Ungentlemanly behavior: Insights into a ransomware operation
GOLD SHERWOOD operates The Gentlemen ransomware-as-a-service scheme using a repeatable post-exploitation playbook. Affiliates gain initial access by exploiting FortiGate firewall vulnerabilities or abusing stolen VPN credentials, then rapidly escalate privileges, deploy BYOVD-based EDR killers, exfiltrate data via cloud storage tools, and deploy Go-based ransomware binaries. Median dwell time is approximately two days, with some intrusions completing in under 24 hours. The attackers stage tools in C:\PerfLogs, use native Windows utilities for privilege escalation, and adaptively switch between Rclone, Restic, and MinIO Client for data exfiltration.
- cveCVE-2024-55591Vulnerability in FortiGate firewall management interfaces exploited by The Gentlemen affiliates for initial access to victim environments.
- filenameC:\PerfLogsLegitimate Windows performance monitoring directory used by attackers to stage EDR killers, exfiltration tools, and discovery utilities.
- filenameC:\Users\<username>\Documents\AVAST2\Staging directory observed as an alternative location for ransomware binary execution.
- md5002417da707b93bf5ce3cb26d28005f6MD5 hash of g111.exe EDR killer (GentleKiller G11 variant).
- md507e9f0b8627a95960e79e930fb099e84MD5 hash of G11.sys vulnerable driver loaded by GentleKiller G11 variant.
- md54741a4976c6abfb3c80c170104518b6eMD5 hash of second acronis.exe EDR killer variant (Havoc).
- md5622b2ca08552535bc142cb815ff9ec16MD5 hash of acronis.exe EDR killer (Havoc variant).
- md5738df7ae0097f6bef93d65be5d4a2a26MD5 hash of acronis.exe and hwaudkiller.exe EDR killer (Havoc variant).
- md58ea97d01cbf459b94d134d05c54cd33eMD5 hash of nogbc.sys vulnerable driver loaded by EDR killers.
- md5b23b653541bd95bdc4da07a0b07b57bfMD5 hash of sophos.exe EDR killer (Havoc variant).
- md5bc4a8d7bbbeb941265dfc954539326c0MD5 hash of eaanticheat2.exe EDR killer (GentleKiller Javelin variant).
- md5d8691ef15eea27cfefafeeb485286080MD5 hash of y7D0.exe EDR killer (GentleKiller Watchdog variant).
- registry_keyHKLM\SOFTWARE\Policies\Microsoft\WindowsDefender\Real-TimeProtectionRegistry key modified to disable Windows Defender real-time monitoring by setting DisableRealtimeMonitoring to 1.
- registry_keyHKLM\System\CurrentControlSet\Control\TerminalServerRegistry key modified to enable RDP by setting fDenyTSConnections to 0 for persistent remote access.
- sha1058c3ff21e79770e4a60937c27b1ede227709248SHA1 hash of EASOLO1.exe EDR killer (GentleKiller Javelin variant).
- sha156bee9df5833a637f5c54d5911df98b0812fe643SHA1 hash of G11.sys vulnerable driver loaded by GentleKiller G11 variant.
- sha15c9bf6b7e4c7dc9b9227ce86e2d271d624c35147SHA1 hash of nogbc.sys vulnerable driver loaded by EDR killers.
- sha18732c1ff565828a0bdef514b5dc0dfea40c1d1f2SHA1 hash of g111.exe EDR killer (GentleKiller G11 variant).
- sha18bca55b3c9bfbdf68c9b6c72a7b1bf1dd6d5e3b2SHA1 hash of y7D0.exe EDR killer (GentleKiller Watchdog variant).
- sha19c0b05eb75f971cc25ee979e49b227b86b19e833SHA1 hash of EASolo1Light.exe EDR killer (GentleKiller Javelin variant).
- sha1a438ba2122a814320f47a056f04122f81c2ae6c5SHA1 hash of EASOLO2.exe EDR killer (GentleKiller Javelin variant).
- sha1a8ba89e67297642dcc1ae77433ab84e1f27d1792SHA1 hash of EASOLO2clear.exe EDR killer (GentleKiller Javelin variant).
- sha1b7cea81e6de895d01d01d20bd6dcfd347940b57fSHA1 hash of eaanticheat2.exe EDR killer (GentleKiller Javelin variant).
- sha1be8c52474ab79a52af31e3cb2f71638299a0de1dSHA1 hash of second acronis.exe EDR killer variant (Havoc).
- sha1c96baab9b7e7ef661921d44d7900f165c794ed25SHA1 hash of acronis.exe and hwaudkiller.exe EDR killer (Havoc variant).
- sha1f0537cbb773ae12100b36731e7c39f5a9d852b14SHA1 hash of sophos.exe EDR killer (Havoc variant).
- sha1f0bc50d2d2838c5294e21cd9bce2f09bf581e508SHA1 hash of acronis.exe EDR killer (Havoc variant).
- sha2560be8f415a485b11747bcfd71c9cd9781e090354728f076791ed6845b69ed78fbSHA256 hash of nogbc.sys, a vulnerable signed driver loaded by EDR killers to terminate security processes at the kernel level.
- sha2561a9291ec869155336bf185d221d655d11c77a55ea0c8ecc0274202f74a90fcd1SHA256 hash of acronis.exe and hwaudkiller.exe EDR killer (Havoc variant).
- sha2562d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145dSHA256 hash of G11.sys, a vulnerable signed driver used by the GentleKiller G11 variant for kernel-level process termination.
- sha2563a31ec3bf9b7eac6593a723145381f5d0f4ede076c4c8818d949a08f5596ff76SHA256 hash of eaanticheat2.exe, a GentleKiller Javelin-variant EDR killer observed in six incidents.
- sha2563c71537b64487bbf4d1793f72c75d332650d09a77b71e4d884ff15c266a847f6SHA256 hash of y7D0.exe, a GentleKiller Watchdog-variant EDR killer used to disable endpoint security solutions.
- sha25650f2cdf16f05da9253fa2d6eb60d5a42da14c02c551c0874c9e953d4119da69cSHA256 hash of sophos.exe, a Havoc-variant EDR killer targeting Sophos EDR endpoint processes.
- sha25668031d549de399a44bb00614b910106baccef5996623b2f1102352a52a5bb444SHA256 hash of EAAntiCheatClear.exe EDR killer (GentleKiller Javelin variant).
- sha256761ce72420edf5e5531cdbad0e93397d7520cdead825886ca7f75cef76031720SHA256 hash of sophos3.exe EDR killer (Havoc variant).
- sha2567a37acb031cddaa39ad20db0961baa5423ec53f318c49c9275c982507da76d6aSHA256 hash of FaceITClear.exe, a GentleKiller FACEIT Anti-Cheat variant EDR killer.
- sha25681053c2c3be8b7dbf7d5087dba05c940b3ee4fd95524272651c816b72c5a9443SHA256 hash of g111.exe, a GentleKiller G11-variant EDR killer used in The Gentlemen ransomware operations.
- sha256a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c0efdSHA256 hash of acronis.exe, a Havoc-variant EDR killer used in The Gentlemen ransomware compromises to terminate security processes via BYOVD.
- sha256bf7a2fb7f7256809dc690213b85f747cef8db7b909caf9783cac181912fb6207SHA256 hash of sophos2.exe EDR killer (Havoc variant).
- sha256ccdde8091d63eaafbe30d9f0482afd245abc10ab16e21ae9254e51e42cb80ae8SHA256 hash of dmx.sys, a vulnerable signed driver abused by EDR killers in The Gentlemen ransomware operations.
- sha256ddba5b4e7a7ada77d56477e9d41c008f93e81d9a33ed09e77cb2af624fa694feSHA256 hash of second acronis.exe EDR killer variant (Havoc).
