The Gentlemen Ransomware Uses 21 Remote Execution Techniques to Encrypt Entire Networks
ID: 7f0f006c-1878-594b-8088-cd7d9f9f2aeb
STIX ID: report--7f0f006c-1878-594b-8088-cd7d9f9f2aeb
Feed Name: cybersecurityNews.com
**Executive summary:** The Gentlemen is a Go-based ransomware-as-a-service observed since mid-2025 that combines strong hybrid encryption (Curve25519 + XChaCha20) with a self‑spreading worm engine (triggered by a --spread flag), abusing hidden SMB shares and tools like PsExec to attempt up to 21 remote execution techniques per target; it disables defenses, deletes Volume Shadow Copies, and uses double extortion across multiple sectors worldwide, with indicators including the .umc16h extension and README-GENTLEMEN.txt ransom note.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
