PULSE NAME
The Gentleman Ransomware | Defense Evasion TTPs Uncovered
WHITE The Gentlemen AlienVault 2026-05-21 Modified: 2026-05-22
4
IOCs
LOW VOLUME
In April and May 2026, investigations revealed two incidents involving The Gentlemen ransomware-as-a-service operation, which has claimed over 400 victims across 70 countries since mid-2025. Both incidents demonstrated common tactics including Scheduled Tasks, PowerShell commands, and defense evasion techniques such as clearing Security, System, and Application Event Logs, disabling Microsoft Defender, and adding antivirus exclusions. A leaked internal database in early May exposed the operation's infrastructure, affiliate structure, and targeting of vulnerabilities like CVE-2024-55591. The attacks showed threat actors using RDP connections, disguised executables, SOCKS proxy connections for persistence, and domain-wide deployment via NETLOGON shares. Despite attempts to evade detection, sufficient forensic telemetry remained for analysis, revealing workstation names previously associated with Qilin ransomware and Lazarus infrastructure.
Indicators of Compromise (1 / 4 total)
All CVE FileHash-SHA256 IPv4
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 f918535f974591ef031bd0f30a8171e3da27a6754e6426a8ba095f83195661c8 2026-05-21