Skip to content
Hastalamuerte Gentlemen Raas Ttps

Hastalamuerte Gentlemen Raas Ttps

www.group-ib.com September 1, 2026

The report provides an overview on tactics, techniques, and procedures (TTPs) of The Gentlemen observed by Group-IB in intrusions conducted by its affiliates, as well as relevant information the group's capabilities collected from underground private sources.

In the face of so many new ransomware brands and the remaining RaaS operations such as Medusa , Qilin , and DragonForce , prioritizing is not an easy task . However, despite the number of groups conducting extortion attacks, the TTPs do not change much, unless we are talking Cl0p , Akira, and other groups that pose a high risk.

After all, why should they exploit complex and time-consuming vulnerabilities when there is so much low-hanging fruit out there, such as vulnerable web-based remote services like RDWeb and SSL VPN devices, and default or easy-to-guess passwords to brute-force? Anyway, it is not up to us but to the criminals to decide what is the best (or the worst) strategy for a ransomware or extortion operation to carry out attacks.

However, we must keep in mind that, regardless of which group claimed responsibility for the attack, it was an individual or an affiliate group that actually conducted the intrusion. These criminals are usually involved with different groups, sharing and absorbing knowledge, and acquiring resources.

This symbiosis among criminals in the underground occurs every day, and that is one of the reasons it is important to focus on adversaries’ TTPs and human aspects rather than prioritizing by group. Please note that, with a few exceptions, the RaaS groups and their Data Leak Sites (DLSs) are merely resources criminals use to boost visibility and expose companies for extortion.

Therefore, to prevent your company from falling prey to opportunists looking for such low-hanging fruit to attack, Group-IB’s Threat Intelligence Team decided to write a very straightforward report on the TTPs of The Gentlemen , whose TTPs overlap with those of other financially motivated threat actors conducting intrusions for extortion. The information shared in this blog comes from intrusion analysis and underground private sources monitored by Group-IB’s Threat Intelligence Team. Thus, the information has a high level of confidence.

This blog covers TTPs from initial access to the data encryption and extortion phases.

The first Windows sample of The Gentlemen ransomware uploaded to VirusTotal on 17 July 2025 already contained The Gentlemen’s Data Leak Site (DLS) URL.

On 22 July 2025 , threat actor hastalamuerte opened a public arbitration thread on the RAMP forum, accusing Qilin ransomware operators of a $48,000 USD payment dispute over an unpaid affiliate commission from a corporate victim negotiation.

The Gentlemen ransomware DLS was likely operational from mid-July 2025, but it only became publicly known in early September 2025.

Primary attack vector exploits CVE-2024-55591 , a critical authentication bypass in FortiOS/FortiProxy.

The group maintains an operational database of approximately 14,700 FortiGate devices that have already been exploited globally.

Separate from exploited devices, the operators maintain 969 validated brute-forced FortiGate VPN credentials ready for attack.

Approximately 94 organizations have already been attacked by this threat group.

Advanced defense evasion employs the Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to terminate EDR/AV processes at the kernel level.

Active reconnaissance and exploit development targeting SonicWall VPN, Cisco ASA appliances, and Oracle E-Business Suite (EBS), attempting to replicate the Cl0p Oracle exploitation campaigns observed in 2025.

Ongoing reverse-engineering of Babuk, Qilin, LockBit 5.0, and Medusa ransomware samples to extract and integrate superior encryption routines, obfuscation techniques, and EDR bypass mechanisms into The Gentlemen codebase.

Group-IB’s analysis shows that defending against The Gentlemen means focusing on behaviors and attack chains, not only on the ransomware brand name.

Who may find this blog interesting:

Cybersecurity analysts and corporate security teams

Threat intelligence specialists

Computer Emergency Response Teams (CERT)

Law enforcement investigators

Who are the Gentlemen and why do they matter?

The Gentlemen is a ransomware operation that emerged in 2025 after breaking away from Qilin affiliate activity and is now tracked by Group-IB as a financially motivated extortion group with strong affiliate-driven tradecraft. Group-IB’s analysis shows the group relies on effective, repeatable tactics, including Fortinet exploitation, brute-forced VPN access, credential abuse, defense evasion, and rapid ransomware deployment, that overlap with techniques used by other high-risk extortion actors.

Group-IB Threat Intelligence Portal:

Group-IB’s customers can access our Threat Intelligence portal for more information The Gentlemen group .

Please find below statistics based on companies disclosed on the group’s data leak site (DLS) and undisclosed victims identified by Group-IB’s Threat Intelligence team.

Figure 1. The Gentlemen’s global victimology.

A Short Story of The Gentlemen

The Gentlemen is a newly emerged Ransomware-as-a-Service (RaaS) operation consisting of approximately 20 members. Before becoming a RaaS, this operation was known as ArmCorp , a very active Qilin’s affiliate group. The name ArmCorp was present on the group’s Rocket Chat webpage title as well as Qilin’s members and affiliates such as Devman referred to the group by this name.

Figure 2. Title of the Rocket Chat page with name “ARMCORP”

Figure 3. Title of the Rocket Chat page with name “GENTLEMEN”

The operation is managed by a Russian speaking criminal known mainly by the nickname hastalamuerte . He promotes technical discussions and provides affiliates with resources for conducting intrusions. This includes: Fortinet compromised devices for initial access, killers for AV/EDR bypassing, scripts, tools and more. At first glance, considering the resources provided by its administrator, from a criminal point of view, joining The Gentlemen may seem like a good idea. However, due to Opsec issues, joining this partnership program (PP) may put its members at risk , as raised by Devman on the Rehub forum in December 2025.

As can be seen in the screenshot above , Hastalamuerte has an interesting but unclear connection with its rival Devman (who allegedly leaked information on The Gentlemen operation) and also with Embargo . But that is another story =)

The chronological sequence of events surrounding The Gentlemen’s emergence reveals that the public dispute with Qilin was likely a formalization of an already-planned departure rather than the trigger for it. It is likely that hastalamuerte took advantage of this to damage Qilin’s reputation as a strategy to later promote his own partnership program .

On July 17, 2025 , a Windows ransomware sample was uploaded to VirusTotal (hash: 51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2 ). This upload occurred five days before the public arbitration with Qilin was opened on RAMP, providing critical evidence that hastalamuerte was already developing an independent ransomware operation , while still nominally affiliated with Qilin.

The sophistication of the July 17 sample indicates that development had been underway for weeks or potentially months before the VirusTotal upload. Creating a multi-platform ransomware operation with custom infrastructure, DLS hosting, and operational security features requires substantial development time, testing, and infrastructure preparation.

On 22 July 2025, hastalamuerte opened a public arbitration thread on the RAMP underground forum accusing Qilin’s core operators of mishandling negotiations with a corporate victim; a claim not only from hastalamuerte , but also from other former affiliates including Devman. In his opening statement, hastalamuerte detailed the dispute:

Hastalamuerte’s Claims:

Operated as a Qilin affiliate for 1.5 months, deploying 14 targets.

On one target, Qilin support contacted him stating that a recovery firm had reached out outside the panel offering $60,000 USD for the ransom.

hastalamuerte had initially set the ransom demand at $500,000 USD.

After negotiation with Qilin support, they agreed on $200,000 USD as an acceptable amount.

The Tox chat with the recovery firm then allegedly disappeared.

hastalamuerte demanded $48,000 USD compensation (his affiliate minus Qilin’s percentage) for the lost deal.

He challenged Qilin’s explanation that Tox chats could disappear, stating “в токсе чаты не пропадают” (“chats don’t disappear in Tox”).

Expressed concern that other negotiations might be conducted outside the panel without affiliate knowledge.

Most significantly, when questioned why he waited 20 days to file the complaint, hastalamuerte publicly admitted: “я занят был писал свой локер, чтобы потом чаты не терялись” (“ I was busy writing my own locker, so that chats wouldn’t get lost later “), direct evidence that he was already developing his own ransomware during his time as a Qilin affiliate.

The Gentlemen ransomware DLS was likely operational from mid-July 2025, but it only became publicly known in early September 2025.

One of so many hastalamuerte’s OpSec fails

In November 2025, Cybereason published an analysis of The Gentlemen ransomware that provided additional forensic evidence linking the operation to hastalamuerte . During static analysis of a Windows sample (hash: 3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235 ), researchers identified a hardcoded string ” ! Ransom Protection(DON’T DELETE)” embedded in the ransomware code that directly matched content from a Rehub forum post by the user hastalamuerte discussing anti-ransomware bypass techniques, providing forensic proof of authorship.

Figure 5. hastalamuerte’s forum post canary files with mention “Ransom Protection(DON’T DELETE)”

Figure 6. Decompiling code segment of Gentlemen ransomware that shows this mention “Ransom Protection(DON’T DELETE)”

T1190 – Exploit Public-Facing Application Confidence: High Context: Threat actors initiated a systematic reconnaissance campaign targeting internet-exposed FortiGate firewall management interfaces. During this phase, exploited CVE-2024-55591

The threat actor exploited this vulnerability by sending specially crafted requests to the exposed FortiGate firewall console. This isn’t a simple bypass, it’s a chain of four critical flaws:

WebSocket from Unauthenticated Request – Create WebSocket connection without authentication.

Special Parameter Abuse – Use local_access_token parameter to skip session checks.

Race Condition – Send authentication to CLI before the server initiates auth challenge.

No Credential Validation – Authentication contains no unique key, password, or identifier, attacker simply selects “super_admin” profile.

Result: Complete firewall takeover with administrative privileges. With super-admin access, the threat actor:

Created backdoor accounts: for example: support_fortinet, badmin, forti-api.

