GOLD SHERWOOD operates The Gentlemen ransomware-as-a-service scheme using a repeatable post-exploitation playbook. Affiliates gain initial access by exploiting FortiGate firewall vulnerabilities or abusing stolen VPN credentials, then rapidly escalate privileges, deploy BYOVD-based EDR killers, exfiltrate data via cloud storage tools, and deploy Go-based ransomware binaries. Median dwell time is approximately two days, with some intrusions completing in under 24 hours. The attackers stage tools in C:\PerfLogs, use native Windows utilities for privilege escalation, and adaptively switch between Rclone, Restic, and MinIO Client for data exfiltration.
CVE-2024-55591
5 posts
Ungentlemanly behavior: Insights into a ransomware operation #StopRansomware: Gunra Ransomware (CVE-2024-55591, CVE-2025-24472) Gunra is a Conti-derived ransomware-as-a-service that employs double extortion, encrypting victim data with ChaCha20 + RSA-4096 and threatening to publish exfiltrated data on a Tor-based leak site. The actors gain initial access primarily by exploiting authentication bypass vulnerabilities (CVE-2024-55591, CVE-2025-24472) in FortiOS and FortiProxy devices, then use Impacket libraries, Mimikatz, and credential dumping for lateral movement and privilege escalation. The ransomware targets both Windows and Linux environments, with the Linux variant containing a weak PRNG flaw that may allow file recovery without paying ransom.
Cyber Centre Daily Advisory Digest — 2026-06-18 (1 advisories) The Canadian Centre for Cyber Security issued an alert regarding 'FortiBleed,' a widespread campaign involving the leak of thousands of compromised credentials for Fortinet firewalls and VPN gateways. Threat actors can leverage these credentials, alongside vulnerabilities like CVE-2024-55591, CVE-2025-59718, and CVE-2025-59719, to gain remote access, create unauthorized accounts, and modify critical security controls.
Thus Spoke…The Gentlemen A recent leak of internal communications and backend data from 'The Gentlemen' RaaS operation has revealed the group's highly structured operational model and mature toolset. The threat actors actively exploit edge appliances and NTLM relay vulnerabilities for initial access, followed by extensive use of red-team tools and custom EDR evasion techniques to deploy their cross-platform ransomware.
The State of Ransomware – Q1 2026 In Q1 2026, the ransomware ecosystem experienced significant consolidation, with top groups like Qilin, Akira, The Gentlemen, and LockBit 5.0 dominating the landscape. Notably, The Gentlemen leveraged a massive stockpile of pre-exploited FortiGate devices (CVE-2024-55591) to rapidly scale operations, while LockBit 5.0 returned with multi-platform capabilities and a strategic shift away from US targets to evade law enforcement.