Site icon TheCyberThrone

The Gentlemen Ransomware Dissection

Advertisements

Ransomware attacks are no longer limited to encrypting files and demanding payment. Modern operations combine data theft, security-tool disruption and network-wide propagation to increase pressure on victims.

The Gentlemen is one such ransomware-as-a-service (RaaS) operation. Microsoft tracks its operators as Storm-2697 and published a technical analysis of its ransomware in May 2026. ESET subsequently documented the group’s collection of tools designed to disable endpoint detection and response (EDR) products.

How The Gentlemen Works

The operation follows a double-extortion model. Attackers can steal sensitive information and encrypt systems, threatening to publish the stolen data if the victim refuses to pay.

Microsoft’s analysis describes a Go-based Windows encryptor that uses Garble obfuscation, Curve25519 key exchange and the XChaCha20 encryption algorithm. It also supports self-propagation, allowing it to attempt to spread to other systems using available credentials and authentication tokens.

This capability makes network segmentation and privileged-account security particularly important. A compromised endpoint can become the starting point for a much larger incident if attackers gain access to other machines.

Disabling security controls

ESET’s investigation, published in June 2026, identified a collection of EDR-disabling tools maintained by the Gentlemen operators. This includes an internally developed framework called GentleKiller, alongside tools obtained from external sources.

The purpose is straightforward: interfere with security products that could detect or stop the attack. For defenders, unexpected security-service termination, suspicious driver loading and unexplained gaps in endpoint telemetry deserve immediate investigation.

Why recovery can be difficult

File encryption is only one part of the incident. Stolen data can create legal, regulatory and reputational consequences even when an organization has reliable backups.

Organizations should therefore investigate potential data exfiltration, preserve forensic evidence and verify that the original access path has been closed before restoring affected systems.

Known Victims and Reported Incidents

Victim numbers vary between threat-intelligence providers because some count every leak-site claim, while others include only incidents supported by independent reporting.

Organization Country Sector
Nishiyama Seisakusho Co., Ltd. Japan Manufacturing
Omikenshi Co., Ltd. Japan Manufacturing
Oriental Diamond Co., Ltd. Japan Manufacturing
Koa Glass Co., Ltd. Japan Glass Manufacturing
HAFA France Manufacturing
Wamtechnik sp. z o.o. Poland Battery Manufacturing
Heinrich Kopp GmbH Germany Electrical Equipment
Gem Terminal Industry Co., Ltd. Taiwan Manufacturing
Arçelik A.Ş. Türkiye Home Appliances
Gator Cases, LLC United States Manufacturing
IP Rings Limited India Automotive Components
Indra Group subsidiary Spain Technology and Defence
TKMS ATLAS North America, LLC United States Defence Technology
HIWIN S.r.l. Italy Industrial Automation

Note: This is a selected list of victims identified in public reporting, not a complete victim inventory. The inclusion of an organization does not establish that every allegation made by the ransomware operators is accurate.

Source: Comparitech — The Gentlemen ransomware victim reporting.

What Organizations Should Do

Organizations should focus on preventing the attacker from moving beyond the initial compromise.

The Gentlemen Ransomware — IOC List

1. File Hashes (SHA-256)

2. Network Indicators (IPv4)

3. File and Host Indicators

4. Behavioral Indicators

Important: Validate indicators against the original vendor reports before deploying detection or blocking rules. Hashes and infrastructure are sample-specific and may change.

Conclusion

The Gentlemen demonstrates how ransomware operations combine encryption, lateral movement and security-tool disruption to increase the impact of an intrusion.

Its technical capabilities make early detection and containment essential. Organizations should not wait for ransom notes or widespread encryption before responding to suspicious activity.

The most effective defence is to prevent initial access where possible, limit the attacker’s ability to move through the network and ensure that recovery remains possible even if production systems are compromised.

Exit mobile version