216.73.217.22

The Gentleman Ransomware | Defense Evasion TTPs Uncovered

· Published 22/05/2026 01:03 · Modified 22/05/2026 06:43

Export JSON

Essential information

Published
22/05/2026 01:03
Modified
22/05/2026 06:43
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
cve-2024-55591 defense evasion event log clearing microsoft defender tampering powershell qilin ransomware-as-a-service rdp compromise scheduled tasks socks proxy the gentlemen trojan:win32/mptamperbulkexcl.h
Tags
2026-05-21 CVE-2024-55591 defense evasion event log clearing microsoft defender tampering powershell qilin ransomware-as-a-service rdp compromise scheduled tasks socks proxy the gentlemen trojan:win32/mptamperbulkexcl.h
Related entities
1 vulnerabilities (cve), 3 indicators, 3 observables, 1 intrusion sets (apt), 20 techniques (mitre), 3 malware, 2 others

Description

In April and May 2026, investigations revealed two incidents involving operation, which has claimed over 400 victims across 70 countries since mid-2025. Both incidents demonstrated common tactics including , commands, and techniques such as clearing Security, System, and Application Event Logs, disabling Microsoft Defender, and adding antivirus exclusions. A leaked internal database in early May exposed the operation's infrastructure, affiliate structure, and targeting of vulnerabilities like . The attacks showed threat actors using RDP connections, disguised executables, connections for persistence, and domain-wide deployment via NETLOGON shares. Despite attempts to evade detection, sufficient forensic telemetry remained for analysis, revealing workstation names previously associated with ransomware and Lazarus infrastructure.

External references