PULSE NAME
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
WHITE Storm-2697 AlienVault 2026-05-28 Modified: 2026-05-29
4
IOCs
LOW VOLUME
The Gentlemen is a ransomware-as-a-service operation tracked as Storm-2697, distinguished by combining robust per-file encryption using Curve25519 with XChaCha20 stream cipher alongside aggressive self-propagation capabilities designed for broad network compromise. Emerging in mid-2025 and transitioning to RaaS by September 2025, the operation recently partnered with BreachForums to recruit affiliates including penetration testers and initial access brokers. Written in Go and obfuscated with Garble, the ransomware employs double extortion tactics, encrypting data while exfiltrating sensitive information. It utilizes 21 distinct lateral movement techniques per target host, including PsExec, WMI, scheduled tasks, services, and PowerShell remoting. The malware disables defenses, deletes shadow copies and forensic artifacts, and can optionally wipe free disk space to prevent recovery, impacting organizations globally across education, transportation, healthcare, and finance sectors.
Indicators of Compromise (4)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 7a262d4cbbc4808932b6af42c4041f06 2026-05-28
FileHash-SHA1 9e951cf2f868b71aaaa05966d8eb96d333b80106 2026-05-28
FileHash-SHA256 22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67 2026-05-28
FileHash-SHA256 fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68 2026-05-28