The Gentlemen Ransomware Dissection

The Gentlemen Ransomware Dissection


Ransomware attacks are no longer limited to encrypting files and demanding payment. Modern operations combine data theft, security-tool disruption and network-wide propagation to increase pressure on victims.

The Gentlemen is one such ransomware-as-a-service (RaaS) operation. Microsoft tracks its operators as Storm-2697 and published a technical analysis of its ransomware in May 2026. ESET subsequently documented the group’s collection of tools designed to disable endpoint detection and response (EDR) products.

How The Gentlemen Works

The operation follows a double-extortion model. Attackers can steal sensitive information and encrypt systems, threatening to publish the stolen data if the victim refuses to pay.

Microsoft’s analysis describes a Go-based Windows encryptor that uses Garble obfuscation, Curve25519 key exchange and the XChaCha20 encryption algorithm. It also supports self-propagation, allowing it to attempt to spread to other systems using available credentials and authentication tokens.

This capability makes network segmentation and privileged-account security particularly important. A compromised endpoint can become the starting point for a much larger incident if attackers gain access to other machines.

Disabling security controls

ESET’s investigation, published in June 2026, identified a collection of EDR-disabling tools maintained by the Gentlemen operators. This includes an internally developed framework called GentleKiller, alongside tools obtained from external sources.

The purpose is straightforward: interfere with security products that could detect or stop the attack. For defenders, unexpected security-service termination, suspicious driver loading and unexplained gaps in endpoint telemetry deserve immediate investigation.

Why recovery can be difficult

File encryption is only one part of the incident. Stolen data can create legal, regulatory and reputational consequences even when an organization has reliable backups.

Organizations should therefore investigate potential data exfiltration, preserve forensic evidence and verify that the original access path has been closed before restoring affected systems.

Known Victims and Reported Incidents

Victim numbers vary between threat-intelligence providers because some count every leak-site claim, while others include only incidents supported by independent reporting.

OrganizationCountrySector
Nishiyama Seisakusho Co., Ltd.JapanManufacturing
Omikenshi Co., Ltd.JapanManufacturing
Oriental Diamond Co., Ltd.JapanManufacturing
Koa Glass Co., Ltd.JapanGlass Manufacturing
HAFAFranceManufacturing
Wamtechnik sp. z o.o.PolandBattery Manufacturing
Heinrich Kopp GmbHGermanyElectrical Equipment
Gem Terminal Industry Co., Ltd.TaiwanManufacturing
Arçelik A.Ş.TürkiyeHome Appliances
Gator Cases, LLCUnited StatesManufacturing
IP Rings LimitedIndiaAutomotive Components
Indra Group subsidiarySpainTechnology and Defence
TKMS ATLAS North America, LLCUnited StatesDefence Technology
HIWIN S.r.l.ItalyIndustrial Automation

Note: This is a selected list of victims identified in public reporting, not a complete victim inventory. The inclusion of an organization does not establish that every allegation made by the ransomware operators is accurate.

Source: Comparitech — The Gentlemen ransomware victim reporting.

What Organizations Should Do

Organizations should focus on preventing the attacker from moving beyond the initial compromise.

  • Enforce multifactor authentication and restrict privileged access.
  • Patch internet-facing systems and investigate suspicious remote access.
  • Monitor for EDR tampering, unusual driver loading and unexpected administrative activity.
  • Detect abnormal file changes and large outbound data transfers.
  • Maintain isolated, immutable backups and test restoration regularly.
  • Preserve evidence and investigate possible data theft during incident response.

The Gentlemen Ransomware — IOC List

1. File Hashes (SHA-256)

  • 22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67 — Ransomware encryptor
  • 078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b — PsExec binary
  • fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68 — Ransomware wallpaper bitmap
  • f918535f974591ef031bd0f30a8171e3da27a6754e6426a8ba095f83195661c8 — Encryptor observed by Huntress

2. Network Indicators (IPv4)

  • 193.233.202[.]17 — Reported command-and-control infrastructure
  • 77.110.122[.]137 — Reported command-and-control infrastructure

3. File and Host Indicators

  • README-GENTLEMEN.txt — Ransom note filename
  • G_hlm7jj_windows_amd64.exe — Reported encryptor filename
  • WIN-8OA3CCQAE4D — Hostname reported in an incident
  • Ransom:Win64/Gentlemen — Microsoft Defender detection name
  • Ransom:Win64/Gentlemen.SH!MTB — Microsoft Defender detection name

4. Behavioral Indicators

  • Widespread file encryption and modification
  • Ransom-note creation across directories
  • Attempts to delete Volume Shadow Copies
  • Unexpected Microsoft Defender exclusions or configuration changes
  • Suspicious driver loading and EDR disruption
  • Unusual PsExec activity and remote execution across endpoints
  • Abnormal outbound data transfers indicating possible exfiltration

Important: Validate indicators against the original vendor reports before deploying detection or blocking rules. Hashes and infrastructure are sample-specific and may change.

Conclusion

The Gentlemen demonstrates how ransomware operations combine encryption, lateral movement and security-tool disruption to increase the impact of an intrusion.

Its technical capabilities make early detection and containment essential. Organizations should not wait for ransom notes or widespread encryption before responding to suspicious activity.

The most effective defence is to prevent initial access where possible, limit the attacker’s ability to move through the network and ensure that recovery remains possible even if production systems are compromised.

1 Comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.