{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/actors/the-gentlemen/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["The Gentlemen"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FortiGate","Veeam Backup \u0026 Replication","SAP","Oracle Database","MySQL","AnyDesk"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Fortinet","Veeam","SAP","Oracle","Microsoft","AnyDesk"],"content_html":"\u003cp\u003eThe Gentlemen is a ransomware group active since August 2025, primarily targeting critical sectors such as financial services, healthcare, and manufacturing. The group is known for its sophisticated TTPs, including extensive network mapping and deliberate efforts to weaken security tooling before initiating encryption. Their operation relies on a mix of legitimate administrative utilities and custom-loaded drivers to maintain stealth. The group has claimed responsibility for over 600 breaches across 80 countries. Defenders should monitor for post-compromise behaviors, specifically the elevation of accounts into privileged security groups and the abuse of standard Windows domain infrastructure for lateral tool transfer.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is achieved through exploitation of internet-exposed appliances, such as FortiGate VPN/firewall interfaces, or via compromised credentials.\u003c/li\u003e\n\u003cli\u003eInternal reconnaissance is performed using the commodity tool Advanced IP Scanner to map network segments and identify administrative accounts.\u003c/li\u003e\n\u003cli\u003ePrivilege escalation is achieved by executing the PowerRun.exe utility to gain elevated administrative rights.\u003c/li\u003e\n\u003cli\u003eDefense evasion is conducted using a Bring Your Own Vulnerable Driver (BYOVD) technique by loading the signed driver ThrottleBlood.sys.\u003c/li\u003e\n\u003cli\u003eThe attacker forces termination of antivirus and security processes by exploiting the loaded driver with a custom tool identified as All.exe.\u003c/li\u003e\n\u003cli\u003ePersistence and lateral movement are maintained using AnyDesk and by creating/elevating accounts into privileged Windows security groups (e.g., Domain Admins).\u003c/li\u003e\n\u003cli\u003eData exfiltration is performed using WinSCP to move sensitive information over encrypted channels.\u003c/li\u003e\n\u003cli\u003eFinal impact is achieved by distributing the ransomware payload via the domain-wide NETLOGON share, causing mass encryption across all joined machines.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe Gentlemen's operations result in severe operational disruption through mass encryption of enterprise environments and the exfiltration of sensitive organizational data. Reported targets include critical services such as hospitals and healthcare networks, as well as financial and manufacturing entities. Impacted systems often require significant recovery efforts, as the group systematically disables backup and database services like Veeam, SAP, Oracle, and MySQL prior to encryption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy Sigma rules to monitor the 'net' utility for additions of accounts to high-privilege groups (Administrators, Domain Admins, etc.) as detailed in the rule below.\u003c/li\u003e\n\u003cli\u003eBaseline and audit changes to privileged group memberships; cross-reference these changes against established change management tickets.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized use of legitimate RMM tools like AnyDesk within the environment.\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering to limit unauthorized WinSCP connections to unknown external infrastructure.\u003c/li\u003e\n\u003cli\u003eHarden the NETLOGON and SYSVOL shares by restricting write access to only verified, necessary administrative service accounts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-11T17:48:26Z","date_published":"2026-08-11T17:48:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-the-gentlemen/","summary":"The Gentlemen ransomware group leverages VPN/firewall exploits to gain initial access, utilizes BYOVD techniques to disable security tools, and propagates ransomware via the NETLOGON share.","title":"The Gentlemen Ransomware Group Activity","url":"https://feed.craftedsignal.io/briefs/2026-08-the-gentlemen/"}],"language":"en","title":"CraftedSignal Threat Feed - The Gentlemen","version":"https://jsonfeed.org/version/1.1"}