Gentlemen Ransomware — Malware Profile

Gentlemen Ransomware is the cross-platform encryptor used by The Gentlemen ransomware-as-a-service operation, with lockers for Windows, Linux and ESXi written in Go and C; the Windows build is a 64-bit Go executable obfuscated with Garble. It encrypts files using per-file ephemeral Curve25519 keys with the XChaCha20 stream cipher and drops a README-GENTLEMEN.txt ransom note alongside a gentlemen.bmp wallpaper; the sample Microsoft analysed appended the extension .umc16h. Microsoft describes aggressive self-propagation, with the encryptor staging its binary on a hidden SMB share and attempting 21 remote execution operations per target host across techniques including PsExec, WMIC, scheduled tasks, Windows services and PowerShell remoting. Deployments pair it with heavy defence evasion — NTDLL unhooking, ETW patching and custom tools named EDRStartupHinder, gfreeze and glinker — and Microsoft tracks the operators behind it as Storm-2697.

IntelFusions coverage

Read the full analysis on IntelFusions