Hunt.io Finds TheGentlemen Ransomware Toolkit on Exposed Proton66 Server

Summary
Hunt.io researchers found an exposed directory on Proton66 containing a TheGentlemen-attributed ransomware toolkit. Mimikatz logs with victim credentials indicate prior use, and scripts show extensive preparation to disable defenses and deploy ransomware.
Key points
- The directory, found on Proton66 infrastructure, contained 126 files across 18 subdirectories; Hunt.io says it analyzed only a portion of the available files.
- Mimikatz output included harvested NTLM hashes and victim usernames, which researchers cite as evidence the tools were used against real targets.
- The toolkit included utilities and scripts for network discovery, privilege escalation, credential theft, defense evasion, remote access, and anti-forensics.
- The 35 KB z1.bat script combines security-product and enterprise-service termination, open SMB share creation, RDP enablement, shadow-copy deletion, and event-log clearing before ransomware deployment.
- Two exposed ngrok authentication tokens and tools including RustDesk provided potential remote-access channels; the article does not establish whether the tokens remain usable.
- The server was last observed active on February 26, 2026; Hunt.io reported the discovery on March 12, 2026.
- The report recommends monitoring for Defender tampering, credential-dumping behavior, mass service changes, event-log clearing, ngrok tunnels, and shadow-copy deletion.
Article Details
- Attack Vectors
- Hunt.io attributed the exposed operational toolkit to a TheGentlemen ransomware affiliate; Mimikatz output containing victim usernames and NTLM hashes supported prior use against live targets. The initial access method was not disclosed.
- Network enumeration utilities and a route-printing script support mapping compromised environments before lateral movement.
- TrustedInstaller token manipulation and UAC disabling support elevated execution and modification of protected security components.
- Overlapping utilities and batch scripts disable endpoint protection through service termination, registry modifications, scheduled-task disabling, and drive-wide exclusions.
- A registry file enables WDigest plaintext credential caching to prepare for Mimikatz extraction from LSASS.
- Two batch scripts establish ngrok TCP tunnels to RDP port 3389; RustDesk provides a separate remote-access mechanism.
- z1.bat creates full-access SMB shares on drives C through K to facilitate ransomware access across compromised networks.
- IFEO debugger redirects on accessibility applications launch a SYSTEM-level command prompt, while RDP enablement and NLA disabling support persistent access.
- Pre-encryption scripts stop enterprise applications and backup services, delete shadow copies, and terminate processes to increase encryption coverage and impede recovery.
- Cleanup scripts clear Windows event logs, delete Recycle Bin contents, and remove RDP connection history.
- Defensive Notes
- Monitor PowerRun execution and unexpected processes running with TrustedInstaller privileges, particularly from non-standard locations.
- Alert on Defender service changes, Defender policy registry modifications, drive-wide exclusions, and bulk security-service termination or disabling.
- Detect LSASS memory access, including Sysmon Event ID 10, and changes to WDigest UseLogonCredential.
- Monitor IFEO debugger modifications affecting sethc.exe, utilman.exe, Magnify.exe, and HelpPane.exe.
- Detect mass SMB share creation granting Everyone full access and anomalous RDP sessions from hosts that do not normally initiate them.
- Block connections to the identified staging server; monitor ngrok tunnel establishment and internal network-scanning patterns.
- Alert on wevtutil-based log clearing, vssadmin shadow-copy deletion, and modifications to EnableLUA.
- Audit Group Policy Objects for unauthorized Defender changes and monitor bulk service configuration changes.
- Use application whitelisting to prevent unauthorized execution from user-writable directories, enable Credential Guard and endpoint tamper protection, and maintain offline immutable backups with tested restoration procedures.
- Prioritize behavioral sequences over individual tool signatures because the toolkit largely consists of legitimate dual-use utilities and established offensive tools.
- The analysis covered only a subset of the directory's files; files not retrieved were not characterized.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 176[.]120[.]22[.]127 | Proton66-hosted server exposing an operational toolkit attributed by Hunt.io to a TheGentlemen ransomware affiliate. |
| URL | hxxp[:]//176[.]120[.]22[.]127 | Unauthenticated HTTP open directory hosting ransomware operator scripts, utilities, and credential-harvesting logs. |
MITRE ATT&CK
T1003.001 · LSASS MemoryMimikatz credential-harvesting logs contain victim NTLM hashes and usernames; enable_dump_pass.reg prepares WDigest plaintext credential storage in LSASS.T1016 · System Network Configuration DiscoveryA command script runs route print to enumerate routing information on a compromised Windows host.T1021.001 · Remote Desktop Protocolrdp.exe supports internal remote connections, while z1.bat enables RDP and disables Network Level Authentication.T1021.002 · SMB/Windows Admin Sharesz1.bat creates SMB shares for drives C through K with Everyone:FULL permissions to support access and propagation across the compromised network.T1046 · Network Service DiscoveryThe toolkit contains SoftPerfect Network Scanner with a license and customized configuration for scanning network services and resources.T1057 · Process DiscoveryPC Hunter inspects running processes, and z.bat uses tasklist to check which security products remain active.T1059.001 · PowerShellThe hybrid batch/PowerShell script manipulates TrustedInstaller execution and Defender settings; z1.bat invokes PowerShell to disable Defender features.T1059.003 · Windows Command ShellBatch scripts automate service destruction, network-share creation, remote-access configuration, and forensic cleanup.T1070.001 · Clear Windows Event Logsclearlog.bat and z1.bat enumerate Windows event log channels and clear them with wevtutil.exe.T1070.002 · Clear Linux or Mac System LogsCleanup scripts delete Terminal Server Client registry entries recording RDP connection history and recreate an empty Servers key.T1070.004 · File DeletionCleanup scripts delete Recycle Bin contents and Default.rdp; the Defender-disabling script deletes scan history.T1082 · System Information DiscoveryPC Hunter variants provide host inspection, including kernel modules, drivers, and startup entries.T1112 · Modify Registrydef1.bat, z1.bat, and enable_dump_pass.reg modify registry settings for security controls, remote access, and credential caching.T1134 · Access Token ManipulationPowerRun and the modified Defender-disabling script use TrustedInstaller token privileges to execute processes and modify protected components.T1219 · Remote Access ToolsRustDesk is included as an additional remote-access channel independent of ngrok and the host's RDP service.T1489 · Service Stopz.bat and z1.bat terminate or disable security, database, Exchange, virtualization, and backup services before ransomware deployment.T1490 · Inhibit System Recoveryz1.bat runs vssadmin.exe Delete Shadows /All /Quiet and disables the VSS service to impede snapshot-based recovery.T1546.008 · Accessibility Featuresz1.bat redirects accessibility applications through IFEO Debugger entries to cmd.exe, enabling SYSTEM-level command prompts from the login screen.T1546.012 · Image File Execution Options Injectionz1.bat sets IFEO Debugger values for sethc.exe, utilman.exe, Magnify.exe, and HelpPane.exe to launch cmd.exe.T1548.002 · Bypass User Account Controlz1.bat sets EnableLUA to 0 to disable UAC, and the hybrid Defender-disabling script includes an elevation chain.T1562.001 · Disable or Modify ToolsMultiple utilities and scripts disable Defender and other endpoint security products through service changes, registry edits, exclusions, and scheduled-task disabling.T1572 · Protocol TunnelingNG1.bat and NG2.bat configure ngrok authentication tokens and establish TCP tunnels to local RDP port 3389.
Threat Actors
Malware
SuperBlackThe hosting choice of Proton66, a provider previously linked to SuperBlack ransomware, WeaXor, and XWorm campaigns, reinforces the infrastructure pattern supporting active ransomware-as-a-service operations.The Gentlemenhosting provider, while pivoting on indicators of compromise published in CyberXTron's report on TheGentlemen ransomware group. The server at 176.120.22[.]127:80 was not a disorganized dump of malware samples. ItWeaXorThe hosting choice of Proton66, a provider previously linked to SuperBlack ransomware, WeaXor, and XWorm campaigns, reinforces the infrastructure pattern supporting active ransomware-as-a-service operations.XWormThe hosting choice of Proton66, a provider previously linked to SuperBlack ransomware, WeaXor, and XWorm campaigns, reinforces the infrastructure pattern supporting active ransomware-as-a-service operations.
Vendors
AVG(12 services), Trend Micro (14 services), McAfee (5 services), ESET (2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services), Quick Heal (8 services)ESETSecurity Sophos (14 services), Kaspersky (12 services), Trend Micro (14 services), McAfee (5 services), ESET (2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services), QuickKasperskyEndpoint Security Sophos (14 services), Kaspersky (12 services), Trend Micro (14 services), McAfee (5 services), ESET (2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services),MalwarebytesMicro (14 services), McAfee (5 services), ESET (2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services), Quick Heal (8 services)McAfeeEndpoint Security Sophos (14 services), Kaspersky (12 services), Trend Micro (14 services), McAfee (5 services), ESET (2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services),PandaMcAfee (5 services), ESET (2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services), Quick Heal (8 services)Proton66On March 12, 2026, Hunt.io researchers discovered an exposed open directory on Proton66, a Russian bulletproof hosting provider, while pivoting on indicators of compromise published in CyberXTron's report onProton66 OOOAn open directory hosted at 176.120.22[.]127:80 on the Russian bulletproof hosting provider Proton66 OOO exposes 126 files (140 MB) containing a complete ransomware operator toolkit attributed to a TheGentlemen RaaSQuick Heal(2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services), Quick Heal (8 services)SophosEndpoint Security Sophos (14 services), Kaspersky (12 services), Trend Micro (14 services), McAfee (5 services), ESET (2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services),Sordumand MIMIMI subdirectory, both 458 KB, each tagged with 3 exploit and 10 malware indicators), dControl is Sordum's Defender Control utility. The accompanying dControl.ini reveals pre-configured operational settings:Trend MicroEndpoint Security Sophos (14 services), Kaspersky (12 services), Trend Micro (14 services), McAfee (5 services), ESET (2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services),Webrootservices), Kaspersky (12 services), Trend Micro (14 services), McAfee (5 services), ESET (2 services), Webroot (1 service), AVG (3 services), Malwarebytes (3 services), Panda (5 services), Quick Heal (8 services)
Products
7-ZipRoot-level executables ~120 MB PCHunter variants, PowerTool, ngrok, RustDesk, 7-Zip, unknown binariesCredential Guardwhitelisting to prevent unauthorized tool execution from user-writable directories. Enable Credential Guard to mitigate LSASS-based credential dumping. Maintain offline, immutable backups and regularlyESXimuch larger. In the context of TheGentlemen's documented cross-platform capability (Windows, Linux, ESXi), this likely facilitates reconnaissance or preparation of virtualization infrastructure prior toFirebirdDatabases SQL Server (18+ instances including Veeam, Wolters Kluwer, Optima, PROGID named instances), PostgreSQL, FirebirdHyper-VVirtualization Hyper-V (8 services)IISTomcat versions (5, 6, 7, 8), IBM services, Veeam backup infrastructure, VMware Tools, TeamViewer, IIS, and various enterprise applications:Linuxtypically much larger. In the context of TheGentlemen's documented cross-platform capability (Windows, Linux, ESXi), this likely facilitates reconnaissance or preparation of virtualization infrastructure prior toMicrosoft EdgeBeyond Defender itself, the script also disables Windows SmartScreen (for Windows, Windows Store, and Microsoft Edge), suppresses security notifications, and deletes Defender scan history to remove evidence of priorMicrosoft Exchange ServerBeyond security products, z1.bat systematically stops and disables 30+ Microsoft Exchange services (covering the full Exchange stack from transport to mailbox to unified messaging), Oracle databases (multiple instancesMicrosoft Windows64_bit_new/ 7 MB / 18 files Primary toolkit: core tools for 64-bit Windows targetsMySQLfrom transport to mailbox to unified messaging), Oracle databases (multiple instances including BIEE), MySQL, multiple Tomcat versions (5, 6, 7, 8), IBM services, Veeam backup infrastructure, VMware Tools,OracleExchange services (covering the full Exchange stack from transport to mailbox to unified messaging), Oracle databases (multiple instances including BIEE), MySQL, multiple Tomcat versions (5, 6, 7, 8), IBMPostgreSQLDatabases SQL Server (18+ instances including Veeam, Wolters Kluwer, Optima, PROGID named instances), PostgreSQL, FirebirdRustDeskRoot-level executables ~120 MB PCHunter variants, PowerTool, ngrok, RustDesk, 7-Zip, unknown binariesSQL ServerDatabases SQL Server (18+ instances including Veeam, Wolters Kluwer, Optima, PROGID named instances), PostgreSQL, FirebirdTeamViewerMySQL, multiple Tomcat versions (5, 6, 7, 8), IBM services, Veeam backup infrastructure, VMware Tools, TeamViewer, IIS, and various enterprise applications:Tomcatto mailbox to unified messaging), Oracle databases (multiple instances including BIEE), MySQL, multiple Tomcat versions (5, 6, 7, 8), IBM services, Veeam backup infrastructure, VMware Tools, TeamViewer, IIS, andUniFiOther UniFi network controllerVeeamDatabases SQL Server (18+ instances including Veeam, Wolters Kluwer, Optima, PROGID named instances), PostgreSQL, FirebirdVMware ToolsBIEE), MySQL, multiple Tomcat versions (5, 6, 7, 8), IBM services, Veeam backup infrastructure, VMware Tools, TeamViewer, IIS, and various enterprise applications:Windows DefenderA 2 MB utility (tagged with 3 malware indicators) providing granular control over Windows Defender configuration, including ASR (Attack Surface Reduction) rules, exclusion paths, cloud protection levels, and individualWindows SmartScreenBeyond Defender itself, the script also disables Windows SmartScreen (for Windows, Windows Store, and Microsoft Edge), suppresses security notifications, and deletes Defender scan history to remove evidence of prior
Tools
ConfigureDefenderand individual protection features. Unlike dControl which functions as a binary on/off toggle, ConfigureDefender allows surgical modification of specific features; for example, disabling real-time protection whileDefender ControldControl.exe: Defender Control v2.1ExcToolDefense Evasion T1562.001 Impair Defenses dControl, def1.bat, z.bat, z1.bat, ConfigureDefender, ExcToolHunt.io AttackCapture"From Access to Encryption in Hours: TheGentlemen Ransomware Playbook Exposed." Using Hunt.io's AttackCapture⢠IOC search, we queried the published indicators against our open directory dataset. The searchMimikatzMimikatz output logs within the directory contain harvested NTLM hashes and victim usernames, confirming the tools were actively used against real targets, not merely staged.NgrokTwo ngrok authentication tokens are exposed in cleartext, providing potential pivot points for tracking additional operator infrastructure.PC HunterThe directory contained four variants of PC Hunter, a kernel-level system inspection tool originally designed for rootkit detection:PowerRun64_bit_new/PowerRun/ 865 KB / 4 files Privilege escalation utility with configurationPowerToolRoot-level executables ~120 MB PCHunter variants, PowerTool, ngrok, RustDesk, 7-Zip, unknown binariesrdp.exerdp.exe, a compact RDP utility for establishing lateral movement connections within the compromised network. Its presence alongside the external access tools (ngrok, RustDesk) suggests it serves a different purpose:SoftPerfect Network Scannerat 119 KB, indicating customized scan profiles), and an OUI lookup table (oui.txt at 1 MB). SoftPerfect Network Scanner is a legitimate commercial tool for network discovery that provides rapid scanning of IPSysmonThis removes Security, System, Application, and all specialized logs including PowerShell, Sysmon (if present), and Windows Defender operational logs.Toggle Defenderis the most technically sophisticated defense evasion tool in the toolkit. It is based on AveYo's "Toggle Defender" tool, modified for offensive use, and operates as a hybrid batch/PowerShell script that escalates