The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go Encryptor — Threadlinqs Intelligence
As of 2026-07-11, The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go Encryptor is a high-severity ransomware threat attributed to The Gentlemen, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-1220 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: The Gentlemen · FINANCIAL
The Gentlemen is a ransomware-as-a-service operation, tracked by Microsoft as Storm-2697, that has claimed over 500 victims across 70+ countries and ranked in the top 10 ransomware actors by victim
The Gentlemen RaaS emerged mid-2025 as a Go-based ransomware family and began offering affiliate partnerships in September 2025, subsequently establishing recruitment ties with BreachForums. By early 2026 the group had ramped up operations sharply, and Kaspersky's Securelist began tracking it in February 2026; by April 2026 Microsoft observed it accounting for roughly 10% of global ransomware activity, ranking among the top 10 RaaS actors by victim announcements in H1 2026.
The group's primary payload is a Go-based ransomware protected by a custom Go obfuscator that scrambles symbols and function signatures, requires a hardcoded execution password (CbdU8EgF), and implements a hybrid cryptographic scheme: for each file, the malware generates an ephemeral Curve25519 key pair, computes an ECDH shared secret against the operator's embedded public key (Base64: HvzC6Dq/siFthWSgE5ozZyQDu9cyxIoxb3NuRHI6pDM=), derives the XChaCha20 key from that shared secret, and derives the nonce from the first 24 bytes of the ephemeral public key. Large files receive partial/intermittent encryption (3 distributed chunks at operator-configurable speeds of 0.3%-9%), while files under 1MB are fully encrypted; the ephemeral public key is stored Base64-encoded in a footer so operators can recover the shared secret and decrypt. The ransom note (README-GENTLEMEN.txt) directs victims to a Tox Messenger ID for negotiation, and the desktop wallpaper is replaced with an operator-supplied image.
A parallel C-based Windows variant remains under active development with unimplemented parameters; it uses AES256-GCM with RSA-wrapped keys, generating a random 32-byte key and 16-byte IV per file, drops a differently formatted ransom note (!-READ-ME—-GEN-TLE-MEN-!.txt), and has shifted victim communication from Tox to email — suggesting operational maturation toward a distinct negotiation channel. A custom Go-based backdoor (sample sihost.exe) uses the Yamux library to maintain a persistent TCP connection to a hardcoded C2 (81.177.215[.]15:9443), exfiltrates host telemetry (hostname, domain membership, UUID, local IPs gathered via WMI) as JSON, accepts remote command execution, and offers SOCKS proxying for network pivoting. A cross-platform ESXi/Linux locker rounds out the toolset for hypervisor and Linux server encryption.
Operationally, The Gentlemen affiliates gain initial access through exploitation of internet-facing service vulnerabilities, stolen or weak VPN/firewall credentials, and probable collaboration with Initial Access Brokers — with observed dwell times ranging from a few hours to several weeks depending on affiliate tradecraft. Reconnaissance relies on SharpADWS (SOAP-wrapped LDAP over ADWS to evade traditional LDAP monitoring), NetScan and Advanced IP Scanner for host/network enumeration, native netsh packet capture, and Wireshark analysis of captured traffic to harvest credentials.
The encryptor is notably self-propagating: rather than relying on a single lateral-movement path, it simultaneously fires 21 distinct techniques per target host without waiting on prior success, first staging payloads to C:\Temp and a hidden SMB share (share$), embedding or downloading PsExec, then executing via remote C$ copy, PsExec, multiple WMIC process-creation variants, six scheduled-task variants (user/system context, three each), three Windows service-creation variants, PowerShell Remoting (Invoke-Command), and PowerShell WMI-class execution. Domain-wide propagation is reinforced via NETLOGON share malware placement and a deploy_gpo.ps1 Group Policy Object push targeting domain controllers, with Remote Server Administration Tools (RSAT) and NetServerEnum API fallback used for domain computer enumeration when PowerShell paths fail.
Defense evasion is extensive and layered. The group markets its own EDR/AV-killer framework, GentleKiller, comprising at least eight distinct BYOVD (Bring Your Own Vulnerable Driver) variants abusing legitimately signed but vulnerabl
Weaknesses (CWE)
CWE-732, CWE-284, CWE-306
Target sectors: manufacturing, itservices, health, financialservices, construction, logistics, education, transport
Target regions: brazil, china, indonesia, taiwan, thailand, North America, 005 - South America, Europe, Africa, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1190, T1078, T1133, T1059, T1059, T1047, T1053, T1569, T1053, T1547