The Gentlemen are knocking: сustom backdoors and evolving tactics
The Gentlemen ransomware group operates a RaaS model targeting large corporations and critical infrastructure worldwide. The group gains initial access through internet-exposed VPN/firewall vulnerabilities and stolen credentials, conducts internal reconnaissance using custom and off-the-shelf tools, and deploys a custom Go-based backdoor for C2 prior to ransomware deployment. The ransomware uses GPO-based and PsExec-based lateral movement, BYOVD techniques to disable security software, and hybrid encryption (Curve25519+XChaCha20 in the Go variant, AES256-GCM+RSA in the emerging C variant). A new C-based variant is under active development, indicating the group is expanding its capabilities.
- filenamedeploy_gpo.ps1PowerShell script generated by the ransomware in %temp% when the --gpo parameter is used. Copies ransomware to NETLOGON share, creates fake GPO to disable Defender, and forces group policy update across all domain computers.
- filename!-READ-ME—-GEN-TLE-MEN-!.txtRansom note filename created by the C-based ransomware variant. This variant shifts communication from Tox Messenger to email.
- filenameREADME-GENTLEMEN.txtRansom note filename created by the Go ransomware variant in each encrypted directory. Contains victim ID, Tox ID, and Data Leak Site address.
- filenameScheduledTasks.xmlMalicious XML file created in the SYSVOL directory by deploy_gpo.ps1 to register a hidden scheduled task that downloads and runs the ransomware on all domain computers via GPO.
- ip81[.]177[.]215[.]15C2 server for the Go-based backdoor implant. The backdoor connects to this IP on TCP port 9443 using the Yamux library for persistent bidirectional communication, enabling remote command execution and SOCKS proxying.
- md502944c8a5535cdb5b2cbb893db2d5acfGo ransomware binary: locker_lqy8xb_windows_amd64.exe
- md510ca9a4040001560d053b7e7885c1b95Go ransomware binary: locker_28f3cl_windows_386.exe
- md53b46a729db7ae6af8b19711c9452194dGo ransomware binary: locker_eryoo5_windows_amd64
- md53c471ebc947cdf32240a90ffadf49b13Go ransomware binary: locker_aga19g_windows_amd64.exe
- md5407b6a136bbaa7172eb44ef9d08bb58aVulnerable driver: biontdrv_winbs.sys (Paragon partition manager driver) used in BYOVD attacks
- md54be8bb62f0ebbcf4ce52c35ab6f794f5Go ransomware binary: locker_wh54td_windows_386.exe
- md5525ef6014f0ef20e44fe47c1d9980b69Vulnerable driver: biontdrv_wink.sys (Paragon partition manager driver) used in BYOVD attacks
- md553c616677bc7e2a0a03127f19166d007Go ransomware binary: locker_p663zs_windows_amd64.exe
- md55537c708edb9a2c21f88e34e8a0f1744Scanning tool: Advanced_IP_Scanner_2.5.4594.1.exe used for network reconnaissance
- md5554e699c96b332468f1ae69c1ae81ef9MD5 hash of sihost.exe, the custom Go-based backdoor implant. Deployed approximately one day before ransomware execution to establish C2, collect system information, and enable lateral movement via SOCKS proxy.
- md55761bd63da03686fc480245da7bd1e9fVulnerable driver: processmonitordriver.sys (Safetica DLP and EDR driver) used in BYOVD attacks
- md55c3b9821fc82a9028cb63b9671950919MD5 hash of locker.exe, the primary Go-based ransomware binary used in most attacks since mid-2025.
- md55f0b2c6d9f442754258bf4dd841c8341Go ransomware binary: locker_t1zged_windows_amd64.exe
- md5608faf58353b65c45ef9833358ac3787Go ransomware binary: locker_u90lyt_windows_amd64.exe
- md56ae7c9a7ea0b8c40a64225734f6bd01dMD5 hash of gentle.exe, another Go-based ransomware binary used by The Gentlemen group.
