logo

The Gentlemen Ransomware Uses 21 Remote Execution Techniques to Encrypt Entire Networks

ID: 7f0f006c-1878-594b-8088-cd7d9f9f2aeb

STIX ID: report--7f0f006c-1878-594b-8088-cd7d9f9f2aeb

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-07-06

Date Updated: 2026-07-06

Author: Tushar Subhra Dutta

...
...

**Executive summary:** The Gentlemen is a Go-based ransomware-as-a-service observed since mid-2025 that combines strong hybrid encryption (Curve25519 + XChaCha20) with a self‑spreading worm engine (triggered by a --spread flag), abusing hidden SMB shares and tools like PsExec to attempt up to 21 remote execution techniques per target; it disables defenses, deletes Volume Shadow Copies, and uses double extortion across multiple sectors worldwide, with indicators including the .umc16h extension and README-GENTLEMEN.txt ransom note.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.