The Gentlemen is a ransomware group using dual-extortion by abusing legitimate utilities to encrypt and exfiltrate data.
Analyst brief
The Gentlemen is a ransomware group employing a dual-extortion strategy, encrypting sensitive data and exfiltrating critical business information to pressure victims. They primarily target medium to large organizations across various sectors, particularly in the Asia-Pacific region. Their key TTPs include abusing legitimate utilities like PowerRun.exe for privilege escalation, using custom-built tools for defense evasion, and applying flexible encryption methods based on file size. Defenders should focus on detecting abnormal use of legitimate system tools, lateral movement within networks, and signs of data exfiltration.
The Gentlemen
unknown
The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure victims into paying ransoms. Their operations leverage advanced techniques such as abusing legitimate utilities like PowerRun.exe for privilege escalation, using custom-built tools for defense evasion, and employing flexible encryption methods based on file size. The group targets medium to large organizations across various sectors, particularly in the Asia-Pacific region, and has demonstrated a high level of technical maturity and operational discipline. Their activities include systematic compromise of enterprise environments, mass account enumeration, and the use of encrypted channels for data exfiltration.