Ungentlemanly behavior: Insights into a ransomware operation
Sophos CTU analyzed 15 intrusions by GOLD SHERWOOD affiliates operating The Gentlemen ransomware-as-a-service scheme, documenting a repeatable playbook combining VPN/firewall exploitation, rapid privilege escalation via native Windows utilities, legitimate tool abuse (Rclone, Restic, MinIO Client), BYOVD-based EDR killing, and ransomware deployment within 24-48 hours. The group has escalated from <20 monthly victims in late 2025 to 169 in July 2026, demonstrating operational maturity and affiliate recruitment success.