Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

0
Medium
Published: Thu May 28 2026 (05/28/2026, 19:56:31 UTC)
Source: AlienVault OTX General

Description

The Gentlemen ransomware is a self-propagating ransomware-as-a-service (RaaS) operation that emerged in mid-2025. It uses strong per-file encryption with Curve25519 and XChaCha20 stream cipher and employs aggressive lateral movement techniques to compromise networks broadly. The malware disables defenses, deletes shadow copies and forensic artifacts, and can wipe free disk space to hinder recovery efforts. It also exfiltrates sensitive data for double extortion. The operation recruits affiliates via BreachForums and targets multiple sectors globally, including education, transportation, healthcare, and finance. No official patch or fix is available as this is malware rather than a software vulnerability. No known exploits in the wild have been reported yet.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/29/2026, 11:03:30 UTC

Technical Analysis

The Gentlemen ransomware, tracked as Storm-2697, is a Go-based ransomware-as-a-service that combines robust encryption using Curve25519 and XChaCha20 with extensive self-propagation capabilities. It employs at least 21 lateral movement techniques such as PsExec, WMI, scheduled tasks, services, and PowerShell remoting to spread across networks. The malware disables security defenses, deletes shadow copies and forensic artifacts, and optionally wipes free disk space to prevent data recovery. It also exfiltrates sensitive information to enable double extortion. The operation transitioned to RaaS by September 2025 and recruits affiliates including penetration testers and initial access brokers via BreachForums. It impacts organizations across multiple sectors globally. There is no patch or remediation available as this is a malware threat rather than a software vulnerability.

Potential Impact

The Gentlemen ransomware can cause significant operational disruption by encrypting files with strong cryptography and preventing recovery through deletion of shadow copies and optional wiping of free disk space. The double extortion tactic increases the risk of data leakage and reputational damage. Its aggressive lateral movement techniques enable broad network compromise, increasing the scope of impact within affected organizations. The disabling of defenses and deletion of forensic artifacts complicate incident response and recovery efforts.

Mitigation Recommendations

As this is a malware threat rather than a software vulnerability, no official patch or fix is available. Organizations should focus on preventive measures such as restricting lateral movement capabilities, monitoring for unusual administrative activity, and maintaining offline backups. Incident response should prioritize containment and recovery. There is no vendor advisory indicating no action required or existing mitigation. Patch status is not applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/"]
Adversary
Storm-2697
Pulse Id
6a189defc88ad66cd0a9d87d
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67
hashfe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68
hash7a262d4cbbc4808932b6af42c4041f06
hash9e951cf2f868b71aaaa05966d8eb96d333b80106

Threat ID: 6a196f02e29bf47b50db4449

Added to database: 5/29/2026, 10:48:34 AM

Last enriched: 5/29/2026, 11:03:30 AM

Last updated: 5/29/2026, 7:45:18 PM

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses