
Ransomware attacks are no longer limited to encrypting files and demanding payment. Modern operations combine data theft, security-tool disruption and network-wide propagation to increase pressure on victims.
The Gentlemen is one such ransomware-as-a-service (RaaS) operation. Microsoft tracks its operators as Storm-2697 and published a technical analysis of its ransomware in May 2026. ESET subsequently documented the group’s collection of tools designed to disable endpoint detection and response (EDR) products.
How The Gentlemen Works
The operation follows a double-extortion model. Attackers can steal sensitive information and encrypt systems, threatening to publish the stolen data if the victim refuses to pay.
Microsoft’s analysis describes a Go-based Windows encryptor that uses Garble obfuscation, Curve25519 key exchange and the XChaCha20 encryption algorithm. It also supports self-propagation, allowing it to attempt to spread to other systems using available credentials and authentication tokens.
This capability makes network segmentation and privileged-account security particularly important. A compromised endpoint can become the starting point for a much larger incident if attackers gain access to other machines.
Disabling security controls
ESET’s investigation, published in June 2026, identified a collection of EDR-disabling tools maintained by the Gentlemen operators. This includes an internally developed framework called GentleKiller, alongside tools obtained from external sources.
The purpose is straightforward: interfere with security products that could detect or stop the attack. For defenders, unexpected security-service termination, suspicious driver loading and unexplained gaps in endpoint telemetry deserve immediate investigation.
Why recovery can be difficult
File encryption is only one part of the incident. Stolen data can create legal, regulatory and reputational consequences even when an organization has reliable backups.
Organizations should therefore investigate potential data exfiltration, preserve forensic evidence and verify that the original access path has been closed before restoring affected systems.
Known Victims and Reported Incidents
Victim numbers vary between threat-intelligence providers because some count every leak-site claim, while others include only incidents supported by independent reporting.
| Organization | Country | Sector |
|---|---|---|
| Nishiyama Seisakusho Co., Ltd. | Japan | Manufacturing |
| Omikenshi Co., Ltd. | Japan | Manufacturing |
| Oriental Diamond Co., Ltd. | Japan | Manufacturing |
| Koa Glass Co., Ltd. | Japan | Glass Manufacturing |
| HAFA | France | Manufacturing |
| Wamtechnik sp. z o.o. | Poland | Battery Manufacturing |
| Heinrich Kopp GmbH | Germany | Electrical Equipment |
| Gem Terminal Industry Co., Ltd. | Taiwan | Manufacturing |
| Arçelik A.Ş. | Türkiye | Home Appliances |
| Gator Cases, LLC | United States | Manufacturing |
| IP Rings Limited | India | Automotive Components |
| Indra Group subsidiary | Spain | Technology and Defence |
| TKMS ATLAS North America, LLC | United States | Defence Technology |
| HIWIN S.r.l. | Italy | Industrial Automation |
Note: This is a selected list of victims identified in public reporting, not a complete victim inventory. The inclusion of an organization does not establish that every allegation made by the ransomware operators is accurate.
Source: Comparitech — The Gentlemen ransomware victim reporting.
What Organizations Should Do
Organizations should focus on preventing the attacker from moving beyond the initial compromise.
- Enforce multifactor authentication and restrict privileged access.
- Patch internet-facing systems and investigate suspicious remote access.
- Monitor for EDR tampering, unusual driver loading and unexpected administrative activity.
- Detect abnormal file changes and large outbound data transfers.
- Maintain isolated, immutable backups and test restoration regularly.
- Preserve evidence and investigate possible data theft during incident response.
The Gentlemen Ransomware — IOC List
1. File Hashes (SHA-256)
22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67— Ransomware encryptor078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b— PsExec binaryfe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68— Ransomware wallpaper bitmapf918535f974591ef031bd0f30a8171e3da27a6754e6426a8ba095f83195661c8— Encryptor observed by Huntress
2. Network Indicators (IPv4)
193.233.202[.]17— Reported command-and-control infrastructure77.110.122[.]137— Reported command-and-control infrastructure
3. File and Host Indicators
README-GENTLEMEN.txt— Ransom note filenameG_hlm7jj_windows_amd64.exe— Reported encryptor filenameWIN-8OA3CCQAE4D— Hostname reported in an incidentRansom:Win64/Gentlemen— Microsoft Defender detection nameRansom:Win64/Gentlemen.SH!MTB— Microsoft Defender detection name
4. Behavioral Indicators
- Widespread file encryption and modification
- Ransom-note creation across directories
- Attempts to delete Volume Shadow Copies
- Unexpected Microsoft Defender exclusions or configuration changes
- Suspicious driver loading and EDR disruption
- Unusual PsExec activity and remote execution across endpoints
- Abnormal outbound data transfers indicating possible exfiltration
Important: Validate indicators against the original vendor reports before deploying detection or blocking rules. Hashes and infrastructure are sample-specific and may change.
Conclusion
The Gentlemen demonstrates how ransomware operations combine encryption, lateral movement and security-tool disruption to increase the impact of an intrusion.
Its technical capabilities make early detection and containment essential. Organizations should not wait for ransom notes or widespread encryption before responding to suspicious activity.
The most effective defence is to prevent initial access where possible, limit the attacker’s ability to move through the network and ensure that recovery remains possible even if production systems are compromised.



Very nice.