The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
ID: 3467d14c-9967-5adf-8264-bbd1de041ac1
STIX ID: report--3467d14c-9967-5adf-8264-bbd1de041ac1
Feed Name: Microsoft Security
Threat Score
**Executive summary:** Microsoft Threat Intelligence analyzes The Gentlemen ransomware RaaS (Storm-2697), a Go-built, Garble-obfuscated encryptor that uses per-file ephemeral Curve25519 ECDH keys with XChaCha20, implements double extortion, aggressively disables defenses, and can self-propagate across networks via 21 lateral techniques; the report provides technical details, IOCs, detections, hunting queries, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
