The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

The Gentlemen ransomware operation is moving from access to full network encryption at striking speed. In some intrusions, attackers disabled defenses and recovery services before deploying ransomware in less than 24 hours across enterprises.

The group runs as a ransomware-as-a-service operation, meaning affiliates can strike organizations they can reach. Its double-extortion approach adds pressure: files are stolen first, then encrypted, leaving victims facing a data leak as well as operational disruption.

Analysts at Sophos examined 15 incidents linked to the group, tracked as GOLD SHERWOOD, and found a repeatable playbook.

The findings show how a small window after a suspicious login can quickly become a business-wide outage.

Sophos said in a report shared with Cyber Security News (CSN) that initial access appears to come from exposed firewall management interfaces, unpatched devices, or stolen VPN credentials.

A Fortinet SSL VPN account without multi-factor authentication gave the intruder a foothold, underlining why FortiOS authentication bypass vulnerability remains a serious concern for exposed infrastructure.

The Gentlemen Ransomware Hackers Disable EDR

Once inside, the affiliates moved across systems using legitimate domain credentials and Remote Desktop Protocol.

They placed their toolkit in a trusted Windows location that is often overlooked, then mapped systems, data stores, and backup infrastructure before the visible stage of the attack began.

They increased their control by changing administrator passwords, adding accounts to privileged groups, and enabling remote desktop access.

In several cases, they created firewall rules to allow outside RDP connections, providing a fallback route if the originally compromised VPN session was lost.

Next, they removed obstacles to encryption. Attackers used custom and publicly available utilities, including vulnerable drivers, to terminate antivirus and endpoint detection and response processes.

They also weakened Windows Defender by adding broad scan exclusions or changing policy settings. A recent report on ransomware operators disable EDR shows the broader pattern of crews stopping security and backup software before spreading across a network.

In this campaign, the effort was deliberate rather than incidental, with multiple approaches used when one method failed. Backup services were then disabled, often immediately before encryption.

The Gentlemen ransom note sample (Source - Sophos)
The Gentlemen ransom note sample (Source – Sophos)

They targeted recovery and backup-agent services, making it harder for teams to restore systems. In one intrusion, they also cleared Application, System, and Security event logs, obscuring the evidence responders need to trace the breach.

Rapid Encryption Playbook

Before locking systems, the group copied selected files with legitimate transfer tools. It commonly focused on newer data and used filters to reduce the volume transferred, which can make outbound activity less obvious while still collecting material valuable for extortion.

Affiliates adapted their process. Researchers saw them switch among transfer utilities and object-storage methods as conditions changed.

That flexibility resembles other attacks against remote infrastructure, including Gunra ransomware VPN attacks, where exposed access points can quickly lead to high-impact ransomware activity.

The median interval from first observed post-compromise activity to ransomware deployment was about two days. The shortest observed period was under 24 hours, leaving little room for manual investigation after an attacker gains entry.

The locker was deployed locally, through network shares, or across the domain using centralized logon shares and remote execution.

It encrypted files, assigned a six-character extension, and left a ransom note in affected directories. Although Windows was the only version deployed in the reviewed cases, related builds also support Linux and ESXi environments.

The pace makes prevention and early detection equally important. Organizations should patch internet-facing firewalls and VPN appliances, require MFA for every remote-access account, restrict RDP exposure, and closely review new privileged accounts. The Fortinet security update guidance provides useful context on fixing a flaw tied to the access methods investigated.

Teams should also alert on unusual activity from system staging folders, unfamiliar data-transfer utilities, Windows Defender exclusions, disabled backup services, cleared logs, and attempts to load vulnerable drivers.

Separating backups from ordinary administrator control and testing recovery plans can prevent attackers from turning a single compromised account into a prolonged outage.

