The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
The Gentlemen ransomware is a self-propagating ransomware-as-a-service (RaaS) operation that emerged in mid-2025. It uses strong per-file encryption with Curve25519 and XChaCha20 stream cipher and employs aggressive lateral movement techniques to compromise networks broadly. The malware disables defenses, deletes shadow copies and forensic artifacts, and can wipe free disk space to hinder recovery efforts. It also exfiltrates sensitive data for double extortion. The operation recruits affiliates via BreachForums and targets multiple sectors globally, including education, transportation, healthcare, and finance. No official patch or fix is available as this is malware rather than a software vulnerability. No known exploits in the wild have been reported yet.
AI Analysis
Technical Summary
The Gentlemen ransomware, tracked as Storm-2697, is a Go-based ransomware-as-a-service that combines robust encryption using Curve25519 and XChaCha20 with extensive self-propagation capabilities. It employs at least 21 lateral movement techniques such as PsExec, WMI, scheduled tasks, services, and PowerShell remoting to spread across networks. The malware disables security defenses, deletes shadow copies and forensic artifacts, and optionally wipes free disk space to prevent data recovery. It also exfiltrates sensitive information to enable double extortion. The operation transitioned to RaaS by September 2025 and recruits affiliates including penetration testers and initial access brokers via BreachForums. It impacts organizations across multiple sectors globally. There is no patch or remediation available as this is a malware threat rather than a software vulnerability.
Potential Impact
The Gentlemen ransomware can cause significant operational disruption by encrypting files with strong cryptography and preventing recovery through deletion of shadow copies and optional wiping of free disk space. The double extortion tactic increases the risk of data leakage and reputational damage. Its aggressive lateral movement techniques enable broad network compromise, increasing the scope of impact within affected organizations. The disabling of defenses and deletion of forensic artifacts complicate incident response and recovery efforts.
Mitigation Recommendations
As this is a malware threat rather than a software vulnerability, no official patch or fix is available. Organizations should focus on preventive measures such as restricting lateral movement capabilities, monitoring for unusual administrative activity, and maintaining offline backups. Incident response should prioritize containment and recovery. There is no vendor advisory indicating no action required or existing mitigation. Patch status is not applicable.
Indicators of Compromise
- hash: 22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67
- hash: fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68
- hash: 7a262d4cbbc4808932b6af42c4041f06
- hash: 9e951cf2f868b71aaaa05966d8eb96d333b80106
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
Description
The Gentlemen ransomware is a self-propagating ransomware-as-a-service (RaaS) operation that emerged in mid-2025. It uses strong per-file encryption with Curve25519 and XChaCha20 stream cipher and employs aggressive lateral movement techniques to compromise networks broadly. The malware disables defenses, deletes shadow copies and forensic artifacts, and can wipe free disk space to hinder recovery efforts. It also exfiltrates sensitive data for double extortion. The operation recruits affiliates via BreachForums and targets multiple sectors globally, including education, transportation, healthcare, and finance. No official patch or fix is available as this is malware rather than a software vulnerability. No known exploits in the wild have been reported yet.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Gentlemen ransomware, tracked as Storm-2697, is a Go-based ransomware-as-a-service that combines robust encryption using Curve25519 and XChaCha20 with extensive self-propagation capabilities. It employs at least 21 lateral movement techniques such as PsExec, WMI, scheduled tasks, services, and PowerShell remoting to spread across networks. The malware disables security defenses, deletes shadow copies and forensic artifacts, and optionally wipes free disk space to prevent data recovery. It also exfiltrates sensitive information to enable double extortion. The operation transitioned to RaaS by September 2025 and recruits affiliates including penetration testers and initial access brokers via BreachForums. It impacts organizations across multiple sectors globally. There is no patch or remediation available as this is a malware threat rather than a software vulnerability.
Potential Impact
The Gentlemen ransomware can cause significant operational disruption by encrypting files with strong cryptography and preventing recovery through deletion of shadow copies and optional wiping of free disk space. The double extortion tactic increases the risk of data leakage and reputational damage. Its aggressive lateral movement techniques enable broad network compromise, increasing the scope of impact within affected organizations. The disabling of defenses and deletion of forensic artifacts complicate incident response and recovery efforts.
Mitigation Recommendations
As this is a malware threat rather than a software vulnerability, no official patch or fix is available. Organizations should focus on preventive measures such as restricting lateral movement capabilities, monitoring for unusual administrative activity, and maintaining offline backups. Incident response should prioritize containment and recovery. There is no vendor advisory indicating no action required or existing mitigation. Patch status is not applicable.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/"]
- Adversary
- Storm-2697
- Pulse Id
- 6a189defc88ad66cd0a9d87d
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67 | — | |
hashfe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68 | — | |
hash7a262d4cbbc4808932b6af42c4041f06 | — | |
hash9e951cf2f868b71aaaa05966d8eb96d333b80106 | — |
Threat ID: 6a196f02e29bf47b50db4449
Added to database: 5/29/2026, 10:48:34 AM
Last enriched: 5/29/2026, 11:03:30 AM
Last updated: 5/29/2026, 7:45:18 PM
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.