Threat reportRansomwareTL-2026-3038

The Gentlemen RaaS: BYOVD AV/EDR Killing (ThrottleBlood.sys / CVE-2025-7771), FortiGate Initial Access and GPO/NETLOGON Ransomware Deployment

highACTIVE

The Gentlemen RaaS (TL-2026-3038), also tracked as Gentlemen ransomware, is a high-severity ransomware operation, first published 2026-10-08. It is attributed to The Gentlemen with low confidence, affects Fortinet FortiOS / FortiProxy, references 2 CVEs (CVE-2024-55591, CVE-2025-7771), maps to 23 MITRE ATT&CK techniques (T1018, T1021.002, T1039), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
23MITRE ATT&CK
Actors
1The Gentlemen
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-3038

Threat ID
TL-2026-3038
Also known as
Gentlemen ransomware, The Gentlemen RaaS
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
The Gentlemen
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
manufacturing, insurance, construction, consumer services, health, financial services
Target regions
Asia-Pacific, thailand, North America, 005 - South America, Middle East
Detection rules
9
Indicators of compromise
27

Malware and tooling in The Gentlemen RaaS

Malware and tooling: AnyDesk, Advanced IP Scanner, AnyDesk, PSEXEC, WinSCP

How The Gentlemen RaaS works

The Gentlemen is a ransomware-as-a-service and data-extortion operation that emerged in 2025 and, per Intel 471, has publicly claimed breaches of over 600 organizations in at least 80 countries. Intrusions start from compromised credentials or exposed FortiGate/VPN admin interfaces, kill AV/EDR with a renamed ThrottleStop driver (ThrottleBlood.sys, CVE-2025-7771) plus All.exe/Allpatch2.exe, exfiltrate with WinSCP, and deploy the locker domain-wide via NETLOGON and Group Policy.

The Gentlemen emerged in mid-to-late 2025 (Intel 471 and Trend Micro say August 2025; HivePro dates the earliest confirmed victim to 30 June 2025 and the forum advertisement under the alias 'Zeta88' to 12 September 2025). It runs a RaaS-and-affiliate model with dual extortion (Tor leak site plus encryption). Intel 471 reports public claims of over 600 organizations in at least 80 countries across manufacturing, insurance, construction, consumer services, healthcare and financial services, with a focus on Asia-Pacific (notably Thailand) and North America; HivePro counted over 320 listed victims by April 2026. Public claim counts differ between vendors and are unverified.

Initial access is by compromised credentials or internet-exposed VPN/firewall services. In the Trend Micro-investigated intrusion (August 2025), a FortiGate server was directly reachable from the internet and a FortiGate administrative account was compromised; Trend did not confirm the exact vector. HivePro and Ampcus-derived reporting attribute FortiGate access to exploitation of CVE-2024-55591 (FortiOS/FortiProxy authentication bypass, CISA KEV) and claim a curated database of roughly 14,700 compromised FortiGate devices and 969 validated brute-forced VPN credentials; this is secondary, single-source reporting. Early discovery used Advanced IP Scanner, Nmap 7.97 and a 1.bat script that ran net user/net group queries against 60+ accounts (admin.it, fortigate, Domain Admins, Enterprise Admins, itgateadmin).

Defense evasion is the group's signature. It loads a signed vulnerable driver, ThrottleStop.sys renamed ThrottleBlood.sys (CVE-2025-7771: two IOCTLs expose unrestricted physical memory access, allowing kernel patching and ring-0 code execution), paired with All.exe (both dropped in %USERPROFILE%\Downloads) to terminate protected AV/EDR processes. PowerRun.exe is abused to escalate privileges and stop security services. A later, per-environment variant, Allpatch2.exe, targets the specific security-agent components found during reconnaissance. Windows Defender is disabled with Set-MpPreference/Add-MpPreference and registry changes; RestrictSendingNTLMTraffic, DisableRestrictedAdmin and the RDP SecurityLayer value are modified, and the firewall is changed to keep RDP enabled for negotiation.

Lateral movement uses PsExec, with possible PuTTY/SSH, and AnyDesk provides persistent remote access. Data is staged in C:\ProgramData\data, accessed over WebDAV (davclnt.dll) from internal shares, and exfiltrated with WinSCP (C:\ProgramData\WinSCP.exe). Group Policy tools (gpmc.msc, gpme.msc) and encoded PowerShell ((Get-ADDomain).PDCEmulator) are used against the primary domain controller, and the password-protected locker (--password, 8 bytes; optional --path) is placed on the domain NETLOGON share. Intel 471 also highlights privileged-group manipulation (net group/localgroup /add) as a behavioral hunt opportunity.

Impact: files are encrypted with the .7mtzhh extension and README-GENTLEMEN.txt is dropped. The locker stops backup, database and security services (Veeam, Acronis, SQL Server, Oracle, MySQL, PostgreSQL, SAP, Exchange, Sophos, Docker, Backup Exec, vmms), kills 100+ processes, deletes shadow copies (vssadmin/wmic), clears Security/Application/System event logs, deletes Prefetch, RDP logs and Defender support files, and drops a {filename}.exe.bat self-delete script. HivePro additionally reports Go-based Windows/Linux/NAS/BSD lockers and a C-based ESXi locker, X25519 + XChaCha20 hybrid encryption, Cobalt Strike and SystemBC use, and a 90/10 affiliate split; these come from a single source. Static indicators (file names, extension, note name) decay quickly, so behavior-based detection of BYOVD driver loads, mass service stops, NETLOGON writes and privileged-group additions is recommended.

