The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR Killers, and Rclone Exfiltration — Threadlinqs Intelligence
As of 2026-09-01, The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR Killers, and Rclone Exfiltration is a critical-severity ransomware threat attributed to The Gentlemen RaaS operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-2271 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: RANSOMWARE
Attribution: The Gentlemen RaaS operators · FINANCIAL
The Gentlemen ransomware-as-a-service operation (Sophos CTU tracking name GOLD SHERWOOD; operator handle hastalamuerte) breaches victims through compromised Fortinet SSL VPN credentials and
The Gentlemen is a Russian-speaking ransomware-as-a-service operation that emerged publicly in July-September 2025, run by an operator known as hastalamuerte (alias Zeta88), who previously operated under the handle ArmCorp as a Qilin affiliate before launching an independent RaaS brand offering a 90/10 affiliate revenue split -- among the most generous in the criminal ecosystem. Sophos CTU (incorporating former Secureworks CTU research and tracking the group as GOLD SHERWOOD) documents the group's primary initial-access chain as a combination of brute-forced and stolen/leaked Fortinet SSL VPN credentials plus active exploitation of CVE-2024-55591, a critical (CVSS 9.8) authentication bypass in the FortiOS/FortiProxy Node.js WebSocket module that lets an unauthenticated remote attacker obtain super-admin privileges on internet-exposed firewall management interfaces via a four-step flaw chain: unauthenticated WebSocket session creation, abuse of the local_access_token parameter, a race-condition window, and bypass of subsequent credential validation. Group-IB's TTP analysis, corroborated by an internal May 2026 data leak (leaked Rocket.Chat operator logs and an operator database), found the group maintains a working inventory of roughly 14,700 internet-exposed FortiGate devices and 969 validated brute-forced VPN credential pairs, and selects targets based on FortiGate misconfiguration, LDAP integration, and ransom-payment likelihood rather than geography or sector.
Once inside, operators pivot rapidly -- median dwell time to ransomware deployment is roughly two days, with some incidents under 24 hours. Lateral movement is conducted primarily over RDP using valid domain credentials against file servers and domain controllers, supported by discovery tooling (Advanced IP Scanner, SoftPerfect Network Scanner, NetExec) and credential access via Mimikatz-based LSASS dumping and a custom Python harvester (userpassfort.py). Persistence and defense-evasion techniques include creating rogue domain admin accounts via native `net` commands, enabling RDP through registry and firewall changes, disabling Windows Defender via PowerShell (`Add-MpPreference -ExclusionPath C:\ -Force`), stopping backup services (VeeamBackupSvc, SQLWriter, BackupExecAgent, and 200+ other service-name variants), clearing Windows Application/System/Security event logs, and staging attacker tooling under the benign-looking `C:\PerfLogs\` directory.
The operation's signature capability, documented in depth by ESET's June 2026 'Killing Me Gently' research, is GentleKiller: a centralized, operator-maintained Bring-Your-Own-Vulnerable-Driver (BYOVD) EDR-killer framework with at least eight distinct variants, each impersonating a legitimate security or gaming product (Kaspersky, FACEIT Anti-Cheat, Valorant, EA/Javelin Anti-Cheat, WatchDog, a network blocker, a file-deletion 'Cleaner', and a Symantec/G11 variant) and each abusing a different vulnerable kernel driver (eb.sys, nseckrnl.sys, GameDriverX64.sys, stpm_old/new.sys, dmx.sys, 360netmon_wfp.sys, IObit's force-delete filter driver, and a PoisonX rootkit driver) to terminate endpoint protection at the kernel level. Rather than leaving driver-sourcing to affiliates, Gentlemen operators actively maintain the portfolio and fold in third-party/leaked killers (HexKiller, ThrottleBlood, HavocKiller), adopting newly disclosed BYOVD proofs-of-concept within days of public release -- consistently outpacing Microsoft's Vulnerable Driver Blocklist update cycle. Collectively the suite targets more than 400 processes across 48 named security products (Microsoft Defender, CrowdStrike, SentinelOne, Sophos, Kaspersky, Bitdefender, Trellix/McAfee, ESET, Palo Alto Networks, Trend Micro, Carbon Black, Cybereason, Huntress, and others). A domain-wide deployment script (`\\NETLOGON\avkill.bat`) pushes the killer suite to hosts network-wide.
Data exfiltration is dominated by Rclone (renamed to evade detection, e.g. avastrclone.exe), used
Target sectors: manufacturing, health, finance, retail, education, critical infrastructure, professional services
Target regions: Global, North America, 155 - Western Europe, Southeast Asia, 005 - South America
Timeline
- CVE-2024-55591 (FortiOS/FortiProxy authentication bypass), later adopted as a primary Gentlemen initial-access vector, is added to the CISA Known Exploited Vulnerabilities catalog after zero-day exploitation since November 2024.
- First Windows ransomware sample attributable to The Gentlemen operation is uploaded to VirusTotal (Group-IB).
- Operator hastalamuerte, then using the ArmCorp handle as a Qilin affiliate, files a public $48,000 arbitration dispute against Qilin on the RAMP forum, foreshadowing the group's split into an independent RaaS.
- The Gentlemen's data-leak site becomes publicly known, marking the operation's public RaaS launch (internally operational since mid-July 2025).
- A dedicated ESXi/Linux hypervisor encryptor variant of the locker is released (Group-IB).
- A background timer and aggressive WMI-based self-propagation module are added to the Go-based locker, enabling automated spread across compromised networks (Group-IB).
- Leak-site postings are running at fewer than 20 victims/month, the baseline pace before the operation's 2026 scale-up (Sophos CTU).
- Monthly leak-site victim postings climb to more than 75/month as the affiliate program scales (Sophos CTU).
- Group-IB publishes TTP analysis attributing operations to hastalamuerte and detailing the four-step CVE-2024-55591 exploitation chain against FortiGate management interfaces.
- An internal Gentlemen operator database and Rocket.Chat logs are leaked by an alleged insider, exposing an inventory of roughly 14,700 targeted FortiGate devices and 969 validated brute-forced VPN credential pairs.
- Microsoft publishes technical analysis of the self-propagating Go-based encryptor under the tracking name Storm-2697.
- ESET publishes 'Killing Me Gently,' detailing the GentleKiller BYOVD EDR-killer framework -- eight variants abusing distinct vulnerable drivers to target over 400 processes across 48 security products.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2024-55591, T1190, T1133, T1078.002, T1059.001, T1136.002, T1003.001, T1110.001, T1046, T1021.001, T1685