The Gentlemen ransom note sample
At a glance
| Malware family | The Gentlemen ransomware (Go-based locker; Windows, Linux, ESXi builds) |
| Threat actor | GOLD SHERWOOD (confirmed by Sophos CTU) |
| Targets | Organizations across many sectors, worldwide; opportunistic victim selection |
| Delivery vector | Stolen VPN credentials and exposed firewall interfaces |
| Key capabilities | Rapid privilege escalation, BYOVD EDR killing, backup tampering, data theft |
| Source | Sophos Counter Threat Unit |
TL;DR
The Gentlemen ransomware runs as a ransomware-as-a-service scheme under GOLD SHERWOOD. Affiliates steal data, disable defenses, and encrypt fast. In some cases, they finish the job in under 24 hours.
Why this operation matters
The Gentlemen ransomware grew quickly through 2026. Fewer than 20 victims appeared each month in late 2025. That average rose above 75 by early 2026. July alone added 169 names, making it the busiest leak site that month.
Sophos summarizes the threat plainly. The intrusions “demonstrate a repeatable affiliate playbook that combines opportunistic initial access, rapid privilege escalation, legitimate remote access mechanisms, tool staging in trusted system paths, targeted data exfiltration, aggressive defense evasion, backup disruption, and ransomware deployment.”
How affiliates get in
Initial access usually starts at the network edge. Affiliates abuse stolen VPN credentials and exposed firewall management interfaces. In one February incident, an attacker logged into a Fortinet SSL VPN with valid credentials. The account lacked MFA, so the login succeeded. Third-party reports also tie the group to a FortiGate flaw, CVE-2024-55591.
Lateral movement
Once inside, the attacker spread through Remote Desktop Protocol. They reused valid domain credentials to reach file servers and domain controllers. Repeated VPN logins kept access alive.
The infection chain
The affiliates stage their tools in trusted system folders. The C:\PerfLogs directory is a favorite hiding spot. That folder holds performance logs and rarely draws scrutiny. Staged files include scanners, exfiltration tools, and EDR killers.
Next, the actors map the network with Advanced IP Scanner and SoftPerfect Network Scanner. They harvest credentials with tools like Mimikatz. For privilege escalation, they add rogue accounts to admin groups and reset high-value passwords. In one case, the attacker changed two admin passwords to lock out defenders.
Persistence
The group keeps several ways back in. In one intrusion, an attacker installed a Cloudflared tunnel as a Windows service. This gave a covert channel separate from the VPN. In other cases, they re-enabled RDP through registry and firewall changes.
Data theft and C2 behavior
The Gentlemen ransomware follows a double-extortion model. Affiliates steal data first, then encrypt. Rclone was the preferred exfiltration tool, seen in five incidents. The attackers also used Restic and MinIO Client when conditions changed.
Sophos describes an adaptive approach rather than a fixed script. In one intrusion, the attacker started with Rclone, switched to Restic 25 minutes later, then moved to MinIO Client. They filtered files by age to cut volume and stay quiet. Data went to attacker-controlled cloud storage named after each victim.
How they disable defenses
Defense evasion sits at the core of the operation. Affiliates use a custom EDR-killer suite that ESET named GentleKiller. It abuses vulnerable drivers through the Bring Your Own Vulnerable Driver method. ESET found at least eight variants targeting more than 400 processes across 48 security products.
The attackers also weaken Microsoft Defender. Some add PowerShell scan exclusions. Others flip a registry policy to disable real-time protection. Before encryption, they disable backup services such as Veeam, SQL Writer, and Backup Exec. CTU saw over 200 variations of these service commands.
Execution and impact
GOLD SHERWOOD gives affiliates a custom Go-based locker. CTU mostly saw the Windows variant deployed. Ransom notes named README-GENTLEMEN.txt land in every affected folder. The median dwell time was about two days, and the fastest run took under 24 hours.
Defense and detection guidance
Start with MFA on every VPN and remote access service. Patch internet-facing firewalls and VPN appliances promptly. Watch for unusual execution from C:\PerfLogs and similar staging paths. Alert on new admin group members and reset high-value passwords carefully.
Also monitor for exfiltration tools like Rclone, Restic, FileZilla, and MinIO Client. Protect backup platforms from service changes. Finally, investigate log clearing, Defender exclusions, and driver-based tampering. These steps break the playbook before encryption starts.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!