phase involves comprehensive reconnaissance, mapping critical systems, data repositories, and backup infrastructure before initiating the overt stages of the attack.
To deepen their control, attackers modify administrator passwords, add new accounts to privileged groups, and enable remote desktop access. In several instances, they configured firewall rules to permit external RDP connections, establishing a resilient fallback access route should the original VPN entry point be compromised or lost.
A critical step in their process involves systematically dismantling security measures. Attackers employ a combination of custom and publicly available utilities, including vulnerable drivers, to terminate antivirus and endpoint detection and response (EDR) processes. They also degrade Windows Defender’s effectiveness by implementing broad scan exclusions or altering policy settings. This aligns with broader trends where ransomware operators disabling EDR are increasingly common. In this campaign, the efforts to disable security and backup software are deliberate and multi-pronged, with attackers adapting their methods if one approach fails. Backup services are frequently disabled just moments before encryption begins.
The attackers specifically target recovery and backup agent services, deliberately complicating system restoration. In one observed incident, they went as far as clearing Application, System, and Security event logs, effectively erasing crucial forensic evidence needed for incident response teams to trace the breach.
Rapid Encryption Playbook
Before initiating encryption, the Gentlemen group exfiltrates specific files using legitimate data transfer tools. They typically focus on recently modified data and employ filters to minimize transfer volume, which helps to obscure outbound activity while still securing valuable data for extortion. The flexibility shown by affiliates in switching between different transfer utilities and object-storage methods highlights their adaptive nature, a trait also observed in other attacks leveraging compromised VPNs for ransomware deployment.
The median time from initial post-compromise activity to the deployment of ransomware was approximately two days. However, the shortest observed interval was under 24 hours, leaving very little time for manual investigation and response once an attacker breaches the network perimeter.
Ransomware deployment occurs locally, via network shares, or across the entire domain using centralized logon shares and remote execution. The malware encrypts files, appending a unique six-character extension, and places a ransom note in affected directories. While Windows was the primary target in the analyzed cases, related variants of the ransomware also support Linux and ESXi environments.
What You Should Do
- Patch and Update: Immediately apply patches to all internet-facing firewalls and VPN appliances. Review and address any Fortinet security update guidance, especially concerning authentication bypass vulnerabilities.
- Implement MFA: Enforce multi-factor authentication (MFA) for all remote access accounts, including VPNs, RDP, and administrative logins.
- Restrict RDP Exposure: Limit RDP exposure to the internet. If external RDP access is necessary, secure it with VPNs and strong authentication policies.
- Monitor Privileged Accounts: Closely monitor the creation of new privileged accounts and any changes to existing ones. Alert on unusual activity from these accounts.
- Enhance Monitoring: Configure alerts for unusual activity in system staging folders, the use of unfamiliar data-transfer utilities, Windows Defender exclusions, disabled backup services, cleared event logs, and attempts to load vulnerable drivers.
- Secure Backups: Implement immutable backups and ensure they are logically and physically separated from the main network, beyond the control of ordinary administrator accounts. Regularly test backup recovery plans to ensure effectiveness.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| MD5 | 622b2ca08552535bc142cb815ff9ec16 |
Sophos-listed threat indicator |
| SHA-1 | f0bc50d2d2838c5294e21cd9bce2f09bf581e508 |
Sophos-listed threat indicator |
| SHA-256 | a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c |
Sophos-listed threat indicator |
| MD5 | 4741a4976c6abfb3c80c170104518b6e |
Sophos-listed threat indicator |
| SHA-1 | be8c52474ab79a52af31e3cb2f71638299a0de1d |
Sophos-listed threat indicator |
| SHA-256 | ddba5b4e7a7ada77d56477e9d41c008f93e81d9a33ed09e77cb2af624f |
Sophos-listed threat indicator |
| MD5 | 738df7ae0097f6bef93d65be5d4a2a26 |
Sophos-listed threat indicator |
| SHA-1 | c96baab9b7e7ef661921d44d7900f165c794ed25 |
Sophos-listed threat indicator |
| SHA-256 | 1a9291ec869155336bf185d221d655d11c77a55ea0c8ecc0274202f74a9 |
Sophos-listed threat indicator |
| MD5 | d8691ef15eea27cfefafeeb485286080 |
Sophos-listed threat indicator |
| SHA-1 | 8bca55b3c9bfbdf68c9b6c72a7b1bf1dd6d5e3b2 |
Sophos-listed threat indicator |
| SHA-256 | 3c71537b64487bbf4d1793f72c75d332650d09a77b71e4d884ff15c266a |
Sophos-listed threat indicator |
| MD5 | b23b653541bd95bdc4da07a0b07b57bf |
Sophos-listed threat indicator |
| SHA-1 | f0537cbb773ae12100b36731e7c39f5a9d852b14 |
Sophos-listed threat indicator |
| SHA-256 | 50f2cdf16f05da9253fa2d6eb60d5a42da14c02c551c0874c9e953d4119 |
Sophos-listed threat indicator |
| SHA-256 | bf7a2fb7f7256809dc690213b85f747cef8db7b909caf9783cac181912fb |
Sophos-listed threat indicator |
| SHA-256 | 761ce72420edf5e5531cdbad0e93397d7520cdead825886ca7f75cef76 |
Sophos-listed threat indicator |
| MD5 | 002417da707b93bf5ce3cb26d28005f6 |
Sophos-listed threat indicator |
| SHA-1 | 8732c1ff565828a0bdef514b5dc0dfea40c1d1f2 |
Sophos-listed threat indicator |
| SHA-256 | 81053c2c3be8b7dbf7d5087dba05c940b3ee4fd95524272651c816b72c |
Sophos-listed threat indicator |
| SHA-256 | 7a37acb031cddaa39ad20db0961baa5423ec53f318c49c9275c982507d |
Sophos-listed threat indicator |
| MD5 | bc4a8d7bbbeb941265dfc954539326c0 |
Sophos-listed threat indicator |
| SHA-1 | b7cea81e6de895d01d01d20bd6dcfd347940b57f |
Sophos-listed threat indicator |
| SHA-256 | 3a31ec3bf9b7eac6593a723145381f5d0f4ede076c4c8818d949a08f559 |
Sophos-listed threat indicator |
| SHA-256 | 68031d549de399a44bb00614b910106baccef5996623b2f1102352a52a |
Sophos-listed threat indicator |
| SHA-1 | 058c3ff21e79770e4a60937c27b1ede227709248 |
Sophos-listed threat indicator |
| SHA-1 | 9c0b05eb75f971cc25ee979e49b227b86b19e833 |
Sophos-listed threat indicator |
| SHA-1 | a438ba2122a814320f47a056f04122f81c2ae6c5 |
Sophos-listed threat indicator |
| SHA-1 | a8ba89e67297642dcc1ae77433ab84e1f27d1792 |
Sophos-listed threat indicator |
| MD5 | 8ea97d01cbf459b94d134d05c54cd33e |
Sophos-listed threat indicator |
| SHA-1 | 5c9bf6b7e4c7dc9b9227ce86e2d271d624c35147 |
Sophos-listed threat indicator |
| SHA-256 | 0be8f415a485b11747bcfd71c9cd
|



No Comment! Be the first one.