Indicators of compromise (IoCs):-

Type Indicator Description
MD5 622b2ca08552535bc142cb815ff9ec16 Sophos-listed threat indicator
SHA-1 f0bc50d2d2838c5294e21cd9bce2f09bf581e508 Sophos-listed threat indicator
SHA-256 a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c Sophos-listed threat indicator
MD5 4741a4976c6abfb3c80c170104518b6e Sophos-listed threat indicator
SHA-1 be8c52474ab79a52af31e3cb2f71638299a0de1d Sophos-listed threat indicator
SHA-256 ddba5b4e7a7ada77d56477e9d41c008f93e81d9a33ed09e77cb2af624f Sophos-listed threat indicator
MD5 738df7ae0097f6bef93d65be5d4a2a26 Sophos-listed threat indicator
SHA-1 c96baab9b7e7ef661921d44d7900f165c794ed25 Sophos-listed threat indicator
SHA-256 1a9291ec869155336bf185d221d655d11c77a55ea0c8ecc0274202f74a9 Sophos-listed threat indicator
MD5 d8691ef15eea27cfefafeeb485286080 Sophos-listed threat indicator
SHA-1 8bca55b3c9bfbdf68c9b6c72a7b1bf1dd6d5e3b2 Sophos-listed threat indicator
SHA-256 3c71537b64487bbf4d1793f72c75d332650d09a77b71e4d884ff15c266a Sophos-listed threat indicator
MD5 b23b653541bd95bdc4da07a0b07b57bf Sophos-listed threat indicator
SHA-1 f0537cbb773ae12100b36731e7c39f5a9d852b14 Sophos-listed threat indicator
SHA-256 50f2cdf16f05da9253fa2d6eb60d5a42da14c02c551c0874c9e953d4119 Sophos-listed threat indicator
SHA-256 bf7a2fb7f7256809dc690213b85f747cef8db7b909caf9783cac181912fb Sophos-listed threat indicator
SHA-256 761ce72420edf5e5531cdbad0e93397d7520cdead825886ca7f75cef76 Sophos-listed threat indicator
MD5 002417da707b93bf5ce3cb26d28005f6 Sophos-listed threat indicator
SHA-1 8732c1ff565828a0bdef514b5dc0dfea40c1d1f2 Sophos-listed threat indicator
SHA-256 81053c2c3be8b7dbf7d5087dba05c940b3ee4fd95524272651c816b72c Sophos-listed threat indicator
SHA-256 7a37acb031cddaa39ad20db0961baa5423ec53f318c49c9275c982507d Sophos-listed threat indicator
MD5 bc4a8d7bbbeb941265dfc954539326c0 Sophos-listed threat indicator
SHA-1 b7cea81e6de895d01d01d20bd6dcfd347940b57f Sophos-listed threat indicator
SHA-256 3a31ec3bf9b7eac6593a723145381f5d0f4ede076c4c8818d949a08f559 Sophos-listed threat indicator
SHA-256 68031d549de399a44bb00614b910106baccef5996623b2f1102352a52a Sophos-listed threat indicator
SHA-1 058c3ff21e79770e4a60937c27b1ede227709248 Sophos-listed threat indicator
SHA-1 9c0b05eb75f971cc25ee979e49b227b86b19e833 Sophos-listed threat indicator
SHA-1 a438ba2122a814320f47a056f04122f81c2ae6c5 Sophos-listed threat indicator
SHA-1 a8ba89e67297642dcc1ae77433ab84e1f27d1792 Sophos-listed threat indicator
MD5 8ea97d01cbf459b94d134d05c54cd33e Sophos-listed threat indicator
SHA-1 5c9bf6b7e4c7dc9b9227ce86e2d271d624c35147 Sophos-listed threat indicator
SHA-256 0be8f415a485b11747bcfd71c9cd9781e090354728f076791ed6845b69e Sophos-listed threat indicator
MD5 07e9f0b8627a95960e79e930fb099e84 Sophos-listed threat indicator
SHA-1 56bee9df5833a637f5c54d5911df98b0812fe643 Sophos-listed threat indicator
SHA-256 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c Sophos-listed threat indicator
SHA-256 ccdde8091d63eaafbe30d9f0482afd245abc10ab16e21ae9254e51e42cb Sophos-listed threat indicator

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours appeared first on Cyber Security News.