Downloaded system configuration containing network topology, credentials, and security policies.

Established persistent SSLVPN access via unlogged “guest” account.

Compromised existing VPN accounts.

Launched AiTM attack to compromise domain administrator account.

Once exploited, compromised Fortinet devices were added to an HTML page named FortiGate Inventory Overview and shared with affiliates. At that time, the HTML page contained approximately 14,700 devices from different countries. Affiliates are free to pick any device they want. However, the group’s admin recommends choosing the ones with LDAP integration and a significant number of users; as it is easier to escalate privileges since the VPN accounts are Active Directory members. Aside from technical details, companies are chosen by affiliates based on their industry and the importance of the data to that specific business, as well as the legal implications the company may eventually face in case of a data leak. In other words, The Gentlemen will prioritize targets that:

can pay high amounts of ransom – high revenue.

have the likelihood to pay the ransom – legal implications, laws and regulators in the country.

have a significant amount of Fortinet’s accounts on the compromised devices.

are companies that provide critical services.

are easy and fast to attack – LDAP integration and users’ privileges.

Figure 7. HTML page with list of exploited targets.

In addition to exploiting public-facing Fortinet devices, members of the group have been discussing targeting SonicWall and Oracle EBS for initial access. While there is no evidence they targeted SonicWall, we collected information which suggests that hastalamuerte intends to make a guide on how to exploit the Oracle EBS vulnerability. For this, the criminal has been allegedly in touch with rose87168 in order to get instructions on how to exploit Oracle.

T1110.001 – Brute Force: Password Guessing Confidence: High Context: Group-IB Threat Intelligence Team observed that members of The Gentlemen ransomware group gained access to approximately 1000 Fortinet VPNs through brute force attacks. Below is the list with common usernames and passwords the criminals are using to brute force Fortinet VPN:

The criminals try these known passwords against all default usernames in the list. They also test combinations of default passwords plus random or garbage strings to determine whether a target is a real device or a honeypot. Examples of such probe passwords include:

These strings appear to be deliberate garbage or obfuscation added to otherwise common credentials.

T1059.001 – Command and Scripting Interpreter: PowerShell Confidence : High Context : The following are commands used by the criminals to enable Windows PowerShell Access (PSWA).

T1059.006 – Command and Scripting Interpreter: Python Confidence : High Context : Group-IB discovered a Python script named userpassfort.py that extracts credentials from a provided config file and executes nxc on the victim machine.

Source code of the userpassfort.py script:

T1053 – Scheduled Task/Job Confidence : High Context : We have seen The Gentlemen’s affiliates execute commands to schedule the execution of the rclone.ps1 script on a target machine for the purpose of data exfiltration.

shared schtasks command

T1098 – Account Manipulation Confidence : Medium Context : An URL of an article published on VMBlog website shared by the criminals suggests that they are possibly following the procedure described in the blog to reset ESXi root passwords

T1098.007 – Account Manipulation: Additional Local or Domain Groups Confidence : High Context : The snippet contains potential references to the real victim . This victim was claimed by Nightspire on their DLS. Therefore, it is very likely that this procedure was used during the intrusion. We observed such commands run by the criminals in order to add users to the RDP group via SMB

Add of user to RDP group:

T1136.002 – Create Account: Domain Account Confidence : High Context : Commands allegedly executed during a real intrusion. The commands consist of the creation of a new account named MicrosoftSupporte, and its addition to two Domain groups. Subsequently, the user was also added to Veeam granting administrative control over it.

Creation of domain and Veeam account (original):

T1484.001 – Domain or Tenant Policy Modification: Group Policy Modification Confidence : High Context : The following GPO-related procedures show how the criminals: enable SMB, move accounts from an CN to an OU, enable RDP and update GPOs. The snippet on how to move accounts from an CN account to an OU contains references to the real victim . This victim was claimed by Gentleman on their DLS, it is very likely that this procedure was used during the intrusion.

How to move accounts from an CN to a OU:

2. How to update GPOs

3. How to enable SMB via GPO

T1068 – Exploitation for Privilege Escalation Confidence : Low Context : We observed The Gentlemen’s affiliates sharing information on techniques and vulnerabilities for privilege escalation. Although there is no evidence (e.g., screenshots, samples) of its exploitation, the sharing of the exploit suggests its potential intent in using it in intrusions by the criminals.

The vulnerabilities include:

BadSuccessor : a privilege escalation vulnerability in Windows Server 2025 that allows attackers to compromise any user in Active Directory (AD).

CVE-2025-32463 : affecting Sudo before 1.9.17p1, allowing local users to obtain root access.

CVE-2024-37085 : an authentication bypass vulnerability, which allows an adversary with sufficient Active Directory (AD) permissions to gain full access to an ESXi host member of the AD.

T1112 – Modify Registry Confidence : medium Context : Intruders shared instructions on how to disable Bitdefender by editing Windows registry and how to kill AV/EDR by editing HKLM\SYSTEM\CurrentControlSet\Control\WMI registry key, in particular AutoLogger and GlobalLogger.

