The attackers keep their tools in C:\PerfLogs. It is a real Windows directory, meant for performance monitoring logs, and almost nobody watches it. Sophos analysts found data theft utilities, discovery scanners, vulnerable drivers and antivirus killers staged there across multiple intrusions by the same crew.
Sophos Counter Threat Unit researchers examined 15 separate incidents involving The Gentlemen ransomware-as-a-service operation, run by a group the team tracks as GOLD SHERWOOD, and found a repeatable affiliate playbook rather than improvisation. The median time between the first observed post-compromise activity and ransomware deployment was about two days. The fastest was under 24 hours.
The operation has grown fast. It started in mid-2025 as a double-extortion scheme and recruited affiliates on the RAMP underground forum with an unusually generous 90/10 ransom split. Fewer than 20 victim names went up per month through the rest of 2025; by early 2026 the monthly average was above 75. Those are the crew's own claims, not confirmed breaches.
Stolen VPN logins and no second factor
In a February incident, the attacker simply logged in. They used compromised credentials against a Fortinet SSL VPN service from an address geolocated to the Netherlands, with no multi-factor authentication in the way, then opened several more sessions from different foreign addresses inside the hour. CTU researchers found artifacts in other intrusions suggesting Fortinet endpoints may have been exploited for initial access, but say the telemetry could not confirm it. From there the attacker moved by Remote Desktop Protocol to file servers and domain controllers on valid credentials, added its own accounts to the local Administrators group and to Domain Admins with native Windows commands, and in one case reset two administrator passwords, which got in the way of the responders trying to evict them.
Killing the alarm before setting the fire
The operators supply affiliates with a suite of tools that abuse vulnerable drivers to shut down endpoint detection, and CTU saw several variants, including three different builds deployed in a single incident against one endpoint agent. One open-source killer was new to this operation, dropping a vulnerable driver before targeting Sophos processes; existing countermeasures caught it. Elsewhere the attackers took the blunt route, excluding the entire C: drive from Windows Defender scanning with one PowerShell command, disabling real-time monitoring through a policy registry value, or pushing a kill script to every host from the domain controller's NETLOGON share. CTU counted over 200 variations of commands disabling backup and replication services, consistently run immediately before encryption, and in one incident the attacker wiped the Application, System and Security event logs across multiple hosts.
Exfiltration that changed tools mid-job
Rclone was the preferred theft tool, seen in five of the 15 incidents, run with filter files and age limits to keep volume and noise down. One intrusion shows the operator working interactively: an Rclone copy off a mapped drive, a pivot to the Restic backup utility about 25 minutes later with changing include and exclude rules, then the MinIO client to push data into object storage. The lockers are Go binaries that can be pushed domain-wide through NETLOGON, leaving a six-character file extension and a note named README-GENTLEMEN.txt.
Watch PerfLogs, and turn MFA on
Sophos recommends enforcing multi-factor authentication on VPN and remote access, patching internet-facing firewalls promptly, restricting and monitoring administrative group changes, limiting RDP exposure, and alerting on registry, firewall and Defender exclusion changes. Add execution from C:\PerfLogs and the exfiltration tools named above. Published indicators include an antivirus killer masquerading as acronis.exe, SHA-256 a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c0efd.
Aside from those killers and the lockers, CTU researchers detected no malware at all in these intrusions. That is the real finding: everything else was a legitimate tool, a native utility or a valid credential, which is why the defences that work here are about identity and administrative control rather than signatures. The analysis was published by the Sophos Counter Threat Unit Research Team, and it fills in the tradecraft behind a crew we have tracked as it armed affiliates with custom EDR killers and then lost the top leak-site spot back to Qilin. Our profile of The Gentlemen has the wider picture.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.