- md573f0a8c3ea794a04e80c32038249f044Vulnerable driver: wsddprm.sys (Topaz anti-fraud software driver) used in BYOVD attacks
- md5846dc77c1246db20d976346e0e359502Go ransomware binary: locker_p663zs_windows_386.exe
- md58f0577d28c4ff5f71b149f444bfaba8eVulnerable driver: gamedriverx64.sys (Fedeen/Hotta studio anti-cheat driver) used in BYOVD attacks
- md59321a61a25c7961d9f36852ecaa86f55Vulnerable driver: inpoutx64.sys (legacy RGB lighting driver) used in BYOVD attacks
- md5adac9984b3cc43d66a0d33079bbec299Go ransomware binary: UcAaJ_o_1j9srso9a14071ps4p7s3f81s1b
- md5ae0e536766788478263bf448a9381641Go ransomware binary: cosmo.exe
- md5b3e418d30312c1b2c58a791286868f42Go ransomware binary: system_386.exe
- md5b6b51508ad6f462c45fe102c85d246c8Vulnerable driver: wamsdk.sys (WatchDog anti-malware driver) used in BYOVD attacks
- md5b9986a0f1f1f1a798dc3f0c59a80a1a3MD5 hash of fin.exe, the new C-based ransomware variant still in development. Uses AES256-GCM+RSA encryption instead of the Go variant's Curve25519+XChaCha20 scheme.
- md5c2764744dcb4b0e1db79ca1e8bf65368Go ransomware binary: getlwd.exe
- md5d12a5b36dd00586cc374a1cae43efed4Go ransomware binary: locker_c65ffp_windows_amd64.exe
- md5d2f72897e8986303d5567eb2384932b8Go ransomware binary: UcAaJ_o_1j9srso9a14071ps4p7s3f81s1b (duplicate filename, different hash)
- md5de1522f9219497632f30f8a6e72f26b6Go ransomware binary: locker_c7ekh7_windows_amd64.exe
- md5edb1c480295250dd1a38f3aa1357deaeScanning tool: netscan64.exe used for network reconnaissance
- md5eef8a950952696b018aa9c6da2f5d7adVulnerable driver: havoc.sys (Huawei audio driver) used in BYOVD attacks
- md5fdae2beb813778b4540a997706862096Go ransomware binary: AIR.exe
- registry_keyHKLM\SOFTWARE\Policies\Microsoft\WindowsDefenderRegistry key modified to disable Windows Defender real-time protection. The group sets DisableAntiSpyware, DisableBehaviorMonitoring, DisableOnAccessProtection, and DisableScanOnRealtimeEnable to 1.
Detection / Hunteropenrouter
What Happened
A criminal group called The Gentlemen is running a ransomware-as-a-service operation, where they rent out their ransomware to other criminals who then attack companies. They break into organizations by exploiting weaknesses in internet-facing devices like VPNs and firewalls, often using stolen passwords. Before locking up files, they plant a hidden backdoor program that lets them remotely control the compromised computers and move through the network. They also disable antivirus software using a technique that installs vulnerable driver files. The ransomware itself spreads automatically across an organization's network by abusing Windows group policy settings, encrypting files on all computers at once. A newer version of their ransomware is being developed, suggesting the group is growing and adapting. Organizations should focus on patching vulnerabilities, strengthening login security, and monitoring for unusual activity on their networks.
Key Takeaways
- The Gentlemen ransomware group operates a RaaS model and has rapidly become a top-10 ransomware actor by victim count in the first half of 2026, targeting critical infrastructure and large corporations globally.
- A custom Go-based backdoor was deployed prior to ransomware execution, establishing persistent C2 via the Yamux library on TCP port 9443, supporting remote command execution and SOCKS proxying for internal pivoting.
- The group uses BYOVD (Bring Your Own Vulnerable Driver) to disable security software, leveraging at least seven different vulnerable drivers including ProcessMonitorDriver.sys, biontdrv.sys, and havoc.sys.
- A new C-based ransomware variant is in development, switching from Curve25519+XChaCha20 to AES256-GCM+RSA encryption and shifting communication from Tox Messenger to email.
- Lateral movement is achieved through GPO deployment via a generated deploy_gpo.ps1 script that copies the ransomware to NETLOGON, creates a fake update policy disabling Defender, and forces group policy refresh across all domain computers.
