The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go Encryptor

The Gentlemen RaaS (Storm-2697) (TL-2026-1220), also tracked as Gentlemen Ransomware, is a high-severity ransomware operation, first published 2026-07-11. It is attributed to The Gentlemen with high confidence, affects Microsoft Windows (all supported versions, workstation and server), maps to 38 MITRE ATT&CK techniques (T1005, T1007, T1018), and is covered by 9 detection rules and 35 indicators of compromise.

Key facts for TL-2026-1220

Threat ID
TL-2026-1220
Also known as
Gentlemen Ransomware, GentleKiller
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-11
Last reviewed
2026-07-11
Attribution
The Gentlemen
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
manufacturing, itservices, health, financialservices, construction, logistics, education, transport
Target regions
brazil, china, indonesia, taiwan, thailand, North America, 005 - South America, Europe, Africa, Asia
Detection rules
9
Indicators of compromise
35

Malware and tooling in The Gentlemen RaaS (Storm-2697)

Malware and tooling: GentleKiller, The Gentlemen Ransomware (C variant), The Gentlemen Ransomware (Go variant), OpenArk64, PSEXEC, SharpADWS, Windows Kernel Explorer, Yamux-based custom Go backdoor

The Gentlemen is a ransomware-as-a-service operation, tracked by Microsoft as Storm-2697, that has claimed over 500 victims across 70+ countries and ranked in the top 10 ransomware actors by victim announcements in H1 2026. It operates a self-propagating Go-based encryptor (Curve25519 + XChaCha20), a C-based Windows variant in development (AES256-GCM + RSA), a custom Go backdoor, and an ESXi/Linux locker, using an in-house BYOVD framework ("GentleKiller") with at least eight vulnerable-driver variants to terminate 400+ security processes across 48 vendors.

How The Gentlemen RaaS (Storm-2697) works

The Gentlemen RaaS emerged mid-2025 as a Go-based ransomware family and began offering affiliate partnerships in September 2025, subsequently establishing recruitment ties with BreachForums. By early 2026 the group had ramped up operations sharply, and Kaspersky's Securelist began tracking it in February 2026; by April 2026 Microsoft observed it accounting for roughly 10% of global ransomware activity, ranking among the top 10 RaaS actors by victim announcements in H1 2026.

The group's primary payload is a Go-based ransomware protected by a custom Go obfuscator that scrambles symbols and function signatures, requires a hardcoded execution password (CbdU8EgF), and implements a hybrid cryptographic scheme: for each file, the malware generates an ephemeral Curve25519 key pair, computes an ECDH shared secret against the operator's embedded public key (Base64: HvzC6Dq/siFthWSgE5ozZyQDu9cyxIoxb3NuRHI6pDM=), derives the XChaCha20 key from that shared secret, and derives the nonce from the first 24 bytes of the ephemeral public key. Large files receive partial/intermittent encryption (3 distributed chunks at operator-configurable speeds of 0.3%-9%), while files under 1MB are fully encrypted; the ephemeral public key is stored Base64-encoded in a footer so operators can recover the shared secret and decrypt. The ransom note (README-GENTLEMEN.txt) directs victims to a Tox Messenger ID for negotiation, and the desktop wallpaper is replaced with an operator-supplied image.

A parallel C-based Windows variant remains under active development with unimplemented parameters; it uses AES256-GCM with RSA-wrapped keys, generating a random 32-byte key and 16-byte IV per file, drops a differently formatted ransom note (!-READ-ME—-GEN-TLE-MEN-!.txt), and has shifted victim communication from Tox to email — suggesting operational maturation toward a distinct negotiation channel. A custom Go-based backdoor (sample sihost.exe) uses the Yamux library to maintain a persistent TCP connection to a hardcoded C2 (81.177.215[.]15:9443), exfiltrates host telemetry (hostname, domain membership, UUID, local IPs gathered via WMI) as JSON, accepts remote command execution, and offers SOCKS proxying for network pivoting. A cross-platform ESXi/Linux locker rounds out the toolset for hypervisor and Linux server encryption.

Operationally, The Gentlemen affiliates gain initial access through exploitation of internet-facing service vulnerabilities, stolen or weak VPN/firewall credentials, and probable collaboration with Initial Access Brokers — with observed dwell times ranging from a few hours to several weeks depending on affiliate tradecraft. Reconnaissance relies on SharpADWS (SOAP-wrapped LDAP over ADWS to evade traditional LDAP monitoring), NetScan and Advanced IP Scanner for host/network enumeration, native netsh packet capture, and Wireshark analysis of captured traffic to harvest credentials.

The encryptor is notably self-propagating: rather than relying on a single lateral-movement path, it simultaneously fires 21 distinct techniques per target host without waiting on prior success, first staging payloads to C:\Temp and a hidden SMB share (share$), embedding or downloading PsExec, then executing via remote C$ copy, PsExec, multiple WMIC process-creation variants, six scheduled-task variants (user/system context, three each), three Windows service-creation variants, PowerShell Remoting (Invoke-Command), and PowerShell WMI-class execution. Domain-wide propagation is reinforced via NETLOGON share malware placement and a deploy_gpo.ps1 Group Policy Object push targeting domain controllers, with Remote Server Administration Tools (RSAT) and NetServerEnum API fallback used for domain computer enumeration when PowerShell paths fail.

Defense evasion is extensive and layered. The group markets its own EDR/AV-killer framework, GentleKiller, comprising at least eight distinct BYOVD (Bring Your Own Vulnerable Driver) variants abusing legitimately signed but vulnerable kernel drivers — including Safetica DLP/EDR's ProcessMonitorDriver.sys, WatchDog Anti-Malware's wamsdk.sys, an anti-cheat driver (gamedriverx64.sys), Paragon's biontdrv.sys partition-manager driver, a legacy RGB-lighting driver (inpoutx64.sys), Topaz anti-fraud's wsddprm.sys, and a Huawei audio driver (havoc.sys) — collectively capable of terminating 400+ security processes across 48 vendors. Kaspersky-specific tradecraft includes kavrmvr.exe to attempt uninstallation of Kaspersky products (blocked by behavioral detection), alongside Windows Kernel Explorer and OpenArk64 for manual driver enumeration/removal. PowerShell and registry tradecraft disables Microsoft Defender real-time monitoring and exclusions (Set-MpPreference -DisableRealtimeMonitoring $true -Force; DisableAntiSpyware=1; DisableBehaviorMonitoring=1 registry keys).

Pre-encryption impact staging includes forced shutdown of Hyper-V virtual machines (Get-VM | Stop-VM -Force -TurnOff), termination of 60+ processes and services spanning databases, backup agents, RMM tools, Office applications, and virtualization software via taskkill.exe and sc.exe, ACL manipulation via takeown.exe/icacls.exe to guarantee write access for encryption, and persistence via a scheduled task (UpdateUser) and a Run-key registry value (GupdateS). Post-encryption anti-forensic cleanup deletes Volume Shadow Copies (vssadmin.exe delete shadows /all /quiet, also via wmic), clears System/Application/Security event logs (wevtutil), purges Prefetch and RDP log directories, and empties the Recycle Bin.

Microsoft attributes operation of the RaaS platform to Storm-2697, a financially motivated actor group, and assigns the detection name Ransom:Win64/Gentlemen. High-confidence attribution derives from consistent group branding across binaries and ransom notes, associated negotiation email addresses, a dedicated Data Leak Site, and leaked internal affiliate communications corroborating continued operational activity. Victimology spans manufacturing, IT services, healthcare, financial services, construction, logistics, education, and transportation sectors across a broad geography — Brazil, China, Indonesia, Taiwan, and Thailand rank highest by Kaspersky telemetry, while Microsoft observed impact across North America, South America, Europe, Africa, and Asia — consistent with an affiliate-driven RaaS model with minimal sector/geographic targeting discipline.

MITRE ATT&CK techniques used in TL-2026-1220

Collection

T1005 Data from Local System

Discovery

T1007 System Service Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1482 Domain Trust Discovery

Lateral Movement

T1021 Remote Services; T1550 Use Alternate Authentication Material; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth

Credential Access

T1040 Network Sniffing

Execution

T1047 Windows Management Instrumentation; T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1569 System Services

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1571 Non-Standard Port

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

defense-impairment

T1112 Modify Registry; T1222 File and Directory Permissions Modification; T1685 Disable or Modify Tools

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1529 System Shutdown/Reboot

Resource Development

T1585 Establish Accounts; T1588 Obtain Capabilities

Affected products and versions in The Gentlemen RaaS (Storm-2697)

  • Microsoft — Windows (all supported versions, workstation and server)
    Vulnerable versions: all supported Windows versions targeted via lateral movement, not a specific CVE
  • VMware — ESXi
    Vulnerable versions: ESXi hosts targeted by dedicated Linux/ESXi locker variant
  • Safetica — Safetica DLP/EDR driver (ProcessMonitorDriver.sys)
    Vulnerable versions: abused as BYOVD vector
  • WatchDog — WatchDog Anti-Malware driver (wamsdk.sys)
    Vulnerable versions: abused as BYOVD vector
  • Paragon Software — Paragon partition manager driver (biontdrv.sys)
    Vulnerable versions: abused as BYOVD vector
  • Topaz — Topaz anti-fraud driver (wsddprm.sys)
    Vulnerable versions: abused as BYOVD vector
  • Huawei — Huawei audio driver (havoc.sys)
    Vulnerable versions: abused as BYOVD vector

Remediation for The Gentlemen RaaS (Storm-2697)

Immediate actions

  • Block outbound connections to C2 IP 81.177.215.15 (TCP/9443) at perimeter firewalls and proxies
  • Enable Windows Defender / EDR tamper protection so BYOVD driver-loading and AV-disabling commands cannot succeed
  • Restrict driver-loading policy (WDAC/HVCI, Microsoft vulnerable driver blocklist) to block ProcessMonitorDriver.sys, wamsdk.sys, gamedriverx64.sys, biontdrv.sys, inpoutx64.sys, wsddprm.sys, and havoc.sys
  • Disable or tightly restrict PsExec, WMIC remote process creation, and PowerShell Remoting for non-admin accounts via Attack Surface Reduction rules
  • Restrict/monitor NETLOGON and SYSVOL share write access to prevent GPO-based malware staging
  • Hunt for scheduled task 'UpdateUser' and registry Run key value 'GupdateS' across the environment

Workarounds

  • Enable Controlled Folder Access to protect critical directories from mass file encryption
  • Block driver loading from non-standard/unsigned-by-policy paths via WDAC to blunt BYOVD variants beyond the seven named drivers

Longer-term hardening

  • Deploy EDR in block mode with automatic attack disruption enabled (Defender XDR or equivalent)
  • Enforce MFA and credential rotation on all internet-facing VPN/firewall management interfaces
  • Implement network segmentation to slow SMB-based self-propagation (C$/share$ lateral movement)
  • Deploy immutable, offline/air-gapped backups given VSS deletion and Hyper-V VM termination behavior
  • Monitor for SharpADWS-style SOAP/ADWS LDAP queries as an AD reconnaissance detection gap

Weaknesses (CWE) in The Gentlemen RaaS (Storm-2697)

CWE-732, CWE-284, CWE-306

Timeline of The Gentlemen RaaS (Storm-2697)

  • The Gentlemen Go-based ransomware family first observed/emerges as an independent RaaS operation (mid-2025).
  • The Gentlemen begins offering affiliate partnerships, expanding the RaaS to third-party operators.
  • Significant ramp-up in operational tempo observed heading into early 2026, with rising victim announcement counts.
  • Kaspersky Securelist begins formally tracking The Gentlemen RaaS, documenting BYOVD tooling, malware variants, and C2 infrastructure.
  • The Gentlemen accounts for approximately 10% of all global ransomware activity observed in April 2026 (Microsoft telemetry).
  • Group establishes official affiliate recruitment ties with the BreachForums cybercrime community.
  • Microsoft publishes detailed technical analysis attributing the RaaS platform's operation to Storm-2697 and dissecting the self-propagating Go encryptor's 21 lateral-movement techniques.
  • The Gentlemen confirmed ranked among the top 10 ransomware actors globally by victim announcements for H1 2026, with 500+ claimed victims across 70+ countries.
  • Threat intelligence compiled from Kaspersky Securelist and Microsoft Storm-2697 reporting for TL-2026-1220.

Sources cited for The Gentlemen RaaS (Storm-2697)

Threats related to The Gentlemen RaaS (Storm-2697)

Detection coverage for TL-2026-1220

As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1220 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats