GBHackers

Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours


The Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours.

Demonstrating how rapidly modern affiliates can turn stolen credentials or exposed infrastructure into a full-scale business disruption.

Counter Threat Unit researchers tracking the operation as GOLD SHERWOOD found that the Gentlemen affiliates follow a repeatable post-compromise playbook: establish access, elevate privileges, turn off defenses, steal selected data, sabotage backup services, and deploy ransomware.

Across 15 incidents, the median time from first observed malicious activity to ransomware deployment was about two days, while the fastest intrusion reached encryption in less than a day.

The operation’s leak-site activity expanded sharply in 2026. By the end of July, The Gentlemen had listed 683 victims, with 169 added during July alone.

That pace made its leak site the most active ransomware publication platform that month, according to the CTU research supplied for this report.

The group’s victim list spans numerous industries rather than focusing on one vertical, reinforcing the assessment that affiliates prioritize whatever accessible organizations they can monetize.

An affiliate-recruitment advertisement published on the RAMP cybercrime forum reportedly offered a 90/10 ransom split, a model designed to attract operators capable of bringing their own access and intrusion skills.

Initial access appears closely tied to exposed Fortinet infrastructure and compromised VPN credentials.

Group-IB documented The Gentlemen affiliates scanning internet-facing FortiGate management interfaces and exploiting CVE-2024-55591, an authentication-bypass vulnerability affecting FortiOS and FortiProxy.

The researchers also reported brute-force activity against FortiGate VPN services and a database of previously compromised devices and credentials.

In one February intrusion described by CTU, an actor authenticated to a Fortinet SSL VPN using compromised user credentials.

The absence of multi-factor authentication enabled the intrusion. Within an hour, the actor created additional VPN sessions from foreign IP addresses, indicating that the access was being validated and made resilient before broader operations began.

The early-access behavior is significant: MFA gaps and unpatched perimeter appliances can provide affiliates with an immediate foothold, while legitimate VPN authentication makes the first stages of an intrusion harder to distinguish from normal remote work.

Once inside, The Gentlemen affiliates rely heavily on valid domain credentials and native Windows administration tools.

Number of victims listed on The Gentlemen leak site each month from September 2025 through July 2026 (Source : Sophos).

They use Remote Desktop Protocol to move between systems, including file servers and domain controllers, while commands such as net1 localgroup and net group add attacker-controlled accounts to privileged local and domain groups.

Researchers repeatedly found attack utilities staged in C:PerfLogs, a legitimate Windows directory that often receives less scrutiny than conventional temporary folders.

Rapid Ransomware Deployment

The files included network-discovery utilities, exfiltration software, backup tools, EDR-killing programs, and vulnerable drivers.

Advanced IP Scanner and SoftPerfect Network Scanner were used to identify valuable systems, backup infrastructure, and data repositories.

Proportion of listed The Gentlemen ransomware victims by sector (Source : Sophos).
Proportion of listed The Gentlemen ransomware victims by sector (Source : Sophos).

Actors also queried the LSASS process identifier, a precursor to credential dumping with tools such as Mimikatz.

Persistence methods included enabling RDP through registry changes, opening TCP port 3389 in the Windows firewall, and deploying Cloudflared as a service to create an alternate remote-access tunnel.

Defense evasion is central to the operation. The Gentlemen provides affiliates with an in-house EDR-killer framework called GentleKiller, which uses the Bring Your Own Vulnerable Driver technique to obtain kernel-level capabilities and terminate security processes.

ESET identified at least eight GentleKiller variants targeting more than 400 processes associated with 48 security products.

Sophos Researchers said that, GOLD SHERWOOD launched The Gentlemen RaaS program in mid-2025, using a double-extortion model in which affiliates exfiltrate data, then encrypt systems and threaten to publish it if the victim refuses to pay.

Affiliates also attempt to weaken Microsoft Defender through PowerShell exclusions or registry-based policy changes. In parallel, they disable backup and recovery services, including Veeam, SQL Writer, and Backup Exec components, shortly before ransomware deployment.

Data theft is equally adaptive. Rclone was the preferred exfiltration utility, but researchers observed actors switching between Rclone, Restic, and MinIO Client depending on transfer performance, data volume, and environmental constraints.

Organizations should treat exposed remote access as a high-risk ransomware entry point.

The immediate priorities are enforcing phishing-resistant MFA on VPN and administrative services, patching internet-facing firewalls, restricting RDP exposure, and monitoring anomalous VPN sessions, especially logins from multiple foreign IP addresses.

Security teams should also alert on executable staging in C:PerfLogs, suspicious use of Rclone, Restic, mc, PsExec, Cloudflared, and Windows commands that alter group membership, Defender exclusions, RDP settings, or backup-service configurations.

The key operational lesson is that ransomware containment must begin at the first signs of credential misuse; waiting for encryption behavior may leave defenders less than 24 hours to respond.

IOCs

IndicatorTypeContext
622b2ca08552535bc142cb815ff9ec16MD5 hashEDR killer used in The Gentlemen ransomware compromises (acronis.exe)
f0bc50d2d2838c5294e21cd9bce2f09bf581e508SHA1 hashEDR killer used in The Gentlemen ransomware compromises (acronis.exe)
a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c0efdSHA256 hashEDR killer used in The Gentlemen ransomware compromises (acronis.exe)
4741a4976c6abfb3c80c170104518b6eMD5 hashEDR killer used in The Gentlemen ransomware compromises (acronis.exe)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.



Source link