Bitdefender remove in safe mode

2. Example of AutoLogger/GlobalLogger registry overwrite (original):

T1562.001 – Impair Defenses: Disable or Modify Tools Confidence : Medium Context : Shared by The Gentlemen group instruction on how to disable Windows Defender by using Group Policy and disabling Bitdefender and other EDR solutions such as SentinelOne, and Crowdstrike by leveraging techniques described in a blog by Aon. In addition, commands shared by the criminals show how to disable Defender real time protection and likely spread malware via SMB.

T1484.001 – Domain or Tenant Policy Modification: Group Policy Modification Confidence : Medium Context : Shared instruction on how to disable windows defender by using Group Policy.

T1036 – Masquerading: Rename Legitimate Utilities Confidence : High Context : Shared Rclone commands allegedly used during exfiltration. In the following snippet, it is possible to observe that the Rclone executable is renamed as avastrclone.exe probably to make the executable look legitimate. The snippet contains references to the real victim . This victim was claimed by Gentleman on their DLS, it is very likely that this procedure was used during the intrusion.

Masquered rclone executable

T1070.001 Indicator Removal: Clear Windows Event Logs

On every target host, the hastalamuerte instructs affiliates to wipe all event logs. After the operation, delete the Rclone configuration file.

T1003.004 – OS Credential Dumping: LSA Secrets Confidence : High Context : Shared by criminals commands to extract DPAPI backup keys by using Impacket’s dpapi.py tool. The snippet contains potential references to an organization. Therefore, it is very likely that this procedure was used during an intrusion.

commands to obtain backup keys by using Impacket’s dpapi.py tool.

T1555 – Credentials from Password Stores Confidence : Medium Context : Criminals shared several references, scripts and snippets related to extraction of Veeam credentials. In addition, the criminals also shared a link to a PoC of CVE-2023-27532 affecting Veeam Backup which allows the extraction of credentials.

Besides, we discovered a self-developed tool named “ChromeKB3.exe” (SHA256: 2834114ff7e487c4ca3f50ca39f7d652dea1be98f885c388f01b6ff35309307b), described by the criminals as a “Chrome Appbound Injection – extract passwords from Chrome.”.

Decryption of Veeam Backup and Replication passwords:

2. Another snippet likely used to obtain Veeam credentials:

T1557.001 Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay Confidence : High Context : The Gentlemen’s affiliates leverage nxc to force authentication via coercion methods, then relay those credentials to bypass security controls.

nxc smb [edited] -u service_firewall -p [edited] -M coerce_plus -o METHOD=Petitpotam L=[edited]

T1222.001 File and Directory Permissions Modification: Windows File and Directory Permissions Modification Confidence: High Context : Shared by threat group instruction: Even when a machine has a clear “Administrator” entry and a domain‑admin (often also local admin) in the ACL, an attacker can still attempt to modify permissions. If neither takeown or icacls works, the attacker usually has not reached administrative rights.

Grant Read & List Rights Recursively to a Controlled User

icacls “C:\Data\Logs” /grant DOMAIN\attacker_user:(OI)(CI)(RX) /t

DOMAIN\attacker_user – the attacker’s account (replace with the actual domain/user).

(OI)(CI) – applies to objects and containers (files & subfolders).

(RX) – read + execute (list).

takeown /F “C:\Data\Logs” /R /D Y

If the ACL change fails, take ownership of the folder and its contents.

Figure 8. The Gentlemen ransomware uses this technique automatically.

T1087.002 – Account Discovery: Domain Account Confidence : High Context : Shared by intruders powershell scripts to list active and inactive devices currently in a specific domain, and commands to obtain IP and name of the devices. The snippet contains references to the real victim . This victim was claimed by Gentleman on their DLS, it is very likely that this procedure was used during the intrusion.

List active and inactive devices

T1615 – Group Policy Discovery Confidence : Medium Context : Shared commands on how to verify applied GPO policies.

T1021.002: Remote Services: SMB/Windows Admin Shares Confidence : High Context : Intruders shared commands to disable Defender real time protection and likely spread malware via SMB. The snippet contains potential references to the real victim . This victim was claimed by Gentleman on their DLS, it is very likely that this procedure was used during the intrusion. In addition, the criminals shared commands to create open network shares using NetExec and smb. The snippet contains potential references to an organization. Therefore, it is very likely that this procedure was used during an intrusion.

Disable of Windows Defender and spread of malware using SMB and NetExec:

2. Create open network shares using SMB and NetExec:

T1021.001: Remote Services: Remote Desktop Protocol Confidence : High Context : Commands used by the criminals to connect to a victim machine during an intrusion via RDP. In addition, we observed commands shared by the criminals to add a user to the RDP group via SMB. The source of the information contains potential references to the real victim . This victim was claimed by Nightspire on their DLS, it is very likely that this procedure was used during the intrusion.

