The Gentlemen ransomware operation is moving from access to full network encryption at striking speed. In some intrusions, attackers disabled defenses and recovery services before deploying ransomware in less than 24 hours across enterprises.
The group runs as a ransomware-as-a-service operation, meaning affiliates can strike organizations they can reach. Its double-extortion approach adds pressure: files are stolen first, then encrypted, leaving victims facing a data leak as well as operational disruption.
Analysts at Sophos examined 15 incidents linked to the group, tracked as GOLD SHERWOOD, and found a repeatable playbook.
The findings show how a small window after a suspicious login can quickly become a business-wide outage.
Sophos said in a report shared with Cyber Security News (CSN) that initial access appears to come from exposed firewall management interfaces, unpatched devices, or stolen VPN credentials.
A Fortinet SSL VPN account without multi-factor authentication gave the intruder a foothold, underlining why FortiOS authentication bypass vulnerability remains a serious concern for exposed infrastructure.
The Gentlemen Ransomware Hackers Disable EDR
Once inside, the affiliates moved across systems using legitimate domain credentials and Remote Desktop Protocol.
They placed their toolkit in a trusted Windows location that is often overlooked, then mapped systems, data stores, and backup infrastructure before the visible stage of the attack began.
They increased their control by changing administrator passwords, adding accounts to privileged groups, and enabling remote desktop access.
In several cases, they created firewall rules to allow outside RDP connections, providing a fallback route if the originally compromised VPN session was lost.
Next, they removed obstacles to encryption. Attackers used custom and publicly available utilities, including vulnerable drivers, to terminate antivirus and endpoint detection and response processes.
They also weakened Windows Defender by adding broad scan exclusions or changing policy settings. A recent report on ransomware operators disable EDR shows the broader pattern of crews stopping security and backup software before spreading across a network.
In this campaign, the effort was deliberate rather than incidental, with multiple approaches used when one method failed. Backup services were then disabled, often immediately before encryption.
They targeted recovery and backup-agent services, making it harder for teams to restore systems. In one intrusion, they also cleared Application, System, and Security event logs, obscuring the evidence responders need to trace the breach.
Rapid Encryption Playbook
Before locking systems, the group copied selected files with legitimate transfer tools. It commonly focused on newer data and used filters to reduce the volume transferred, which can make outbound activity less obvious while still collecting material valuable for extortion.
Affiliates adapted their process. Researchers saw them switch among transfer utilities and object-storage methods as conditions changed.
That flexibility resembles other attacks against remote infrastructure, including Gunra ransomware VPN attacks, where exposed access points can quickly lead to high-impact ransomware activity.
The median interval from first observed post-compromise activity to ransomware deployment was about two days. The shortest observed period was under 24 hours, leaving little room for manual investigation after an attacker gains entry.
The locker was deployed locally, through network shares, or across the domain using centralized logon shares and remote execution.
It encrypted files, assigned a six-character extension, and left a ransom note in affected directories. Although Windows was the only version deployed in the reviewed cases, related builds also support Linux and ESXi environments.
The pace makes prevention and early detection equally important. Organizations should patch internet-facing firewalls and VPN appliances, require MFA for every remote-access account, restrict RDP exposure, and closely review new privileged accounts. The Fortinet security update guidance provides useful context on fixing a flaw tied to the access methods investigated.
Teams should also alert on unusual activity from system staging folders, unfamiliar data-transfer utilities, Windows Defender exclusions, disabled backup services, cleared logs, and attempts to load vulnerable drivers.
Separating backups from ordinary administrator control and testing recovery plans can prevent attackers from turning a single compromised account into a prolonged outage.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| MD5 | 622b2ca08552535bc142cb815ff9ec16 | Sophos-listed threat indicator |
| SHA-1 | f0bc50d2d2838c5294e21cd9bce2f09bf581e508 | Sophos-listed threat indicator |
| SHA-256 | a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c | Sophos-listed threat indicator |
| MD5 | 4741a4976c6abfb3c80c170104518b6e | Sophos-listed threat indicator |
| SHA-1 | be8c52474ab79a52af31e3cb2f71638299a0de1d | Sophos-listed threat indicator |
| SHA-256 | ddba5b4e7a7ada77d56477e9d41c008f93e81d9a33ed09e77cb2af624f | Sophos-listed threat indicator |
| MD5 | 738df7ae0097f6bef93d65be5d4a2a26 | Sophos-listed threat indicator |
| SHA-1 | c96baab9b7e7ef661921d44d7900f165c794ed25 | Sophos-listed threat indicator |
| SHA-256 | 1a9291ec869155336bf185d221d655d11c77a55ea0c8ecc0274202f74a9 | Sophos-listed threat indicator |
| MD5 | d8691ef15eea27cfefafeeb485286080 | Sophos-listed threat indicator |
| SHA-1 | 8bca55b3c9bfbdf68c9b6c72a7b1bf1dd6d5e3b2 | Sophos-listed threat indicator |
| SHA-256 | 3c71537b64487bbf4d1793f72c75d332650d09a77b71e4d884ff15c266a | Sophos-listed threat indicator |
| MD5 | b23b653541bd95bdc4da07a0b07b57bf | Sophos-listed threat indicator |
| SHA-1 | f0537cbb773ae12100b36731e7c39f5a9d852b14 | Sophos-listed threat indicator |
| SHA-256 | 50f2cdf16f05da9253fa2d6eb60d5a42da14c02c551c0874c9e953d4119 | Sophos-listed threat indicator |
| SHA-256 | bf7a2fb7f7256809dc690213b85f747cef8db7b909caf9783cac181912fb | Sophos-listed threat indicator |
| SHA-256 | 761ce72420edf5e5531cdbad0e93397d7520cdead825886ca7f75cef76 | Sophos-listed threat indicator |
| MD5 | 002417da707b93bf5ce3cb26d28005f6 | Sophos-listed threat indicator |
| SHA-1 | 8732c1ff565828a0bdef514b5dc0dfea40c1d1f2 | Sophos-listed threat indicator |
| SHA-256 | 81053c2c3be8b7dbf7d5087dba05c940b3ee4fd95524272651c816b72c | Sophos-listed threat indicator |
| SHA-256 | 7a37acb031cddaa39ad20db0961baa5423ec53f318c49c9275c982507d | Sophos-listed threat indicator |
| MD5 | bc4a8d7bbbeb941265dfc954539326c0 | Sophos-listed threat indicator |
| SHA-1 | b7cea81e6de895d01d01d20bd6dcfd347940b57f | Sophos-listed threat indicator |
| SHA-256 | 3a31ec3bf9b7eac6593a723145381f5d0f4ede076c4c8818d949a08f559 | Sophos-listed threat indicator |
| SHA-256 | 68031d549de399a44bb00614b910106baccef5996623b2f1102352a52a | Sophos-listed threat indicator |
| SHA-1 | 058c3ff21e79770e4a60937c27b1ede227709248 | Sophos-listed threat indicator |
| SHA-1 | 9c0b05eb75f971cc25ee979e49b227b86b19e833 | Sophos-listed threat indicator |
| SHA-1 | a438ba2122a814320f47a056f04122f81c2ae6c5 | Sophos-listed threat indicator |
| SHA-1 | a8ba89e67297642dcc1ae77433ab84e1f27d1792 | Sophos-listed threat indicator |
| MD5 | 8ea97d01cbf459b94d134d05c54cd33e | Sophos-listed threat indicator |
| SHA-1 | 5c9bf6b7e4c7dc9b9227ce86e2d271d624c35147 | Sophos-listed threat indicator |
| SHA-256 | 0be8f415a485b11747bcfd71c9cd9781e090354728f076791ed6845b69e | Sophos-listed threat indicator |
| MD5 | 07e9f0b8627a95960e79e930fb099e84 | Sophos-listed threat indicator |
| SHA-1 | 56bee9df5833a637f5c54d5911df98b0812fe643 | Sophos-listed threat indicator |
| SHA-256 | 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c | Sophos-listed threat indicator |
| SHA-256 | ccdde8091d63eaafbe30d9f0482afd245abc10ab16e21ae9254e51e42cb | Sophos-listed threat indicator |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