- urlhxxp://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad[.]onion/The Gentlemen ransomware leak site on the dark web where victim names are published as part of the double-extortion model.
Detection / Hunteropenrouter
What Happened
A criminal group called GOLD SHERWOOD runs a ransomware service known as The Gentlemen. They break into organizations by exploiting firewall vulnerabilities or using stolen login credentials for remote access services. Once inside, they move quickly to take control of more systems, steal data, disable security software, and encrypt files. In some cases, this entire process takes less than 24 hours. The attackers hide their tools in standard Windows folders that security teams do not usually monitor. They also disable backup systems to prevent recovery. Organizations should require multi-factor authentication for remote access, patch internet-facing devices, monitor for unusual tool usage, and protect backup systems from tampering.
Key Takeaways
- GOLD SHERWOOD operates The Gentlemen RaaS with a consistent post-exploitation playbook enabling ransomware deployment within 24 hours of initial access in some cases.
- Initial access is achieved by exploiting FortiGate firewall vulnerabilities (CVE-2024-55591) or abusing stolen VPN credentials where MFA is absent.
- Affiliates deploy custom BYOVD-based EDR killers (GentleKiller variants, Xkpsm-Killer) alongside PowerShell-based Windows Defender exclusions to disable security tooling.
- Tools are staged in C:\PerfLogs, a legitimate Windows directory not commonly scrutinized by security controls.
- Data exfiltration is adaptive, with attackers switching between Rclone, Restic, and MinIO Client based on environmental constraints.
Affected Systems
- Fortinet FortiGate firewalls (CVE-2024-55591)
- Fortinet SSL VPN services
- Windows systems (all versions targeted by ransomware variant)
- ESXi environments (ransomware variant available but not observed deployed)
- Linux systems (ransomware variant available)
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2024-55591 | Fortinet FortiGate firewalls | Vulnerability in FortiGate firewall management interfaces exploited by The Gentlemen affiliates for initial access to victim environments. |
Attack Chain
- Initial Access: Exploit FortiGate firewall vulnerability (CVE-2024-55591) or use stolen VPN credentials without MFA to access victim network
- Lateral Movement and Discovery: Use RDP with valid domain credentials to access file servers and domain controllers; enumerate network with Advanced IP Scanner and SoftPerfect Network Scanner
- Privilege Escalation and Persistence: Add accounts to local/domain admin groups via net commands; install Cloudflared agent as Windows service; enable RDP via registry and firewall modifications
- Defense Evasion: Deploy BYOVD-based EDR killers (GentleKiller variants, Xkpsm-Killer); disable Windows Defender via PowerShell exclusions and registry; disable backup services; clear event logs
- Exfiltration: Use Rclone, Restic, and MinIO Client to exfiltrate data to cloud storage with adaptive tool switching based on environmental constraints
- Impact: Deploy Go-based ransomware binaries via local execution, PsExec, or NETLOGON shares; encrypt files with six-character extension and drop README-GENTLEMEN.txt ransom notes
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Sophos countermeasures
The article lists Sophos-specific countermeasure detection names (e.g., ATK/KillAV-ENI, ATK/KillAV-HID, Troj/ABYSSW-B) but does not provide YARA, Sigma, Snort, Suricata, KQL, SPL, or EQL rules. No query or rule bodies are included in the article.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR solutions can detect process execution, registry modifications, and service configuration changes. However, BYOVD-based EDR killers are designed to terminate EDR processes at the kernel level, which may blind the sensor before critical activity is captured. PowerShell-based Defender exclusions and registry modifications are visible if telemetry is collected before evasion tools execute. |
| Network Visibility | Medium | VPN authentication events from foreign IP addresses are visible in VPN logs. Rclone, Restic, and MinIO Client exfiltration traffic to cloud storage providers may be visible via network flow data or proxy logs. However, Cloudflared tunnels encrypt traffic and may bypass network monitoring controls. |
| Detection Difficulty | Hard | The attackers use legitimate tools (Advanced IP Scanner, Rclone, Restic, Cloudflared) and native Windows utilities (net, reg, netsh, sc) that blend with administrative activity. BYOVD-based EDR killers can blind endpoint sensors. The combination of valid credentials, legitimate tools, and aggressive defense evasion requires behavioral detection rather than signature-based approaches. |
Required Log Sources
- Windows Event Logs (Security, System, Application)
- VPN authentication logs
- PowerShell Script Block Logging (Event ID 4104)
- Windows Sysmon (Process Creation Event ID 1, Registry Event IDs 12-14, Driver Loading Event ID 6)
- EDR telemetry (process execution, file creation, service modification)
- Network flow data or proxy logs for cloud storage exfiltration
- DNS logs for cloud storage endpoint resolution
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for processes executing from the C:\PerfLogs directory, which is an uncommon execution path for legitimate software and was used as a staging directory in multiple incidents. | Sysmon Event ID 1 (Process Creation) or EDR process telemetry filtering on Image paths containing C:\PerfLogs | Execution | Low — legitimate performance monitoring tools rarely execute binaries from this directory. |
| Consider hunting for Windows Defender exclusion modifications that add broad paths (e.g., entire drives) or exclude processes matching ransomware binary naming patterns, which would indicate defense evasion activity. | PowerShell Script Block Logging (Event ID 4104) or Windows Defender operational log for Add-MpPreference calls | Defense Evasion | Medium — administrators may legitimately add exclusions, but drive-level exclusions are rare. |
| Consider hunting for service configuration changes that disable backup-related services (e.g., VeeamBackupSvc, SQLWriter, BackupExecAgent) in rapid succession, which indicates preparation for ransomware deployment. | Windows System Event ID 7040 (Service state change) or EDR service modification telemetry | Impact | Low — disabling multiple backup services simultaneously is uncommon in normal operations. |
| Consider hunting for Rclone, Restic, or MinIO Client execution with command-line parameters indicating data exfiltration to cloud storage, especially when initiated from non-standard user contexts or staging directories. | EDR process execution telemetry with command-line capture, or network flow data to known cloud storage providers | Exfiltration | Medium — these tools have legitimate administrative uses, but execution from C:\PerfLogs or by compromised accounts is suspicious. |
| Consider hunting for driver loading events where the driver filename matches known vulnerable drivers (e.g., nogbc.sys, G11.sys, dmx.sys, xkpsm.sys) loaded from non-standard paths, which would indicate BYOVD-based EDR killing activity. | Sysmon Event ID 6 (Driver Loaded) or EDR kernel driver loading telemetry | Defense Evasion | Low — these specific driver filenames are not associated with legitimate software in most environments. |
Control Gaps
- Signature-based antivirus may not detect custom EDR killers or legitimate tools repurposed for exfiltration.
- Network controls may not detect Cloudflared tunnel traffic, which encrypts and tunnels connections through legitimate infrastructure.
- BYOVD-based EDR killers can terminate endpoint security processes at the kernel level, blinding EDR sensors before ransomware deployment.
- VPN services without MFA allow attackers to authenticate with stolen credentials without additional verification.
- Monitoring of C:\PerfLogs and similar trusted system directories is often absent, allowing attackers to stage tools undetected.
Key Behavioral Indicators
- Process execution originating from C:\PerfLogs directory
- Rapid succession of net commands adding accounts to local Administrators or Domain Admins groups
- PowerShell Add-MpPreference calls excluding entire drives or ransomware binary paths from Windows Defender
- Registry modifications to HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection setting DisableRealtimeMonitoring to 1
- Registry modifications to HKLM\System\CurrentControlSet\Control\Terminal Server setting fDenyTSConnections to 0
- netsh firewall rules opening port 3389 for inbound RDP access
- sc config commands disabling backup-related services (VeeamBackupSvc, SQLWriter, BackupExecAgent)
- Batch script execution from NETLOGON shares (e.g., avkill.bat)
- Rclone, Restic, or MinIO Client execution with cloud storage destinations and filter file parameters
- Cloudflared agent installed as a Windows service with authentication token configuration
- Driver loading of nogbc.sys, G11.sys, dmx.sys, or xkpsm.sys from non-standard paths
- Execution of binaries named with patterns matching locker_windows_amd64.exe or G_windows_amd64.exe
- Creation of README-GENTLEMEN.txt files across multiple directories
False Positive Assessment
Medium — The Gentlemen affiliates use legitimate tools (Advanced IP Scanner, Rclone, Restic, Cloudflared) and native Windows utilities (net, reg, netsh, sc) that may appear in normal administrative activity. Behavioral detections targeting execution from C:\PerfLogs, drive-level Defender exclusions, and rapid backup service disabling have lower false positive risk. Driver-based detections for specific vulnerable driver filenames have low false positive potential.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified EDR killer hashes and vulnerable driver hashes in your endpoint security platform.
- If your EDR supports it, consider enabling driver blocklist features to prevent loading of known vulnerable drivers (nogbc.sys, G11.sys, dmx.sys, xkpsm.sys).
- Consider reviewing VPN authentication logs for logins from unexpected geographic locations, especially if MFA is not enforced on VPN services.
- If applicable, consider searching for the presence of README-GENTLEMEN.txt files or binaries matching locker_windows_amd64.exe and G_windows_amd64.exe naming patterns across your environment.
Infrastructure Hardening
- Consider enforcing MFA on all VPN and remote access services to prevent authentication with stolen credentials.
- Evaluate whether internet-facing FortiGate firewalls and VPN appliances are patched against CVE-2024-55591 and other known vulnerabilities.
- Consider restricting RDP access to internal networks only and removing any firewall rules that expose port 3389 to the internet.
- Consider implementing network segmentation to limit lateral movement via RDP between workstations, file servers, and domain controllers.
- Evaluate whether backup service accounts have restricted permissions to prevent unauthorized service configuration changes via sc config.
User Protection
- Consider deploying endpoint detection rules that alert on process execution from C:\PerfLogs and similar uncommon staging directories.
- If supported by your EDR, consider alerting on PowerShell Add-MpPreference calls that add drive-level exclusions or exclude processes matching ransomware binary naming patterns.
- Consider monitoring for and alerting on registry modifications that disable Windows Defender real-time monitoring or enable RDP via Terminal Server registry keys.
- Evaluate whether your endpoint security can detect and block the loading of known vulnerable drivers associated with BYOVD attacks.
Security Awareness
- Consider incorporating training on the risks of credential reuse and the importance of MFA for remote access services.
- If applicable, consider educating IT staff on the risks of staging tools in system directories like C:\PerfLogs and the importance of monitoring these locations.
- Consider reviewing with system administrators the indicators of backup service tampering and the importance of alerting on unauthorized service configuration changes.
MITRE ATT&CK Mapping
Initial Access
Persistence
Stealth
Credential Access
Discovery
Lateral Movement
Exfiltration
Additional IOCs
- File Hashes:
622b2ca08552535bc142cb815ff9ec16(MD5) - MD5 hash of acronis.exe EDR killer (Havoc variant).f0bc50d2d2838c5294e21cd9bce2f09bf581e508(SHA1) - SHA1 hash of acronis.exe EDR killer (Havoc variant).4741a4976c6abfb3c80c170104518b6e(MD5) - MD5 hash of second acronis.exe EDR killer variant (Havoc).be8c52474ab79a52af31e3cb2f71638299a0de1d(SHA1) - SHA1 hash of second acronis.exe EDR killer variant (Havoc).ddba5b4e7a7ada77d56477e9d41c008f93e81d9a33ed09e77cb2af624fa694fe(SHA256) - SHA256 hash of second acronis.exe EDR killer variant (Havoc).738df7ae0097f6bef93d65be5d4a2a26(MD5) - MD5 hash of acronis.exe and hwaudkiller.exe EDR killer (Havoc variant).c96baab9b7e7ef661921d44d7900f165c794ed25(SHA1) - SHA1 hash of acronis.exe and hwaudkiller.exe EDR killer (Havoc variant).1a9291ec869155336bf185d221d655d11c77a55ea0c8ecc0274202f74a90fcd1(SHA256) - SHA256 hash of acronis.exe and hwaudkiller.exe EDR killer (Havoc variant).d8691ef15eea27cfefafeeb485286080(MD5) - MD5 hash of y7D0.exe EDR killer (GentleKiller Watchdog variant).8bca55b3c9bfbdf68c9b6c72a7b1bf1dd6d5e3b2(SHA1) - SHA1 hash of y7D0.exe EDR killer (GentleKiller Watchdog variant).b23b653541bd95bdc4da07a0b07b57bf(MD5) - MD5 hash of sophos.exe EDR killer (Havoc variant).f0537cbb773ae12100b36731e7c39f5a9d852b14(SHA1) - SHA1 hash of sophos.exe EDR killer (Havoc variant).bf7a2fb7f7256809dc690213b85f747cef8db7b909caf9783cac181912fb6207(SHA256) - SHA256 hash of sophos2.exe EDR killer (Havoc variant).761ce72420edf5e5531cdbad0e93397d7520cdead825886ca7f75cef76031720(SHA256) - SHA256 hash of sophos3.exe EDR killer (Havoc variant).002417da707b93bf5ce3cb26d28005f6(MD5) - MD5 hash of g111.exe EDR killer (GentleKiller G11 variant).8732c1ff565828a0bdef514b5dc0dfea40c1d1f2(SHA1) - SHA1 hash of g111.exe EDR killer (GentleKiller G11 variant).bc4a8d7bbbeb941265dfc954539326c0(MD5) - MD5 hash of eaanticheat2.exe EDR killer (GentleKiller Javelin variant).b7cea81e6de895d01d01d20bd6dcfd347940b57f(SHA1) - SHA1 hash of eaanticheat2.exe EDR killer (GentleKiller Javelin variant).68031d549de399a44bb00614b910106baccef5996623b2f1102352a52a5bb444(SHA256) - SHA256 hash of EAAntiCheatClear.exe EDR killer (GentleKiller Javelin variant).058c3ff21e79770e4a60937c27b1ede227709248(SHA1) - SHA1 hash of EASOLO1.exe EDR killer (GentleKiller Javelin variant).9c0b05eb75f971cc25ee979e49b227b86b19e833(SHA1) - SHA1 hash of EASolo1Light.exe EDR killer (GentleKiller Javelin variant).a438ba2122a814320f47a056f04122f81c2ae6c5(SHA1) - SHA1 hash of EASOLO2.exe EDR killer (GentleKiller Javelin variant).a8ba89e67297642dcc1ae77433ab84e1f27d1792(SHA1) - SHA1 hash of EASOLO2clear.exe EDR killer (GentleKiller Javelin variant).8ea97d01cbf459b94d134d05c54cd33e(MD5) - MD5 hash of nogbc.sys vulnerable driver loaded by EDR killers.5c9bf6b7e4c7dc9b9227ce86e2d271d624c35147(SHA1) - SHA1 hash of nogbc.sys vulnerable driver loaded by EDR killers.07e9f0b8627a95960e79e930fb099e84(MD5) - MD5 hash of G11.sys vulnerable driver loaded by GentleKiller G11 variant.56bee9df5833a637f5c54d5911df98b0812fe643(SHA1) - SHA1 hash of G11.sys vulnerable driver loaded by GentleKiller G11 variant.
- Registry Keys:
HKLM\System\CurrentControlSet\Control\Terminal Server- Registry key modified to enable RDP by setting fDenyTSConnections to 0 for persistent remote access.HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection- Registry key modified to disable Windows Defender real-time monitoring by setting DisableRealtimeMonitoring to 1.