Affected Systems
- Windows endpoints and servers (amd64 and 386 architectures)
- Windows Domain Controllers
- Hyper-V virtual machines
- Hardware VPNs and firewalls exposed to the internet
- Linux ESXi servers (C-based variant mentioned but not detailed)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Exploit vulnerabilities in internet-exposed VPNs/firewalls or use stolen/weak credentials, potentially sourced from initial access brokers
- Reconnaissance: Deploy SharpADWS, NetScan, Advanced IP Scanner, and netsh to enumerate Active Directory, scan network services, and capture network traffic for credentials
- Backdoor Deployment: Deploy custom Go-based backdoor (sihost.exe) that connects to C2 at 81.177.215.15:9443, collects system info, executes commands, and establishes SOCKS proxy for pivoting
- Defense Evasion: Use BYOVD technique with vulnerable drivers, Windows Kernel Explorer, OpenArk64, and registry modifications to disable security software and Windows Defender
- Lateral Movement: Spread ransomware via GPO deployment (deploy_gpo.ps1 copying to NETLOGON and creating malicious ScheduledTasks.xml) or PsExec with domain computer enumeration via RSAT
- Impact: Stop Hyper-V VMs and processes, encrypt files using Curve25519+XChaCha20 (Go) or AES256-GCM+RSA (C variant), drop ransom notes, delete shadow copies and event logs
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article does not include detection rules. IOCs including file hashes, IP addresses, and command-line fragments are provided in the text. Additional IOCs are available to Kaspersky Intelligence Reporting Service customers via [email protected].
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | Many activities such as scheduled task creation, registry modifications, and process execution would be visible to EDR. However, the BYOVD technique and use of kernel-level tools (Windows Kernel Explorer, OpenArk64) to disable security drivers could blind EDR sensors. The Go backdoor uses standard cmd.exe for execution which may blend with legitimate activity. |
| Network Visibility | Medium | The backdoor C2 connection to 81.177.215.15:9443 over TCP would be visible in network telemetry. The netsh packet capture and SOCKS proxy traffic could also be detected. However, if the C2 uses standard TCP without TLS, it may not trigger network inspection rules. Internal lateral movement via SMB and NETLOGON may appear as legitimate admin traffic. |
| Detection Difficulty | Hard | The group uses multiple defense evasion techniques including BYOVD to disable security software, custom Go obfuscation, and legitimate admin tools (netsh, PsExec, RSAT). The GPO-based lateral movement abuses legitimate Windows infrastructure. The backdoor uses standard cmd.exe execution. Detection requires correlation across multiple telemetry sources and behavioral analysis rather than simple signature matching. |
Required Log Sources
- Windows Security Event Log (Event IDs 4624, 4688, 4698, 4702, 5140, 5145)
- Windows System Event Log
- Windows Application Event Log
- PowerShell Script Block Logging (Event ID 4104)
- Windows Defender Event Log
- Sysmon Event Logs (Event IDs 1, 3, 7, 11, 12, 13, 22)
- DNS resolution logs
- Network firewall/IDS logs for C2 traffic
- Active Directory Group Policy change logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for processes loading vulnerable driver files associated with BYOVD attacks, particularly driver files being loaded from non-standard paths or by unexpected processes. This would typically correspond to T1562.001. | Sysmon Event ID 6 (driver loaded), EDR driver load events, Windows System Event Log | Defense Evasion | Medium — legitimate software may load some of these drivers (e.g., Paragon partition manager, Huawei audio driver). Correlate with subsequent security tool termination or registry modifications. |
| Consider hunting for modifications to Windows Defender registry keys under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender, specifically DisableAntiSpyware or DisableRealtimeMonitoring being set to 1. This would correspond to T1562.001. | Sysmon Event ID 12/13 (registry value set), Windows Security Event Log, EDR registry monitoring | Defense Evasion | Low — these registry changes are rarely made by legitimate administrative tools in enterprise environments. |
| Consider hunting for scheduled task creation with names 'UpdateUser' or 'TaskSystem' configured for ONSTART or DAILY execution, especially when the task command points to an executable in a temporary or unusual path. This corresponds to T1053.005. | Windows Security Event ID 4698 (scheduled task created), Sysmon Event ID 1 (process creation), EDR scheduled task monitoring | Persistence | Low — these specific task names are not associated with legitimate software. |
| Consider hunting for files named deploy_gpo.ps1 or ScheduledTasks.xml being created in the SYSVOL directory or NETLOGON share, which would indicate GPO-based ransomware deployment. This corresponds to T1570. | File system monitoring on domain controllers, Sysmon Event ID 11 (file creation), EDR file creation events | Lateral Movement | Low — legitimate GPO scripts are typically not named deploy_gpo.ps1, and ScheduledTasks.xml in SYSVOL with task content pointing to executables is suspicious. |
| Consider hunting for outbound TCP connections to port 9443 from processes exhibiting backdoor behavior such as spawning cmd.exe child processes or establishing SOCKS proxy connections. This corresponds to T1090.001 and T1059.001. | Network connection logs, EDR network events, Sysmon Event ID 3 (network connection) | Command and Control | Medium — port 9443 is used by some legitimate applications. Correlate with process behavior and known-bad IP 81.177.215.15. |
Control Gaps
- BYOVD attacks exploit vulnerable signed drivers that are legitimately loaded by the kernel, bypassing driver signature enforcement and potentially blinding EDR before detection logic can fire.
