# The Gentlemen RaaS: BYOVD AV/EDR Killing (ThrottleBlood.sys / CVE-2025-7771), FortiGate Initial Access and GPO/NETLOGON Ransomware Deployment

> The Gentlemen is a ransomware-as-a-service and data-extortion operation that emerged in 2025 and, per Intel 471, has publicly claimed breaches of over 600 organizations in at least 80 countries. Intrusions start from compromised credentials or exposed FortiGate/VPN admin interfaces, kill AV/EDR with a renamed ThrottleStop driver (ThrottleBlood.sys, CVE-2025-7771) plus All.exe/Allpatch2.exe, exfiltrate with WinSCP, and deploy the locker domain-wide via NETLOGON and Group Policy.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3038
- **ID:** TL-2026-3038
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** The Gentlemen
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2024-55591, CVE-2025-7771

## Description

The Gentlemen emerged in mid-to-late 2025 (Intel 471 and Trend Micro say August 2025; HivePro dates the earliest confirmed victim to 30 June 2025 and the forum advertisement under the alias 'Zeta88' to 12 September 2025). It runs a RaaS-and-affiliate model with dual extortion (Tor leak site plus encryption). Intel 471 reports public claims of over 600 organizations in at least 80 countries across manufacturing, insurance, construction, consumer services, healthcare and financial services, with a focus on Asia-Pacific (notably Thailand) and North America; HivePro counted over 320 listed victims by April 2026. Public claim counts differ between vendors and are unverified.

Initial access is by compromised credentials or internet-exposed VPN/firewall services. In the Trend Micro-investigated intrusion (August 2025), a FortiGate server was directly reachable from the internet and a FortiGate administrative account was compromised; Trend did not confirm the exact vector. HivePro and Ampcus-derived reporting attribute FortiGate access to exploitation of CVE-2024-55591 (FortiOS/FortiProxy authentication bypass, CISA KEV) and claim a curated database of roughly 14,700 compromised FortiGate devices and 969 validated brute-forced VPN credentials; this is secondary, single-source reporting. Early discovery used Advanced IP Scanner, Nmap 7.97 and a 1.bat script that ran net user/net group queries against 60+ accounts (admin.it, fortigate, Domain Admins, Enterprise Admins, itgateadmin).

Defense evasion is the group's signature. It loads a signed vulnerable driver, ThrottleStop.sys renamed ThrottleBlood.sys (CVE-2025-7771: two IOCTLs expose unrestricted physical memory access, allowing kernel patching and ring-0 code execution), paired with All.exe (both dropped in %USERPROFILE%\Downloads) to terminate protected AV/EDR processes. PowerRun.exe is abused to escalate privileges and stop security services. A later, per-environment variant, Allpatch2.exe, targets the specific security-agent components found during reconnaissance. Windows Defender is disabled with Set-MpPreference/Add-MpPreference and registry changes; RestrictSendingNTLMTraffic, DisableRestrictedAdmin and the RDP SecurityLayer value are modified, and the firewall is changed to keep RDP enabled for negotiation.

Lateral movement uses PsExec, with possible PuTTY/SSH, and AnyDesk provides persistent remote access. Data is staged in C:\ProgramData\data, accessed over WebDAV (davclnt.dll) from internal shares, and exfiltrated with WinSCP (C:\ProgramData\WinSCP.exe). Group Policy tools (gpmc.msc, gpme.msc) and encoded PowerShell ((Get-ADDomain).PDCEmulator) are used against the primary domain controller, and the password-protected locker (--password, 8 bytes; optional --path) is placed on the domain NETLOGON share. Intel 471 also highlights privileged-group manipulation (net group/localgroup /add) as a behavioral hunt opportunity.

Impact: files are encrypted with the .7mtzhh extension and README-GENTLEMEN.txt is dropped. The locker stops backup, database and security services (Veeam, Acronis, SQL Server, Oracle, MySQL, PostgreSQL, SAP, Exchange, Sophos, Docker, Backup Exec, vmms), kills 100+ processes, deletes shadow copies (vssadmin/wmic), clears Security/Application/System event logs, deletes Prefetch, RDP logs and Defender support files, and drops a {filename}.exe.bat self-delete script. HivePro additionally reports Go-based Windows/Linux/NAS/BSD lockers and a C-based ESXi locker, X25519 + XChaCha20 hybrid encryption, Cobalt Strike and SystemBC use, and a 90/10 affiliate split; these come from a single source. Static indicators (file names, extension, note name) decay quickly, so behavior-based detection of BYOVD driver loads, mass service stops, NETLOGON writes and privileged-group additions is recommended.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078.002 Valid Accounts: Domain Accounts
- T1133 External Remote Services
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1098 Account Manipulation
- T1219 Remote Access Tools
- T1484.001 Domain or Tenant Policy Modification: Group Policy Modification
- T1685 Disable or Modify Tools
- T1686 Disable or Modify System Firewall
- T1685.005 Clear Windows Event Logs
- T1112 Modify Registry
- T1018 Remote System Discovery
- T1046 Network Service Discovery
- T1087.002 Account Discovery: Domain Account
- T1069.002 Permission Groups Discovery: Domain Groups
- T1021.002 Remote Services: SMB/Windows Admin Shares
- T1570 Lateral Tool Transfer
- T1074.001 Data Staged: Local Data Staging
- T1039 Data from Network Shared Drive
- T1048.001 Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol
- T1489 Service Stop
- T1490 Inhibit System Recovery

## Sources

- [Threat Hunting Case Study: The Gentlemen (Intel 471)](https://www.intel471.com/blog/threat-hunting-case-study-the-gentlemen)
- [Unmasking the Gentlemen Ransomware (Trend Micro / TrendAI)](https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html)
- [The Gentlemen Ransomware: A Rapidly Scaling RaaS Threat (Hive Pro)](https://www.hivepro.com/threat-advisory/the-gentlemen-ransomware-a-rapidly-scaling-raas-threat)
- [Dressed to Encrypt: Inside the Gentlemen Ransomware Operations (Ampcus Cyber)](https://www.ampcuscyber.com/shadowopsintel/inside-the-gentlemen-ransomware-operations/)
- [NVD CVE-2025-7771 (ThrottleStop.sys)](https://nvd.nist.gov/vuln/detail/CVE-2025-7771)
- [Kaspersky Securelist: AV killer exploiting ThrottleStop.sys](https://securelist.com/av-killer-exploiting-throttlestop-sys/117026/)
- [Kaspersky advisory K-TechPowerUp-2025-001](https://github.com/klsecservices/Advisories/blob/master/K-TechPowerUp-2025-001.md)
- [NVD CVE-2024-55591 (FortiOS/FortiProxy auth bypass)](https://nvd.nist.gov/vuln/detail/CVE-2024-55591)
- [Fortinet PSIRT FG-IR-24-535](https://fortiguard.fortinet.com/psirt/FG-IR-24-535)
- [CISA KEV entry for CVE-2024-55591](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55591)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3038
