logo

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

ID: 3467d14c-9967-5adf-8264-bbd1de041ac1

STIX ID: report--3467d14c-9967-5adf-8264-bbd1de041ac1

Feed Name: Microsoft Security

Threat Score
80/100

Date Published: 2026-05-28

Date Updated: 2026-05-29

Author: Microsoft Threat Intelligence

...
...

**Executive summary:** Microsoft Threat Intelligence analyzes The Gentlemen ransomware RaaS (Storm-2697), a Go-built, Garble-obfuscated encryptor that uses per-file ephemeral Curve25519 ECDH keys with XChaCha20, implements double extortion, aggressively disables defenses, and can self-propagate across networks via 21 lateral techniques; the report provides technical details, IOCs, detections, hunting queries, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.