Connection to victim machine:

2. Add of user to the RDP group using SMB and NetExec:

T1572 – Protocol Tunneling Confidence : Medium Context : Commands for using Chisel to encapsulate C2 communication and avoid detection.

T1048 – Exfiltration Over Alternate Protocol Confidence : Low Context : Intruders shared sample of Rclone configuration file. SFTP is hardcoded in the configuration, which could mean an intention to exploit rclone and alternative protocols for exfiltration.

Example of an Rclone configuration shared by the criminals:

Scope & immediate effect

Domain-wide spread: The actor deployed a password-protected executable into the domain NETLOGON , guaranteeing execution on domain-joined hosts and rapid, automated propagation:

Impact: near-simultaneous execution across workstations and servers, massively increasing blast radius and reducing time-to-encryption.

T1490 – Inhibit System Recovery

Criminals shared mass service stop pattern used to render backups and critical applications nonfunctional:

Impact: Immediate takedown of backup engines, DB servers, virtualization management and some AV services – prevents backups from completing or being used for recovery and increases downtime.

Process-level disruption – forced terminations (commands)

Mass process termination pattern used to stop running backup/DB/remote-access/AV and productivity processes:

Impact: Halts live services and processes that could otherwise allow partial access to data or enable live backups/restores; forces system states incompatible with normal operations and complicates forensic collection.

T1486 – Data Encrypted for Impact

Ransom artifacts and execution parameters:

Final self-cleanup batch (behavior described): the ransomware drops {filename}.exe.bat that pings localhost briefly, deletes the ransomware binary, then deletes itself.

Beyond service and process termination, the ransomware executes additional commands to impede recovery and forensic investigation:

Deletes the Recycle Bin content: cmd /C “rd /s /q C:\$Recycle.Bin”

Deletes Remote Desktop Protocol (RDP) log files: cmd /C “del /f /q %SystemRoot%\System32\LogFiles\RDP*\*.*”

Deletes Windows Defender support files: cmd /C “del /f /q C:\ProgramData\Microsoft\Windows Defender\Support\*.*”

Deletes Prefetch files: cmd /C “del /f /q C:\Windows\Prefetch\*.*”

Adds C:\ to Windows Defender exclusion path: powershell -Command “Add-MpPreference -ExclusionPath C:\ -Force”

Adds the {filename} of the ransomware to the Windows Defender exclusion process: powershell -Command “Add-MpPreference -ExclusionProcess C:\Users\User\Desktop\{filename}.exe -Force

Disables Windows Defender real-time monitoring: powershell -Command “Set-MpPreference -DisableRealtimeMonitoring $true -Force”

wevtutil cl Application

Deletes shadow copies:

wmic shadowcopy delete

vssadmin delete shadows /all /quiet

Impact: Encrypted files and the presence of README-GENTLEMEN.txt enable double-extortion demands; the self-deleting cleanup limits post-infection artifacts and complicates malware sample recovery.

On 21 September 2025 the Windows component of Gentlemen introduced a background timer. The malware sits in the foreground and does nothing until the user (or attacker) supplies the –T flag. The value of this flag is interpreted as minutes, giving the operator a simple way to delay execution until a chosen time.

The same day an aggressive WMI‑based spread was added. This “under‑the‑hood” attack performs three key steps on every available workstation in the domain: it disables Windows Defender, adds drive C to the exclusion list and excludes its own process name from Defender. After these actions every machine that runs the spread copies the locker binary to its temporary folder and immediately re‑executes it on all visible machines in the network. The result is an essentially infinite recursive spread – a perfect storm for rapid infection.

The lockers themselves are protected by passwords. If the password was not in place, the operator would have been unable to reach victims later on. A similar timer flag (–T or –timer) was also introduced for the ESXi lockers, allowing a single‑use delay before code execution.

On 10 September 2025 a new ESXi‑specific locker was released. This version kills all processes on the host except those explicitly exempted, removes any snapshots that might be used for recovery, disables auto‑start services (critical for persistence removal), and shuts down VMware services. Only after these steps does the locker begin encrypting data on the host.

The operator also added a “re‑kill” mechanism that triggers if a process terminates unexpectedly, ensuring the malware remains active even if it gets stuck. Additional minor tricks were mentioned but not detailed.

The builder component was then compiled into a single executable called GLOCKER. It offers one‑click deployment and prompts the user for a target name so that victim identity is not lost. This makes the tool easy to use and harder for defenders to track.

Figure 9. Example of builder process.

Work remaining includes adding support for ESXi 5.5, refining the locker with several new features:

File squeezing – the locker can kill any process holding a file (except itself) before locking it.

Windows path specification – similar to the Linux support already in place.

Mutex on launch – prevents multiple instances from running simultaneously, a useful way to avoid detection.

Wallpaper/style customization – changes the desktop background for a more subtle presence.

