logo

The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours

ID: 135d8c63-3823-5635-ac3d-f7cdf2cdfb14

STIX ID: report--135d8c63-3823-5635-ac3d-f7cdf2cdfb14

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-09-03

Date Updated: 2026-09-16

Author: Tushar Subhra Dutta

...
...

The report describes the Gentlemen ransomware-as-a-service operation (GOLD SHERWOOD) that gains access via exposed firewall/VPN interfaces or stolen credentials, moves laterally using legitimate credentials and RDP, disables EDR and backup services, exfiltrates selected data for double extortion, and rapidly deploys encryption—sometimes in under 24 hours; Sophos analyzed 15 incidents, provides hashes and IoCs, and recommends patching internet-facing appliances, enforcing MFA, restricting RDP, and monitoring for staging and backup-disabling activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.