CTU researchers found that GOLD SHERWOOD’s The Gentlemen RaaS uses a repeatable post-exploitation playbook with rapid privilege escalation, adaptive tool use, and strong defense evasion to deploy ransomware quickly after access. Affiliates rely on compromised credentials, legitimate tools, and exfiltration utilities like Rclone, Restic, and MinIO Client while targeting VPNs, firewalls, backups, and EDR defenses. #TheGentlemen #GOLDSHERWOOD #Rclone #Restic #Cloudflared
Keypoints
- The Gentlemen affiliates often deploy ransomware within 24 hours of post-compromise activity.
- Initial access commonly comes from exposed firewalls, VPN services, and stolen credentials.
- Attackers stage tools in C:PerfLogs and use legitimate utilities to move, discover, and exfiltrate data.
- Rclone, Restic, and MinIO Client are used for adaptive data theft before encryption.
- Defenders should enforce MFA, monitor admin changes, protect backups, and detect EDR-killing activity.
Read More: https://www.sophos.com/en-us/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation