Published on September 3, 2026

The Gentlemen Ransomware Disables EDR and Backup Services Before Encrypting Networks in Under 24 Hours


Severity

High

Detail

Researchers have reported that the Gentlemen ransomware operation, tracked by Sophos as GOLD SHERWOOD, is conducting rapid ransomware attacks that can progress from initial compromise to full network encryption in less than 24 hours. The group operates under a Ransomware-as-a-Service (RaaS) model, allowing affiliates to conduct attacks using the ransomware platform against a broad range of organizations.

The threat actor employs a double-extortion strategy, where sensitive data is exfiltrated prior to encryption. Victims are subsequently pressured to pay a ransom to both restore access to encrypted systems and prevent the public release of stolen information. Sophos analyzed 15 incidents associated with the group and identified a consistent attack methodology involving the compromise of exposed remote access infrastructure, privilege escalation, defense evasion, data theft, and rapid ransomware deployment.

The findings highlight how quickly a successful compromise can escalate into a large-scale operational disruption, significantly reducing the time available for defenders to detect and contain malicious activity.

How?

Initial access was primarily obtained through exposed firewall administration interfaces, unpatched internet-facing devices, or stolen VPN credentials. In several incidents, attackers gained access through Fortinet SSL VPN accounts that lacked multi-factor authentication.

After gaining access, the attackers moved laterally using legitimate domain credentials and Remote Desktop Protocol (RDP). They staged tools in trusted Windows directories, conducted reconnaissance to identify critical servers, backup infrastructure, and valuable data repositories, then expanded control across the environment.

The attackers elevated privileges by modifying administrator passwords, creating new privileged accounts, adding users to administrative groups, and enabling remote desktop access. Some intrusions also involved creating firewall rules to permit external RDP connections, ensuring continued access if the original VPN session was lost.

Prior to ransomware deployment, the group focused on disabling security controls and recovery mechanisms. Attackers used custom tools and publicly available utilities, including vulnerable drivers, to terminate antivirus and Endpoint Detection and Response (EDR) processes. Windows Defender protections were weakened through policy modifications and the addition of extensive scan exclusions.

The attackers then disabled backup and recovery services, reducing the victim’s ability to restore encrypted systems. In some cases, event logs including Application, System, and Security logs were cleared to hinder forensic investigations and incident response efforts.

Before encryption, selected files were exfiltrated using legitimate file transfer tools and cloud storage methods. Affiliates adapted their data theft techniques depending on environmental conditions, allowing them to maintain operational flexibility while minimizing detection.

The median dwell time observed by Sophos was approximately two days, although the shortest observed attack reached ransomware deployment in less than 24 hours. The ransomware was distributed locally, via network shares, or through centralized domain resources and remotely executed across multiple systems. Affected files were encrypted and assigned a six-character extension while ransom notes were dropped throughout the environment.

Conclusion

The Gentlemen ransomware operation demonstrates how threat actors continue to reduce the time between initial access and ransomware deployment while actively disrupting defensive and recovery capabilities. By exploiting exposed remote access services, leveraging legitimate administrative tools, disabling EDR solutions, and targeting backup infrastructure, attackers can rapidly achieve widespread impact across enterprise environments.

The group’s deliberate focus on defense evasion, data exfiltration, and backup disruption significantly increases recovery challenges for affected organizations. Organizations should prioritize patching internet-facing systems, enforcing MFA for all remote access services, restricting RDP exposure, monitoring for unauthorized privileged account changes, and alerting on attempts to modify security controls, disable backup services, or clear Windows event logs.

Source

https://cybersecuritynews.com/the-gentlemen-ransomware/