Other planned capabilities are:

Network discovery – the malware will scan for SMB shares and mount them before locking, a complex but powerful way to expand reach.

Automatic spread via Group Policy Objects – enabling domain‑wide propagation without manual intervention.

Operationally, the operator advises against printing ransom notes on printers. A physical printout would draw unwanted attention; quieter, less obvious methods are preferred.

Figure 10. Command-line arguments of Linux version Gentlemen ransomware.

Figure 11. Command-line arguments of ESXi version Gentlemen ransomware.

Figure 12. Command-line arguments of Windows version Gentlemen ransomware.

Figure 13. Screenshot of encrypted ESXi.

Reconnaissance & Network Discovery

hastalamuerte leverages specialized engines, particularly Shodan and ZoomEye, to identify and enumerate publicly exposed Fortinet devices via API queries.

SoftPerfect Network Scanner

A cracked version of this commercial network scanning software has been distributed within the group’s communications.

MD5 Hash: d65c293efb5e6d033c83b2ac472bf0cb

Source of tool:

Exploitation & Lateral Movement

This tool serves as a primary framework for post-exploitation activities, including:

Windows host and discovery

Credential brute-forcing

Lateral movement across networks

Screenshots of using NetExec:

Figure 14. Using NetExec by Gentlemen ransomware members on real targets.

Figure 15. Using NetExec by Gentlemen ransomware members on real targets.

Figure 16. Using NetExec by Gentlemen ransomware members on real targets.

Figure 17. Using NetExec by Gentlemen ransomware members on real targets.

Reference: NetExec Token Broker Cache Dumping

• Weak file permissions

• Secure config file permissions

• Regular credential rotation

• Token lifetime management

• Privilege escalation in sync

• Least privilege for sync accounts

• Regular credential updates

• OAuth token exposure

• Secure application permissions

• Cloud app security policies

• Weak cache encryption

• Regular cache clearing

• Endpoint protection

• WDigest protocol flaws

• Weak profile protection

• Credential Guard evasion

• Restricted admin mode

• Weak encryption of saved passwords

• Insecure cached web credentials

• Use enterprise password managers

• Clear browser data regularly

• Enable device encryption

DonPAPI Automates remote extraction of secrets from multiple Windows computers simultaneously.

Custom-developed Capabilities

MD5 Hash: 42c062d6299ca9f76554441a29429404

This PowerShell script exploits VMware environments by leveraging the PowerCLI module to:

Establish remote connections to hypervisors via vCenter/vSphere (Connect-VIServer -Server $Server -Credential $Cred -Force).

Disable High Availability (HA).

Disable Distributed Resource Scheduler (DRS).

Power off virtual machines.

Status: Confirmed use in active intrusions.

Figure 18. Example of status HA and Drs before executing script.

Figure 19. Status of VMs before executing script.

Figure 20. Executing script.

Figure 21. Malicious script disables cluster protection mechanisms.

Keylogger (Go-based) Three versions of a custom Go-based keylogger were shared by the criminals, though the tool appears non-functional. The actor acknowledged bugs requiring fixes, and no evidence exists of operational use.

BYOVD (Bring Your Own Vulnerable Driver)

The group employs vulnerable signed drivers to terminate EDR/AV processes:

Status: Confirmed use in intrusions Additional BYOVD Resources (No confirmed operational use): EDR-Freeze Tool – Analysis Research Tools Discussed: PPL Process Scanner

A GitHub-hosted webshell for Windows systems. Screenshots show deployment on a possible victim. Reference: AntSword

Figure 22. Executing AntSword on real target.

Figure 23. Executing AntSword on real target.

Command & Control / Persistence

MeshCentral – Free remote monitoring and management (RMM) software commonly abused by extortion groups for persistence and C2. Status: CLI screenshot shared, no confirmed use in intrusions

Figure 24. Screenshot of using MeshCentral.

Anydesk – Remote desktop software discussed within group communications for persistent access and command & control. The threat actor shares automated deployment scripts with hardcoded passwords for unauthorized remote access.

Status: Discussion only; no evidence of operational use by this group

Deployment Method 1: One-liner Script

The criminals a batch script (deploy.cmd) for rapid deployment:

Execution via NetExec (old version):

Deployment Method 2: Conti-style PowerShell Function

The group shares a deployment technique originally used by Conti ransomware:

Velociraptor – an advanced digital forensic and incident response (DFIR) tool discussed in group communications. While criminals appear unfamiliar with the software, multiple security vendors have documented its abuse for C2 and ransomware deployment (Warlock, LockBit, Babuk).

Status : Discussion only, no evidence of operational use by this group

Related Resources that shared shared by the criminals in their discussion:

Sophos Report – Velociraptor Abuse

Talos Intelligence – Storm-2603 Campaign

N1ghtFury74::Scripts – Automated Velociraptor deployment

MSI sample shared on VT by hastalamuerte

Primary tool for data exfiltration. The actor has also suggested MEGA as an alternative platform.

Artificial Intelligence Integration

The threat actor actively employs AI tools for various operational purposes, including the development of The Gentlemen ransomware.

Confirmed AI Platforms in Use

Screenshots with proof:

Figure 25. Screenshot of using ChatGPT by Gentlemen ransomware members.

Figure 26. Screenshot of using Gemini by Gentlemen ransomware members.

Claude AI – Penetration Testing Integration

While not confirmed in intrusions, the group has referenced a project integrating Kali Linux tools with Claude Desktop via the Model Context Protocol (MCP) for automated penetration testing.

Additional MCP Resources Discussed:

Claude Kali Commander – Integrates Kali Linux tools with Claude

AdaptixC2 MCP Server – MCP integration for C2 framework

Alternative AI Models

Due to ChatGPT restrictions, the actor recommends local alternatives with fewer content limitations:

Older versions of GPT-4

The Gentlemen represents a textbook example of the modern ransomware ecosystem’s fluidity and pragmatism. Born from a payment dispute with Qilin, this operation demonstrates how quickly experienced affiliates can pivot to launch independent RaaS programs and how shared TTPs transcend group branding. After all, obvious solutions become self-reinforcing as everyone expects everyone else to use them as well. The Gentlemen has rapidly established itself as a credible threat to organizations worldwide.

What makes this group particularly concerning is not novelty, but effectiveness: they weaponize well-documented vulnerabilities like CVE-2024-55591, rely on perennially weak credentials, and systematically disable defenses using BYOVD techniques and AI-assisted development. Their targeting of healthcare and critical infrastructure reveals a profit-driven disregard for operational impact. The administrator hastalamuerte’s operational security failures, from hardcoded forum references to public disputes, provide valuable intelligence, but do not diminish the group’s technical capability or reach.

The real lesson here extends beyond The Gentlemen. Ransomware affiliates rotate between groups, absorbing and sharing knowledge across operations. Tomorrow’s attack may carry a different name, but the TTPs are remarkably consistent. Defenders must prioritize patching internet-facing assets, enforce strong authentication, implement robust EDR with driver-load monitoring, segment networks, secure backup infrastructure offline, and focus threat intelligence efforts on adversary behaviors rather than trying to keep up with ever-changing group names.

The underground ecosystem ensures that today’s The Gentlemen affiliate may become tomorrow’s new RaaS operator. Focus on the how, not just the who.

Although ransomware groups have gained notoriety for targeting critical sectors, they pose a threat to organizations across all industries. The growth of affiliate programs continues to equip cybercriminals with advanced tools and techniques. Here are essential steps to protect your mission-critical operations and data:

Implement Multi-Factor Authentication (MFA): Deploy MFA and credential-based access controls wherever possible, especially for privileged or high-risk accounts. This adds a critical validation layer, making unauthorized entry significantly more difficult.

Deploy Advanced EDR Solutions: Leverage Endpoint Detection and Response (EDR) solutions with behavioral detection capabilities to identify ransomware indicators across managed endpoints. This proactive approach enables agile detection, investigation, and remediation of both known and unknown threats.

Maintain Regular Backups: Conduct data backup processes regularly and store backups offline or on separate networks to protect against lateral movement by criminals.

Utilize AI-Based Detection and Analytics: Employ advanced malware detonation solutions that leverage AI-infused, analytics-based platforms to analyze and quarantine suspicious files before execution, detecting intrusions in real-time.

Deploy Managed XDR with Threat Intelligence: Implement Group-IB’s Managed XDR coupled with Threat Intelligence for comprehensive protection. This solution provides: Insights into unique TTPs: Gain visibility into Tactics, Techniques, and Procedures used by APTs and ransomware groups, enabling faster security pivots. Multi-layered cybersecurity: Protect across endpoint, email, web, and network layers. Automated threat detection and response: Leverage behavioral analytics to identify and respond to both known and emerging threats. Real-time intrusion detection: Detect sophisticated threats like Rust-based ransomware that evade traditional antivirus engines.

Insights into unique TTPs: Gain visibility into Tactics, Techniques, and Procedures used by APTs and ransomware groups, enabling faster security pivots.

Multi-layered cybersecurity: Protect across endpoint, email, web, and network layers.

Automated threat detection and response: Leverage behavioral analytics to identify and respond to both known and emerging threats.

Real-time intrusion detection: Detect sophisticated threats like Rust-based ransomware that evade traditional antivirus engines.

Implement Business Email Protection: Deploy Group-IB’s Business Email Protection to effectively counter spear phishing attacks, which remain a primary initial access vector for ransomware groups. This dedicated email security solution helps prevent credential theft and malicious payload delivery before they reach user inboxes.

Prioritize Patch Management: Establish a routine process to regularly review and apply security patches as they become available. The longer vulnerabilities remain unpatched, the greater the exploitation risk.

Enable Attack Surface Reduction Rules: Configure rules that specifically block ransomware activities and credential theft attempts to minimize potential attack vectors.

Monitor Remote Access Infrastructure: Investigate unusual activity in event logs immediately. Ensure password resets for all accounts in case of compromise.

Incorporate Known IOCs into IDS: Add known Indicators of Compromise (IOCs) from recent attacks into your Intrusion Detection System (IDS) to catch suspicious behavior related to emerging threats.

Maintain Continuous Malware Monitoring: Stay current on intelligence and advancements regarding existing and emerging malware types to effectively prevent, defend against, and mitigate these threats.

Conduct Security Awareness Programs: Educate employees organizational risks through regular training programs and security drills. Help them identify and report tell-tale signs of cybercrime, such as phishing emails. The human factor remains one of the greatest cybersecurity vulnerabilities.

Practice Strong Cyber Hygiene: Ensure users verify the validity of emails, links, downloads, and other sources before engaging. All sources should be authenticated before interaction.

Perform Regular Technical Audits and Security Assessments: Conduct annual or biannual infrastructure checks through technical audits or comprehensive security assessments. Monitor infrastructural integrity and digital hygiene processes continually to uncover hidden weaknesses and maintain strict access control and configuration management. Group-IB’s Vulnerability Assessment service provides thorough evaluation of your infrastructure, helping identify vulnerabilities before attackers can exploit them.

Never Pay the Ransom – Incident Response Experts Immediately: An experienced team will manage containment, eradication, and recovery efforts professionally and efficiently. Group-IB Incident Response experts strongly advise against paying ransoms because: Payment encourages further extortion and signals your willingness to pay. It leads to increased future attack attempts on your organization. In 97% of cases, regaining access without proper decryption remains uncertain. Financially-motivated threat actors are driven to make you pay more. Even if one attacker returns your data, others will learn of your compliance.

Payment encourages further extortion and signals your willingness to pay.

It leads to increased future attack attempts on your organization.

In 97% of cases, regaining access without proper decryption remains uncertain.

Financially-motivated threat actors are driven to make you pay more.

Even if one attacker returns your data, others will learn of your compliance.

Frequently Asked Questions (FAQ)

Ransomware is a type of malicious software (malware) designed to deny access to a computer system or data until a ransom is paid. Modern ransomware typically works by encrypting files on infected systems using strong cryptographic algorithms, making them inaccessible without the decryption key held by attackers. Find out more ransomware on the Group-IB Knowledge Hub .

What is BYOVD (Bring Your Own Vulnerable Driver)

BYOVD (Bring Your Own Vulnerable Driver) is an advanced attack technique where cybercriminals exploit legitimately signed but vulnerable Windows drivers to gain kernel-level access to a system. Since these drivers are digitally signed by trusted vendors, they can bypass Windows security controls. Attackers load these vulnerable drivers and exploit their flaws to terminate security software, manipulate system processes, or disable protective mechanisms at the deepest level of the operating system, where most security products cannot defend themselves.

What is a RaaS (Ransomware-as-a-Service) operation?

What is double extortion?

Double extortion is a ransomware tactic where attackers both encrypt victim data AND steal copies before encryption. Victims face two threats: (1) loss of access to encrypted files, and (2) public release of sensitive data if ransom isn’t paid. This makes backup strategies alone insufficient, as attackers can still leak stolen data even if victims recover files from backups. Some groups have evolved to “triple extortion” (threatening customers, partners, or regulators) or even “quadruple extortion” (DDoS attacks during negotiations).

What is a Data Leak Site (DLS)?

Indicators of Compromise (IOCs)

194[.]87[.]31[.]69 – Rclone

51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2

3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235

d65c293efb5e6d033c83b2ac472bf0cb

42c062d6299ca9f76554441a29429404

2834114ff7e487c4ca3f50ca39f7d652dea1be98f885c388f01b6ff35309307b

efd5366eb7473d6f7fb97ec7ac59f09d

8901ce810f999f79c51c4d4f6c93fe6b

DISCLAIMER: All technical information, including malware analysis, indicators of compromise and infrastructure details provided in this publication, is shared solely for defensive cybersecurity and research purposes. Group-IB does not endorse or permit any unauthorized or offensive use of the information contained herein. The data and conclusions represent Group-IB’s analytical assessment based on available evidence and are intended to help organizations detect, prevent, and respond to cyber threats.

Group-IB expressly disclaims liability for any misuse of the information provided. Organizations and readers are encouraged to apply this intelligence responsibly and in compliance with all applicable laws and regulations.

This blog may reference legitimate third-party services such as Telegram and others, solely to illustrate cases where threat actors have abused or misused these platforms.

This material is provided for informational purposes, prepared by Group-IB as part of its own analytical investigation, and reflects recently identified threat activity.

All trademarks referenced herein are the property of their respective owners and are used solely for informational purposes, without any implication of affiliation or sponsorship.