Threat reportRansomwareTL-2026-3038
The Gentlemen RaaS: BYOVD AV/EDR Killing (ThrottleBlood.sys / CVE-2025-7771), FortiGate Initial Access and GPO/NETLOGON Ransomware Deployment
The Gentlemen RaaS (TL-2026-3038), also tracked as Gentlemen ransomware, is a high-severity ransomware operation, first published 2026-10-08. It is attributed to The Gentlemen with low confidence, affects Fortinet FortiOS / FortiProxy, references 2 CVEs (CVE-2024-55591, CVE-2025-7771), maps to 23 MITRE ATT&CK techniques (T1018, T1021.002, T1039), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 23MITRE ATT&CK
- Actors
- 1The Gentlemen
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-3038
- Threat ID
- TL-2026-3038
- Also known as
- Gentlemen ransomware, The Gentlemen RaaS
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- The Gentlemen
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, insurance, construction, consumer services, health, financial services
- Target regions
- Asia-Pacific, thailand, North America, 005 - South America, Middle East
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in The Gentlemen RaaS
Malware and tooling: AnyDesk, Advanced IP Scanner, AnyDesk, PSEXEC, WinSCP
How The Gentlemen RaaS works
The Gentlemen is a ransomware-as-a-service and data-extortion operation that emerged in 2025 and, per Intel 471, has publicly claimed breaches of over 600 organizations in at least 80 countries. Intrusions start from compromised credentials or exposed FortiGate/VPN admin interfaces, kill AV/EDR with a renamed ThrottleStop driver (ThrottleBlood.sys, CVE-2025-7771) plus All.exe/Allpatch2.exe, exfiltrate with WinSCP, and deploy the locker domain-wide via NETLOGON and Group Policy.
The Gentlemen emerged in mid-to-late 2025 (Intel 471 and Trend Micro say August 2025; HivePro dates the earliest confirmed victim to 30 June 2025 and the forum advertisement under the alias 'Zeta88' to 12 September 2025). It runs a RaaS-and-affiliate model with dual extortion (Tor leak site plus encryption). Intel 471 reports public claims of over 600 organizations in at least 80 countries across manufacturing, insurance, construction, consumer services, healthcare and financial services, with a focus on Asia-Pacific (notably Thailand) and North America; HivePro counted over 320 listed victims by April 2026. Public claim counts differ between vendors and are unverified.
Initial access is by compromised credentials or internet-exposed VPN/firewall services. In the Trend Micro-investigated intrusion (August 2025), a FortiGate server was directly reachable from the internet and a FortiGate administrative account was compromised; Trend did not confirm the exact vector. HivePro and Ampcus-derived reporting attribute FortiGate access to exploitation of CVE-2024-55591 (FortiOS/FortiProxy authentication bypass, CISA KEV) and claim a curated database of roughly 14,700 compromised FortiGate devices and 969 validated brute-forced VPN credentials; this is secondary, single-source reporting. Early discovery used Advanced IP Scanner, Nmap 7.97 and a 1.bat script that ran net user/net group queries against 60+ accounts (admin.it, fortigate, Domain Admins, Enterprise Admins, itgateadmin).
Defense evasion is the group's signature. It loads a signed vulnerable driver, ThrottleStop.sys renamed ThrottleBlood.sys (CVE-2025-7771: two IOCTLs expose unrestricted physical memory access, allowing kernel patching and ring-0 code execution), paired with All.exe (both dropped in %USERPROFILE%\Downloads) to terminate protected AV/EDR processes. PowerRun.exe is abused to escalate privileges and stop security services. A later, per-environment variant, Allpatch2.exe, targets the specific security-agent components found during reconnaissance. Windows Defender is disabled with Set-MpPreference/Add-MpPreference and registry changes; RestrictSendingNTLMTraffic, DisableRestrictedAdmin and the RDP SecurityLayer value are modified, and the firewall is changed to keep RDP enabled for negotiation.
Lateral movement uses PsExec, with possible PuTTY/SSH, and AnyDesk provides persistent remote access. Data is staged in C:\ProgramData\data, accessed over WebDAV (davclnt.dll) from internal shares, and exfiltrated with WinSCP (C:\ProgramData\WinSCP.exe). Group Policy tools (gpmc.msc, gpme.msc) and encoded PowerShell ((Get-ADDomain).PDCEmulator) are used against the primary domain controller, and the password-protected locker (--password, 8 bytes; optional --path) is placed on the domain NETLOGON share. Intel 471 also highlights privileged-group manipulation (net group/localgroup /add) as a behavioral hunt opportunity.
Impact: files are encrypted with the .7mtzhh extension and README-GENTLEMEN.txt is dropped. The locker stops backup, database and security services (Veeam, Acronis, SQL Server, Oracle, MySQL, PostgreSQL, SAP, Exchange, Sophos, Docker, Backup Exec, vmms), kills 100+ processes, deletes shadow copies (vssadmin/wmic), clears Security/Application/System event logs, deletes Prefetch, RDP logs and Defender support files, and drops a {filename}.exe.bat self-delete script. HivePro additionally reports Go-based Windows/Linux/NAS/BSD lockers and a C-based ESXi locker, X25519 + XChaCha20 hybrid encryption, Cobalt Strike and SystemBC use, and a 90/10 affiliate split; these come from a single source. Static indicators (file names, extension, note name) decay quickly, so behavior-based detection of BYOVD driver loads, mass service stops, NETLOGON writes and privileged-group additions is recommended.
