Gentlemen Ransomware — Malware Profile
Gentlemen Ransomware is the cross-platform encryptor used by The Gentlemen ransomware-as-a-service operation, with lockers for Windows, Linux and ESXi written in Go and C; the Windows build is a 64-bit Go executable obfuscated with Garble. It encrypts files using per-file ephemeral Curve25519 keys with the XChaCha20 stream cipher and drops a README-GENTLEMEN.txt ransom note alongside a gentlemen.bmp wallpaper; the sample Microsoft analysed appended the extension .umc16h. Microsoft describes aggressive self-propagation, with the encryptor staging its binary on a hidden SMB share and attempting 21 remote execution operations per target host across techniques including PsExec, WMIC, scheduled tasks, Windows services and PowerShell remoting. Deployments pair it with heavy defence evasion — NTDLL unhooking, ETW patching and custom tools named EDRStartupHinder, gfreeze and glinker — and Microsoft tracks the operators behind it as Storm-2697.
IntelFusions coverage
- The Gentlemen ransomware lists Colombia's Ecopetrol and a US Navy command 2026-07-19
- Gentlemen ransomware ends Qilin's 13-month reign on top 2026-08-02
- Colombia links a Remcos spyware case to Blind Eagle hackers 2026-08-03
- The Gentlemen ransomware dumps nearly 20 victims in a single day 2026-07-17
- New WhiteLock ransomware kills remote tools to block recovery 2026-07-08
- Colombia warns on Gentlemen ransomware as 30 victims land in a day 2026-07-26
- Gentlemen ransomware gang builds custom backdoor and stealthy network spying 2026-06-29
- The Gentlemen ransomware lures affiliates with rare 90 percent payouts 2026-07-11
- Gentlemen ransomware crew names 41 victims in a single day 2026-07-04
- Gentlemen ransomware encrypts within two days of break-in 2026-09-01