- File Paths:
C:\PerfLogs- Legitimate Windows performance monitoring directory used by attackers to stage EDR killers, exfiltration tools, and discovery utilities.C:\Users\<username>\Documents\AVAST2\- Staging directory observed as an alternative location for ransomware binary execution.
- Command Lines:
- Purpose: Enumerate LSASS process identifier for credential dumping | Tools:
tasklist,findstr| Stage: Credential Access |tasklist /v /fo csv | findstr /i "lsass" - Purpose: Add attacker-controlled account to local Administrators group | Tools:
net1| Stage: Privilege Escalation |net1 localgroup administrators <account> /add - Purpose: Add account to Domain Admins group for domain-wide privilege escalation | Tools:
net| Stage: Privilege Escalation |net group "domain admins" <account> /add /domain - Purpose: Reset password for high-value administrator account | Tools:
net| Stage: Privilege Escalation |net user administrator <password> /domain - Purpose: Enable RDP at the system level via registry modification | Tools:
reg| Stage: Persistence - Purpose: Create inbound firewall rule to allow RDP access from external networks | Tools:
netsh| Stage: Persistence - Purpose: Exclude entire C: drive from Windows Defender scanning to disable real-time protection | Tools:
powershell| Stage: Defense Evasion |powershell -command "Add-MpPreference -ExclusionPath C:\ -Force" - Purpose: Exclude ransomware executable process from Windows Defender monitoring | Tools:
powershell| Stage: Defense Evasion |powershell -command "add-mppreference -exclusionprocess" <path> -force - Purpose: Disable Windows Defender real-time monitoring via registry policy | Tools:
reg| Stage: Defense Evasion - Purpose: Execute batch script from NETLOGON share to deploy vulnerable drivers across multiple hosts | Tools:
cmd.exe| Stage: Defense Evasion |cmd.exe /c "\\NETLOGON\avkill.bat" - Purpose: Disable backup and recovery services to prevent system restoration | Tools:
sc| Stage: Impact |sc config <service> start= disabled - Purpose: Exfiltrate data to cloud storage using Rclone with high-speed parallel transfers and file type filtering | Tools:
rclone| Stage: Exfiltration - Purpose: Initialize Restic backup repository for structured data staging | Tools:
restic| Stage: Exfiltration |restic init - Purpose: Perform iterative backup operations with Restic using inclusion and exclusion criteria | Tools:
restic| Stage: Exfiltration |restic backup <path> --include-file=filter.txt - Purpose: Copy data recursively to object storage using MinIO Client | Tools:
mc| Stage: Exfiltration |mc cp --recursive <source> <dest>
- Purpose: Enumerate LSASS process identifier for credential dumping | Tools:
- Other:
98C132E2B20B531BE6604397D97040C1E9EB42FCE12EDF119BCE8B4031CA5C70DAF5E65FA3C3- Tox ID used by The Gentlemen ransomware operators for ransom negotiation communications, extracted from ransom note.05809b2da1d5b1a302f48b5767fd1843d54f3c516f9ab0eb26b544ffa73340292e- Session ID used by The Gentlemen ransomware operators as an alternative contact method, extracted from ransom note.README-GENTLEMEN.txt- Ransom note filename dropped by The Gentlemen ransomware across all affected directories after encryption.decryptor.exe- Filename format used by The Gentlemen ransomware binary when distributed via NETLOGON shares.locker_<file extension string>_windows_amd64.exe- Filename pattern for Go-based The Gentlemen ransomware locker binary on Windows.G_<file extension string>_windows_amd64.exe- Alternative filename pattern for Go-based The Gentlemen ransomware locker binary on Windows.xkpsm.sys- Vulnerable driver downloaded and loaded by Xkpsm-Killer tool to target Sophos EDR endpoint processes at the kernel level.x.exe- Executable component of Xkpsm-Killer tool that leverages xkpsm.sys vulnerable driver to terminate EDR processes.