PULSE NAME
An Overview of The Gentlemen's TTPs
WHITE The Gentlemen AlienVault 2026-03-20 Modified: 2026-03-20
16
IOCs
MEDIUM VOLUME
This intelligence report provides a comprehensive analysis of The Gentlemen, a ransomware group known for its sophisticated tactics, techniques, and procedures (TTPs). The group exploits vulnerabilities in FortiOS/FortiProxy, maintains a database of compromised devices, and employs advanced defense evasion techniques. Their initial access methods include exploiting public-facing applications and brute-force attacks. The Gentlemen utilize various execution, persistence, and privilege escalation techniques, while also focusing on credential access and lateral movement. The group's impact includes data encryption and inhibiting system recovery. The report highlights the group's ongoing efforts to improve their ransomware capabilities by reverse-engineering other malware samples.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
The Gentlemen Babuk - S0638 Babyk Vasa Locker Qilin LockBit 5.0 Medusa
Indicators of Compromise (16)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2023-27532 2026-03-20
CVE CVE-2024-37085 2026-03-20
CVE CVE-2024-55591 2026-03-20
CVE CVE-2025-32463 2026-03-20
FileHash-MD5 4200b46a93c6ab059e2b34ce200c4a5b 2026-03-20
FileHash-MD5 42c062d6299ca9f76554441a29429404 2026-03-20
FileHash-MD5 8901ce810f999f79c51c4d4f6c93fe6b 2026-03-20
FileHash-MD5 adf675ffc1acb357f2d9f1a94e016f52 2026-03-20
FileHash-MD5 d65c293efb5e6d033c83b2ac472bf0cb 2026-03-20
FileHash-MD5 efd5366eb7473d6f7fb97ec7ac59f09d 2026-03-20
FileHash-SHA1 2cd15d5d4cc58d06cfb6be5eabc681925d0ce5ce 2026-03-20
FileHash-SHA1 42bcc743c71a9ea083c1c750a398110582796762 2026-03-20
FileHash-SHA256 2834114ff7e487c4ca3f50ca39f7d652dea1be98f885c388f01b6ff35309307b 2026-03-20
FileHash-SHA256 3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235 2026-03-20
FileHash-SHA256 51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2 2026-03-20
IPv4 194.87.31.69 2026-03-20