MITRE ATT&CK techniques used in TL-2026-3038
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1069.002 Permission Groups Discovery: Domain Groups; T1087.002 Account Discovery: Domain Account
Lateral Movement
T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer
Collection
T1039 Data from Network Shared Drive; T1074.001 Data Staged: Local Data Staging
Exfiltration
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell
Initial Access
T1078.002 Valid Accounts: Domain Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Persistence
defense-impairment
T1112 Modify Registry; T1685.005 Clear Windows Event Logs
command-and-control
Privilege Escalation
T1484.001 Domain or Tenant Policy Modification: Group Policy Modification
Impact
T1489 Service Stop; T1490 Inhibit System Recovery
Defense Impairment
T1685 Disable or Modify Tools; T1686 Disable or Modify System Firewall
Affected products and versions in The Gentlemen RaaS
- Fortinet — FortiOS / FortiProxy
Vulnerable versions: FortiOS 7.0.0-7.0.16; FortiProxy 7.0.0-7.0.19; FortiProxy 7.2.0-7.2.12
Fixed in: FortiOS 7.0.17+; FortiProxy 7.0.20+; FortiProxy 7.2.13+ - TechPowerUp — ThrottleStop (ThrottleStop.sys driver)
Vulnerable versions: 3.0.0.0 and possibly others - Microsoft — Windows / Active Directory (GPO and NETLOGON abuse)
Vulnerable versions: Domain-joined Windows hosts
Remediation for The Gentlemen RaaS
Patches
- Upgrade FortiOS to 7.0.17 or later and FortiProxy to 7.0.20 / 7.2.13 or later for CVE-2024-55591 (Fortinet PSIRT FG-IR-24-535)
- Block vulnerable ThrottleStop.sys 3.0.0.0 and renamed copies via driver blocklist (CVE-2025-7771)
Immediate actions
- Hunt for ThrottleBlood.sys / ThrottleStop.sys driver loads, All.exe, Allpatch2.exe and PowerRun.exe, and for the .7mtzhh extension and README-GENTLEMEN.txt
- Alert on net group/localgroup /add to Administrators, Domain Admins, Enterprise Admins, Schema Admins, DnsAdmins and Hyper-V Administrators and review whether the added account later logged in
- Alert on new or modified executables on NETLOGON/SYSVOL and on new GPOs creating immediate scheduled tasks
- Audit FortiGate/VPN admin interfaces and accounts for unexpected logins and rotate credentials
Workarounds
- Restrict FortiGate administrative interface access to trusted management networks
- Restrict domain controller share write access and monitor NETLOGON changes
Longer-term hardening
- Enable EDR tamper protection, agent self-protection and password-protected uninstall
- Enforce Microsoft vulnerable driver blocklist / HVCI and driver signature verification, alerting on vulnerable driver loads
- Remove direct internet exposure of RDP and admin interfaces; require MFA and segment management networks
- Use just-in-time privileged access with automatic de-escalation; restrict unapproved remote-access tools such as AnyDesk
- Keep offline, immutable backups for Veeam and database servers; block execution from Temp and Downloads directories
CVEs associated with The Gentlemen RaaS
Weaknesses (CWE) in The Gentlemen RaaS
Timeline of The Gentlemen RaaS
- CVE-2024-55591 (FortiOS/FortiProxy authentication bypass, later reported as a Gentlemen initial-access vector) is published and added to CISA KEV with a remediation due date of 2025-01-21.
- Earliest confirmed victim, a Peruvian steel manufacturer, compromised (Hive Pro; single-source).
- CVE-2025-7771 (ThrottleStop.sys arbitrary physical memory access) is published; Kaspersky had documented AV-killer abuse of the driver.
- The Gentlemen emerges as a data-extortion/RaaS operation in August 2025 (Intel 471, Trend Micro); Trend investigates an intrusion that month. Day is approximate; sources give the month only.
- Trend Micro publishes 'Unmasking the Gentlemen Ransomware' describing BYOVD, GPO manipulation, custom anti-AV tools and WinSCP exfiltration.
- Ampcus Cyber publishes 'Dressed to Encrypt' with defensive recommendations.
- RaaS program advertised on underground forums under the alias 'Zeta88' with a 90/10 affiliate split (Hive Pro; single-source).
- Hive Pro advisory (April 2026; day approximate) counts over 320 publicly listed victims, mostly from early 2026, and notes Linux, NAS, BSD and ESXi lockers.
- Intel 471 publishes a threat hunting case study citing claimed breaches of over 600 organizations in at least 80 countries and a privileged-group-addition hunt.
Sources cited for The Gentlemen RaaS
- Threat Hunting Case Study: The Gentlemen (Intel 471)
- Unmasking the Gentlemen Ransomware (Trend Micro / TrendAI)
- The Gentlemen Ransomware: A Rapidly Scaling RaaS Threat (Hive Pro)
- Dressed to Encrypt: Inside the Gentlemen Ransomware Operations (Ampcus Cyber)
- NVD CVE-2025-7771 (ThrottleStop.sys)
- Kaspersky Securelist: AV killer exploiting ThrottleStop.sys
- Kaspersky advisory K-TechPowerUp-2025-001
- NVD CVE-2024-55591 (FortiOS/FortiProxy auth bypass)
- Fortinet PSIRT FG-IR-24-535
- CISA KEV entry for CVE-2024-55591
Detection coverage for TL-2026-3038
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3038 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-3038
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.