MITRE ATT&CK techniques used in TL-2026-3038

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1069.002 Permission Groups Discovery: Domain Groups; T1087.002 Account Discovery: Domain Account

Lateral Movement

T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer

Collection

T1039 Data from Network Shared Drive; T1074.001 Data Staged: Local Data Staging

Exfiltration

T1048.001 Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell

Initial Access

T1078.002 Valid Accounts: Domain Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Persistence

T1098 Account Manipulation

defense-impairment

T1112 Modify Registry; T1685.005 Clear Windows Event Logs

command-and-control

T1219 Remote Access Tools

Privilege Escalation

T1484.001 Domain or Tenant Policy Modification: Group Policy Modification

Impact

T1489 Service Stop; T1490 Inhibit System Recovery

Defense Impairment

T1685 Disable or Modify Tools; T1686 Disable or Modify System Firewall

Affected products and versions in The Gentlemen RaaS

  • Fortinet — FortiOS / FortiProxy
    Vulnerable versions: FortiOS 7.0.0-7.0.16; FortiProxy 7.0.0-7.0.19; FortiProxy 7.2.0-7.2.12
    Fixed in: FortiOS 7.0.17+; FortiProxy 7.0.20+; FortiProxy 7.2.13+
  • TechPowerUp — ThrottleStop (ThrottleStop.sys driver)
    Vulnerable versions: 3.0.0.0 and possibly others
  • Microsoft — Windows / Active Directory (GPO and NETLOGON abuse)
    Vulnerable versions: Domain-joined Windows hosts

Remediation for The Gentlemen RaaS

Patches

  • Upgrade FortiOS to 7.0.17 or later and FortiProxy to 7.0.20 / 7.2.13 or later for CVE-2024-55591 (Fortinet PSIRT FG-IR-24-535)
  • Block vulnerable ThrottleStop.sys 3.0.0.0 and renamed copies via driver blocklist (CVE-2025-7771)

Immediate actions

  • Hunt for ThrottleBlood.sys / ThrottleStop.sys driver loads, All.exe, Allpatch2.exe and PowerRun.exe, and for the .7mtzhh extension and README-GENTLEMEN.txt
  • Alert on net group/localgroup /add to Administrators, Domain Admins, Enterprise Admins, Schema Admins, DnsAdmins and Hyper-V Administrators and review whether the added account later logged in
  • Alert on new or modified executables on NETLOGON/SYSVOL and on new GPOs creating immediate scheduled tasks
  • Audit FortiGate/VPN admin interfaces and accounts for unexpected logins and rotate credentials

Workarounds

  • Restrict FortiGate administrative interface access to trusted management networks
  • Restrict domain controller share write access and monitor NETLOGON changes

Longer-term hardening

  • Enable EDR tamper protection, agent self-protection and password-protected uninstall
  • Enforce Microsoft vulnerable driver blocklist / HVCI and driver signature verification, alerting on vulnerable driver loads
  • Remove direct internet exposure of RDP and admin interfaces; require MFA and segment management networks
  • Use just-in-time privileged access with automatic de-escalation; restrict unapproved remote-access tools such as AnyDesk
  • Keep offline, immutable backups for Veeam and database servers; block execution from Temp and Downloads directories

CVEs associated with The Gentlemen RaaS

CVE-2024-55591, CVE-2025-7771

Weaknesses (CWE) in The Gentlemen RaaS

CWE-288, CWE-782

Timeline of The Gentlemen RaaS

  • CVE-2024-55591 (FortiOS/FortiProxy authentication bypass, later reported as a Gentlemen initial-access vector) is published and added to CISA KEV with a remediation due date of 2025-01-21.
  • Earliest confirmed victim, a Peruvian steel manufacturer, compromised (Hive Pro; single-source).
  • CVE-2025-7771 (ThrottleStop.sys arbitrary physical memory access) is published; Kaspersky had documented AV-killer abuse of the driver.
  • The Gentlemen emerges as a data-extortion/RaaS operation in August 2025 (Intel 471, Trend Micro); Trend investigates an intrusion that month. Day is approximate; sources give the month only.
  • Trend Micro publishes 'Unmasking the Gentlemen Ransomware' describing BYOVD, GPO manipulation, custom anti-AV tools and WinSCP exfiltration.
  • Ampcus Cyber publishes 'Dressed to Encrypt' with defensive recommendations.
  • RaaS program advertised on underground forums under the alias 'Zeta88' with a 90/10 affiliate split (Hive Pro; single-source).
  • Hive Pro advisory (April 2026; day approximate) counts over 320 publicly listed victims, mostly from early 2026, and notes Linux, NAS, BSD and ESXi lockers.
  • Intel 471 publishes a threat hunting case study citing claimed breaches of over 600 organizations in at least 80 countries and a privileged-group-addition hunt.

Sources cited for The Gentlemen RaaS

Detection coverage for TL-2026-3038

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3038 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-3038

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats