The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR Killers, and Rclone Exfiltration

The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte) (TL-2026-2271), also tracked as Storm-2697, is a critical-severity ransomware operation scored CVSS 9.8, first published 2026-09-01. It is attributed to The Gentlemen RaaS operators with medium confidence, affects Fortinet FortiOS, references 1 CVE (CVE-2024-55591), maps to 15 MITRE ATT&CK techniques (T1003.001, T1021.001, T1036.001), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-2271

Threat ID
TL-2026-2271
Also known as
Storm-2697
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
RANSOMWARE
First published
2026-09-01
Last reviewed
2026-09-01
Attribution
The Gentlemen RaaS operators
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
manufacturing, health, finance, retail, education, critical infrastructure, professional services
Target regions
Global, North America, 155 - Western Europe, Southeast Asia, 005 - South America
Detection rules
9
Indicators of compromise
23

Malware and tooling in The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte)

Malware and tooling: AnyDesk, GentleKiller, MimiKatz, the gentlemen, MeshCentral, PSEXEC, Rclone - S1040, userpassfort.py

The Gentlemen ransomware-as-a-service operation (Sophos CTU tracking name GOLD SHERWOOD; operator handle hastalamuerte) breaches victims through compromised Fortinet SSL VPN credentials and exploitation of the FortiOS/FortiProxy authentication-bypass flaw CVE-2024-55591, then moves laterally over RDP with valid domain credentials, deploys the in-house GentleKiller BYOVD EDR-killer framework, and exfiltrates data via Rclone before detonating Go-based locker binaries. Leak-site postings rose from under 20/month in late 2025 to 169 in July 2026 alone (683 victims total), with a median attacker dwell time near two days.

How The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte) works

The Gentlemen is a Russian-speaking ransomware-as-a-service operation that emerged publicly in July-September 2025, run by an operator known as hastalamuerte (alias Zeta88), who previously operated under the handle ArmCorp as a Qilin affiliate before launching an independent RaaS brand offering a 90/10 affiliate revenue split -- among the most generous in the criminal ecosystem. Sophos CTU (incorporating former Secureworks CTU research and tracking the group as GOLD SHERWOOD) documents the group's primary initial-access chain as a combination of brute-forced and stolen/leaked Fortinet SSL VPN credentials plus active exploitation of CVE-2024-55591, a critical (CVSS 9.8) authentication bypass in the FortiOS/FortiProxy Node.js WebSocket module that lets an unauthenticated remote attacker obtain super-admin privileges on internet-exposed firewall management interfaces via a four-step flaw chain: unauthenticated WebSocket session creation, abuse of the local_access_token parameter, a race-condition window, and bypass of subsequent credential validation. Group-IB's TTP analysis, corroborated by an internal May 2026 data leak (leaked Rocket.Chat operator logs and an operator database), found the group maintains a working inventory of roughly 14,700 internet-exposed FortiGate devices and 969 validated brute-forced VPN credential pairs, and selects targets based on FortiGate misconfiguration, LDAP integration, and ransom-payment likelihood rather than geography or sector.

Once inside, operators pivot rapidly -- median dwell time to ransomware deployment is roughly two days, with some incidents under 24 hours. Lateral movement is conducted primarily over RDP using valid domain credentials against file servers and domain controllers, supported by discovery tooling (Advanced IP Scanner, SoftPerfect Network Scanner, NetExec) and credential access via Mimikatz-based LSASS dumping and a custom Python harvester (userpassfort.py). Persistence and defense-evasion techniques include creating rogue domain admin accounts via native `net` commands, enabling RDP through registry and firewall changes, disabling Windows Defender via PowerShell (`Add-MpPreference -ExclusionPath C:\ -Force`), stopping backup services (VeeamBackupSvc, SQLWriter, BackupExecAgent, and 200+ other service-name variants), clearing Windows Application/System/Security event logs, and staging attacker tooling under the benign-looking `C:\PerfLogs\` directory.

The operation's signature capability, documented in depth by ESET's June 2026 'Killing Me Gently' research, is GentleKiller: a centralized, operator-maintained Bring-Your-Own-Vulnerable-Driver (BYOVD) EDR-killer framework with at least eight distinct variants, each impersonating a legitimate security or gaming product (Kaspersky, FACEIT Anti-Cheat, Valorant, EA/Javelin Anti-Cheat, WatchDog, a network blocker, a file-deletion 'Cleaner', and a Symantec/G11 variant) and each abusing a different vulnerable kernel driver (eb.sys, nseckrnl.sys, GameDriverX64.sys, stpm_old/new.sys, dmx.sys, 360netmon_wfp.sys, IObit's force-delete filter driver, and a PoisonX rootkit driver) to terminate endpoint protection at the kernel level. Rather than leaving driver-sourcing to affiliates, Gentlemen operators actively maintain the portfolio and fold in third-party/leaked killers (HexKiller, ThrottleBlood, HavocKiller), adopting newly disclosed BYOVD proofs-of-concept within days of public release -- consistently outpacing Microsoft's Vulnerable Driver Blocklist update cycle. Collectively the suite targets more than 400 processes across 48 named security products (Microsoft Defender, CrowdStrike, SentinelOne, Sophos, Kaspersky, Bitdefender, Trellix/McAfee, ESET, Palo Alto Networks, Trend Micro, Carbon Black, Cybereason, Huntress, and others). A domain-wide deployment script (`\\NETLOGON\avkill.bat`) pushes the killer suite to hosts network-wide.

Data exfiltration is dominated by Rclone (renamed to evade detection, e.g. avastrclone.exe), used with filtered, multi-threaded copy jobs (`--transfers 8 --max-age`, `--include-from`/`--filter-from`) staged to attacker-controlled Wasabi object-storage buckets named after the victim; Restic, MinIO Client, MEGAsync, and FileZilla are used as secondary channels, and remote-access tooling (Cloudflared, AnyDesk, MeshCentral, Datto RMM, Chisel) supports persistence and tunneling. The final-stage locker is a Go-based binary (`locker_<ext>_windows_amd64.exe` / `G_<ext>_windows_amd64.exe`), distributed with dedicated Windows, Linux/ESXi, and NAS encryptors, incorporating reverse-engineered encryption routines drawn from Babuk, Qilin, LockBit 5.0, and Medusa, appending a six-character extension to encrypted files, requiring a password/key argument to execute, and dropping a `README-GENTLEMEN.txt` ransom note; a September 2025 update added aggressive WMI-based self-propagation across a compromised network. By end of July 2026, Sophos CTU counted 683 total leak-site victims, up from fewer than 20/month in late 2025 to 169 in July 2026 alone, spanning manufacturing (the most-targeted single sector per Trend Micro, 103 of 580 tracked victims through early July), healthcare, finance, retail, and critical-infrastructure organizations across at least 17 regions/77 countries.

MITRE ATT&CK techniques used in TL-2026-2271

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory; T1110.001 Brute Force: Password Guessing

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol

Defense Evasion

T1036.001 Masquerading: Invalid Code Signature

Discovery

T1046 Network Service Discovery

Execution

T1059.001 Command and Scripting Interpreter: PowerShell

Initial Access

T1078.002 Valid Accounts: Domain Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Persistence

T1136.002 Create Account: Domain Account

Command and Control

T1219 Remote Access Tools

Impact

T1490 Inhibit System Recovery

Exfiltration

T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

defense-impairment

T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Affected products and versions in The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte)

  • Fortinet — FortiOS
    Vulnerable versions: 7.0.0 - 7.0.16
    Fixed in: 7.0.17 or later
  • Fortinet — FortiProxy
    Vulnerable versions: 7.0.0 - 7.0.19; 7.2.0 - 7.2.12
    Fixed in: 7.0.20 or later; 7.2.13 or later

Remediation for The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte)

Patches

  • FortiOS: upgrade to 7.0.17 or later
  • FortiProxy: upgrade to 7.2.13 or later (7.2.x branch) or 7.0.20 or later (7.0.x branch)

Immediate actions

  • Patch FortiOS to 7.0.17+ and FortiProxy to 7.2.13+/7.0.20+ to remediate CVE-2024-55591
  • Disable internet exposure of the FortiOS/FortiProxy HTTP/HTTPS administrative interface, or restrict it via trusted-host IP allowlisting
  • Force MFA and rotate credentials on all Fortinet SSL VPN accounts; hunt for logins from unexpected geolocations
  • Hunt for and block known GentleKiller filenames/hashes and the vulnerable drivers they load (nogbc.sys, G11.sys, dmx.sys and related BYOVD hashes) via EDR/AV signature and Microsoft's Vulnerable Driver Blocklist
  • Alert on RDP authentication bursts against multiple internal hosts in rapid succession from a single account, and on rogue domain-admin account creation via net.exe/net1.exe
  • Monitor for Rclone/Restic/MinIO Client execution and outbound traffic to cloud object-storage providers (e.g. Wasabi) from endpoints that do not normally perform backups

Workarounds

  • Disable the HTTP/HTTPS administrative interface on FortiOS/FortiProxy until patched
  • Restrict administrative interface access to trusted source IP addresses only

Longer-term hardening

  • Deploy EDR/XDR with kernel-level driver-load monitoring and behavioral (not signature-only) detection to counter BYOVD EDR killers
  • Segment management interfaces for network/security appliances onto an out-of-band management network with no direct internet exposure
  • Maintain immutable, offline backup copies and pre-emptively harden backup-service accounts (Veeam, Backup Exec, SQL Writer) against tamper/disable attempts
  • Enforce least-privilege and tiered administration to blunt rapid RDP-based lateral movement with reused domain-admin credentials

CVEs associated with The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte)

CVE-2024-55591

Weaknesses (CWE) in The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte)

CWE-288

Timeline of The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte)

  • CVE-2024-55591 (FortiOS/FortiProxy authentication bypass), later adopted as a primary Gentlemen initial-access vector, is added to the CISA Known Exploited Vulnerabilities catalog after zero-day exploitation since November 2024.
  • First Windows ransomware sample attributable to The Gentlemen operation is uploaded to VirusTotal (Group-IB).
  • Operator hastalamuerte, then using the ArmCorp handle as a Qilin affiliate, files a public $48,000 arbitration dispute against Qilin on the RAMP forum, foreshadowing the group's split into an independent RaaS.
  • The Gentlemen's data-leak site becomes publicly known, marking the operation's public RaaS launch (internally operational since mid-July 2025).
  • A dedicated ESXi/Linux hypervisor encryptor variant of the locker is released (Group-IB).
  • A background timer and aggressive WMI-based self-propagation module are added to the Go-based locker, enabling automated spread across compromised networks (Group-IB).
  • Leak-site postings are running at fewer than 20 victims/month, the baseline pace before the operation's 2026 scale-up (Sophos CTU).
  • Monthly leak-site victim postings climb to more than 75/month as the affiliate program scales (Sophos CTU).
  • Group-IB publishes TTP analysis attributing operations to hastalamuerte and detailing the four-step CVE-2024-55591 exploitation chain against FortiGate management interfaces.
  • An internal Gentlemen operator database and Rocket.Chat logs are leaked by an alleged insider, exposing an inventory of roughly 14,700 targeted FortiGate devices and 969 validated brute-forced VPN credential pairs.
  • Microsoft publishes technical analysis of the self-propagating Go-based encryptor under the tracking name Storm-2697.
  • ESET publishes 'Killing Me Gently,' detailing the GentleKiller BYOVD EDR-killer framework -- eight variants abusing distinct vulnerable drivers to target over 400 processes across 48 security products.
  • Sophos CTU reports 683 cumulative leak-site victims, with July 2026 alone accounting for 169 postings -- the operation's most active month to date and a median attacker dwell time near two days.

Sources cited for The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte)

More in ransomware

Detection coverage for TL-2026-2271

As of 2026-09-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2271 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats