logo

License to Encrypt: “The Gentlemen” Make Their Move

ID: 444f89a9-26d3-5ced-b235-b3d48e7f1dde

STIX ID: report--444f89a9-26d3-5ced-b235-b3d48e7f1dde

Feed Name: Cybereason Blog

Threat Score
80/100

Date Published: 2025-11-18

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason assesses 'The Gentlemen' as an emergent (circa July 2025) and technically advanced ransomware RaaS operation that uses dual‑extortion, cross‑platform lockers (Windows/Linux/ESXi), robust encryption (XChaCha20/Curve25519), automated persistence and propagation mechanisms (WMI, PowerShell Remoting, schtasks, registry autoruns), and affiliate support; the report includes static/behavioral analysis of a Go-based Windows sample (SHA256 provided), PowerShell and anti-forensic activity, kill‑lists, registry usage, mapped IOCs, ATT&CK mappings, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.