The Gentlemen Kill Your Security First. Then They Encrypt Everything
- The Mess: The Gentlemen ransomware affiliates are moving from initial access to network-wide encryption in less than 24 hours in some attacks. Before deploying ransomware, they disable security tools, weaken endpoint defenses and shut down backup services.
- The Damage: By the time encryption starts, the victim may already have lost endpoint visibility, recovery options and control of privileged systems.
- The Fix: Enforce MFA on remote access, remove exposed management interfaces, patch internet-facing devices, protect backups from administrative compromise and monitor aggressively for sudden security-tool and backup-service shutdowns.
The ransomware does not start with encryption.
It starts by making sure nobody can stop it.
The Gentlemen ransomware operation has been observed moving from initial access to full-scale encryption in less than 24 hours during some enterprise intrusions.
That speed changes the entire incident-response equation.
There is no comfortable three-day dwell time.
No long reconnaissance period.
No guarantee that the SOC will have hours to investigate an unusual login before the real damage begins.
According to recent incident analysis, The Gentlemen affiliates first work to establish control over the environment. They move through the network using legitimate credentials and remote access mechanisms, identify valuable systems and map backup infrastructure.
Then they start removing the safety nets.
Security software is one of the first targets.
Attackers have been observed weakening Windows Defender protections through policy changes and broad exclusions. They also attempt to disable endpoint security processes and other defensive tooling before the ransomware deployment reaches its final stage.
That is not an accidental side effect of the intrusion.
It is part of the workflow.
A ransomware operation becomes much easier when the software designed to detect it has already been silenced.
Backups come next.
The attackers identify backup infrastructure and disable recovery services shortly before encryption.
That timing matters.
If defenders discover the attack after ransomware begins, but the backups have already been disabled or compromised, the victim may find that the normal recovery plan exists only on paper.
Then comes encryption.
The Gentlemen is not a small Windows-only locker.
Microsoft has documented the operation as a ransomware-as-a-service platform tracked as Storm-2697. The ransomware ecosystem includes support for multiple enterprise environments, including Windows, Linux and ESXi targets.
That gives affiliates options.
Corporate networks rarely consist of one operating system.
A modern ransomware attack can move through Windows infrastructure, target Linux servers, reach NAS devices and eventually hit virtualization platforms.
The Gentlemen was built for that reality.
The operation also uses the ransomware-as-a-service model.
The core operators provide the platform.
Affiliates obtain access to victim environments and carry out the attacks.
That model allows the operation to scale without requiring one central group to personally break into every company it attacks.
Check Point Research has described The Gentlemen as a rapidly growing ransomware-as-a-service operation and documented affiliate activity involving SystemBC, a proxy malware used to create covert SOCKS5 tunnels and deliver additional payloads.
The attack chain therefore does not need to begin with a sophisticated zero-day.
Recent reporting indicates that affiliates can obtain initial access through familiar failures:
exposed management interfaces,
unpatched internet-facing devices,
and stolen VPN credentials.
In one documented case, a Fortinet SSL VPN account without multi-factor authentication provided an entry point.
That is the uncomfortable part.
The initial compromise can be ordinary.
The impact is not.
Once inside, the attackers can change administrator passwords, create or modify privileged accounts, enable remote access and move across systems before defenders understand that the first suspicious login was the beginning of a ransomware incident.
The clock is running from that moment.
And according to the latest analysis, it may reach zero in less than a day.
The group also combines encryption with data theft.
That gives attackers a second weapon.
Even if a victim restores systems from backups, stolen information can still be used for extortion.
Pay for the decryption key.
Or pay to prevent publication.
Or deal with both problems.
That double-extortion model has become standard ransomware business logic, but The Gentlemen adds pressure by compressing the time between access and impact.
For defenders, the most useful warning signs may therefore appear before the ransomware itself.
A privileged account suddenly enabling Remote Desktop.
Security exclusions appearing on multiple endpoints.
Backup services stopping unexpectedly.
Administrator passwords changing.
New privileged accounts.
Unexpected remote administration tools.
Those events should not be treated as isolated anomalies.
Together, they can be the opening stages of an attack that is already moving toward encryption.
The old assumption that ransomware gives defenders plenty of time is becoming dangerous.
The attackers know exactly what security teams rely on.
Detection.
Endpoint protection.
Backups.
Administrative access controls.
They remove those pieces first.
Then they encrypt what is left.
Bugstoday’s take: The scary part about The Gentlemen is not the ransomware binary. Plenty of criminals can encrypt files. The real problem is the preparation. Kill the EDR. Disable the backups. Take control of privileged accounts. Then start encrypting before defenders have finished their first incident-response meeting. If your security strategy assumes ransomware gives you days to react, attackers have already updated their schedule.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- Microsoft Threat Intelligence — The Gentlemen Ransomware: Dissecting a Self-Propagating Go Encryptor
- Check Point Research — DFIR Report: The Gentlemen & SystemBC
- Unit 42 — The Ruthless Rise of The Gentlemen Ransomware
- Cyber Security News — The Gentlemen Disable EDR and Backups Before Encrypting Networks
- FortiGuard Labs — The Gentlemen Ransomware Threat Actor