- GPO-based lateral movement abuses legitimate Windows infrastructure (SYSVOL, NETLOGON, Group Policy) which may not be monitored for malicious content by standard endpoint controls.
- The Go backdoor uses standard cmd.exe for command execution and TCP for C2, which may not trigger network IDS signatures without specific port or IP-based rules.
- Volume shadow copy deletion and event log clearing occur rapidly during the impact phase, potentially destroying forensic evidence before analysts can respond.
- If initial access is obtained through an IAB, the time gap between initial compromise and ransomware deployment may exceed typical detection windows, allowing attackers to establish persistence unnoticed.
Key Behavioral Indicators
- Process ancestry: sihost.exe spawning cmd.exe with /c argument, especially when sihost.exe is not in a standard system path
- Registry pattern: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender with DisableAntiSpyware set to dword:00000001
- Registry pattern: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run with value name 'GupdateS'
- Scheduled task named 'UpdateUser' with ONSTART trigger or 'TaskSystem' with DAILY trigger at 20:00
- File creation of deploy_gpo.ps1 in %temp% directory
- File creation of ScheduledTasks.xml in SYSVOL directory
- File creation of README-GENTLEMEN.txt or !-READ-ME—-GEN-TLE-MEN-!.txt in multiple directories
- Sequential execution of vssadmin.exe delete shadows, wmic.exe shadowcopy delete, and wevtutil.exe cl commands
- Driver loading events for processmonitordriver.sys, wamsdk.sys, gamedriverx64.sys, biontdrv.sys, inpoutx64.sys, wsftprm.sys, or havoc.sys from non-standard paths
- PowerShell execution of Set-MpPreference -DisableRealtimeMonitoring $true followed by Add-MpPreference -ExclusionPath 'C:'
- netsh trace start capture=yes executed from cmd.exe with output redirected to ADMIN$ share
False Positive Assessment
Low — the combination of specific ransom note filenames, scheduled task names, registry modifications, and the C2 IP provide high-fidelity indicators. Individual indicators such as netsh trace usage or PsExec execution may generate false positives in environments with active system administration, but the full attack chain involving BYOVD, Defender disabling, and mass file encryption is unlikely to occur in legitimate operations.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking IP 81.177.215.15 at network firewalls and proxy gateways if it is not present in your allowlists.
- Consider adding the listed vulnerable driver MD5 hashes to your EDR blocklist or Windows Defender driver block rules if your tooling supports driver hash-based blocking.
- If your EDR supports host isolation, consider preparing isolation procedures for endpoints exhibiting scheduled task creation named 'UpdateUser' or 'TaskSystem' combined with Windows Defender registry modifications.
- Consider searching endpoint telemetry for the presence of sihost.exe with MD5 554E699C96B332468F1AE69C1AE81EF9 or any listed ransomware binary hashes. Verify findings with your IR team before taking containment action.
Infrastructure Hardening
- Evaluate whether internet-exposed VPNs and firewalls are running current firmware versions. Consider implementing network-level MFA for all remote access devices.
- Consider monitoring SYSVOL and NETLOGON shares on domain controllers for unauthorized file creation, particularly .ps1 and .xml files, if your tooling provides file integrity monitoring on these paths.
- Evaluate whether Windows Defender tamper protection is enabled across all endpoints, which would prevent registry-based disabling of real-time protection features.
- Consider implementing Microsoft's vulnerable driver blocklist if not already deployed, to mitigate BYOVD attacks across the fleet.
- If supported by your environment, consider restricting PsExec execution and SMB admin share access (ADMIN$, C$) to specific administrative accounts and workstations.
User Protection
- Consider enforcing MFA on all remote access points including VPNs, RDP, and web-based administration portals, particularly for accounts with elevated privileges.
- Evaluate whether endpoint detection tools are configured to alert on Windows Defender exclusion path additions, especially broad exclusions like 'C:'.
- Consider verifying that Hyper-V VMs have backup copies stored on separate infrastructure that would not be affected by host-level encryption.
- If applicable, consider deploying application control (e.g., WDAC, AppLocker) to restrict execution of unsigned binaries from %temp% and user-writable directories.
Security Awareness
- Consider incorporating awareness training on credential hygiene, emphasizing the risk of reused or weak passwords on internet-exposed services.
- If your organization uses Tox Messenger or similar encrypted communication tools, consider awareness training for IT staff on how ransomware groups abuse these platforms for victim communication.
- Consider briefing IT operations teams on the indicators of GPO-based ransomware deployment so they can recognize suspicious Group Policy changes during incident response.
MITRE ATT&CK Mapping
Initial Access
Execution
Persistence
Defense Impairment
Credential Access
Discovery
Lateral Movement
Command and Control
Additional IOCs
- File Hashes:
3B46A729DB7AE6AF8B19711C9452194D(MD5) - Go ransomware binary: locker_eryoo5_windows_amd6402944C8A5535CDB5B2CBB893DB2D5ACF(MD5) - Go ransomware binary: locker_lqy8xb_windows_amd64.exe10CA9A4040001560D053B7E7885C1B95(MD5) - Go ransomware binary: locker_28f3cl_windows_386.exe3C471EBC947CDF32240A90FFADF49B13(MD5) - Go ransomware binary: locker_aga19g_windows_amd64.exe4BE8BB62F0EBBCF4CE52C35AB6F794F5(MD5) - Go ransomware binary: locker_wh54td_windows_386.exe53C616677BC7E2A0A03127F19166D007(MD5) - Go ransomware binary: locker_p663zs_windows_amd64.exe5F0B2C6D9F442754258BF4DD841C8341(MD5) - Go ransomware binary: locker_t1zged_windows_amd64.exe608FAF58353B65C45EF9833358AC3787(MD5) - Go ransomware binary: locker_u90lyt_windows_amd64.exe846DC77C1246DB20D976346E0E359502(MD5) - Go ransomware binary: locker_p663zs_windows_386.exeADAC9984B3CC43D66A0D33079BBEC299(MD5) - Go ransomware binary: UcAaJ_o_1j9srso9a14071ps4p7s3f81s1bAE0E536766788478263BF448A9381641(MD5) - Go ransomware binary: cosmo.exeB3E418D30312C1B2C58A791286868F42(MD5) - Go ransomware binary: system_386.exeC2764744DCB4B0E1DB79CA1E8BF65368(MD5) - Go ransomware binary: getlwd.exeD12A5B36DD00586CC374A1CAE43EFED4(MD5) - Go ransomware binary: locker_c65ffp_windows_amd64.exeD2F72897E8986303D5567EB2384932B8(MD5) - Go ransomware binary: UcAaJ_o_1j9srso9a14071ps4p7s3f81s1b (duplicate filename, different hash)DE1522F9219497632F30F8A6E72F26B6(MD5) - Go ransomware binary: locker_c7ekh7_windows_amd64.exeFDAE2BEB813778B4540A997706862096(MD5) - Go ransomware binary: AIR.exe5761BD63DA03686FC480245DA7BD1E9F(MD5) - Vulnerable driver: processmonitordriver.sys (Safetica DLP and EDR driver) used in BYOVD attacksB6B51508AD6F462C45FE102C85D246C8(MD5) - Vulnerable driver: wamsdk.sys (WatchDog anti-malware driver) used in BYOVD attacks8F0577D28C4FF5F71B149F444BFABA8E(MD5) - Vulnerable driver: gamedriverx64.sys (Fedeen/Hotta studio anti-cheat driver) used in BYOVD attacks525EF6014F0EF20E44FE47C1D9980B69(MD5) - Vulnerable driver: biontdrv_wink.sys (Paragon partition manager driver) used in BYOVD attacks407B6A136BBAA7172EB44EF9D08BB58A(MD5) - Vulnerable driver: biontdrv_winbs.sys (Paragon partition manager driver) used in BYOVD attacks9321A61A25C7961D9F36852ECAA86F55(MD5) - Vulnerable driver: inpoutx64.sys (legacy RGB lighting driver) used in BYOVD attacks73F0A8C3EA794A04E80C32038249F044(MD5) - Vulnerable driver: wsddprm.sys (Topaz anti-fraud software driver) used in BYOVD attacksEEF8A950952696B018AA9C6DA2F5D7AD(MD5) - Vulnerable driver: havoc.sys (Huawei audio driver) used in BYOVD attacksEDB1C480295250DD1A38F3AA1357DEAE(MD5) - Scanning tool: netscan64.exe used for network reconnaissance5537C708EDB9A2C21F88E34E8A0F1744(MD5) - Scanning tool: Advanced_IP_Scanner_2.5.4594.1.exe used for network reconnaissance
- Registry Keys:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection- Registry subkey where DisableBehaviorMonitoring, DisableOnAccessProtection, and DisableScanOnRealtimeEnable are set to 1 to disable Windows Defender real-time protection.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run- Registry Run key where the ransomware adds a value named 'GupdateS' pointing to the ransomware path for persistence on startup.
- File Paths:
\\Netlogon\- Network share where the ransomware copies itself for distribution to all domain computers via GPO deployment.C:\Windows\sysvol\domain\scripts\- SYSVOL directory path where the malicious ScheduledTasks.xml is placed for GPO-based ransomware deployment.C:\Temp- Directory where PsExec.exe is downloaded when the --spread parameter is used and PsExec is absent on the target system.
- Command Lines:
- Purpose: Capture network traffic for reconnaissance using netsh trace, saving to a remote admin share with a random filename | Tools:
cmd.exe,netsh| Stage: Reconnaissance |cmd.exe /Q /c netsh trace start capture=yes - Purpose: Disable Windows Defender real-time monitoring and controlled folder access, and add exclusions | Tools:
powershell.exe| Stage: Defense Evasion |Set-MpPreference -DisableRealtimeMonitoring $true -Force - Purpose: Create a scheduled task named 'UpdateUser' to run the ransomware on system startup for persistence | Tools:
schtasks.exe| Stage: Persistence |schtasks.exe /Create /SC ONSTART /TN "UpdateUser" /TR - Purpose: Add a registry Run key value named 'GupdateS' for ransomware persistence on startup | Tools:
reg.exe| Stage: Persistence |reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GupdateS" - Purpose: Delete volume shadow copies to inhibit system recovery | Tools:
vssadmin.exe| Stage: Impact |vssadmin.exe delete shadows /all /quiet - Purpose: Clear Windows event logs to cover tracks | Tools:
wevtutil.exe| Stage: Defense Evasion |wevtutil.exe cl System - Purpose: Modify file ACL to grant full control to Everyone before encryption | Tools:
takeown.exe,icacls.exe| Stage: Impact |icacls.exe <target_file> /grant *S-1-1-0:F - Purpose: Create a scheduled task named 'TaskSystem' to execute with SYSTEM privileges in the C-based ransomware variant | Tools:
schtasks.exe| Stage: Privilege Escalation |schtasks /create /sc DAILY /tn "TaskSystem" /tr - Purpose: Stop Hyper-V virtual machines before encrypting virtual disk files | Tools:
powershell.exe| Stage: Impact |Get-VM | Stop-VM -Force -TurnOff - Purpose: Download PsExec.exe from Sysinternals when not present on target system for lateral movement | Tools:
powershell.exe| Stage: Lateral Movement |powershell.exe -Command "Invoke-WebRequest -Uri
- Purpose: Capture network traffic for reconnaissance using netsh trace, saving to a remote admin share with a random filename | Tools:
- Other:
CbdU8EgF- Hardcoded password required by the Go ransomware variant to execute. Acts as an anti-sandbox/anti-analysis mechanism. The binary terminates if the password is incorrect or absent.HvzC6Dq/siFthWSgE5ozZyQDu9cyxIoxb3NuRHI6pDM=- Base64-encoded Curve25519 attacker public key embedded in the Go ransomware binary. Used to compute a shared secret for file encryption.UpdateUser- Scheduled task name created by the Go ransomware variant for persistence, configured to run on startup.TaskSystem- Scheduled task name created by the C-based ransomware variant to execute with SYSTEM privileges, configured as a daily task at 20:00.GupdateS- Registry value name added to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run by the Go ransomware for startup persistence.