The Gentleman Ransomware | Defense Evasion TTPs Uncovered
Essential information
- Published
- 22/05/2026 01:03
- Modified
- 22/05/2026 06:43
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- cve-2024-55591 defense evasion event log clearing microsoft defender tampering powershell qilin ransomware-as-a-service rdp compromise scheduled tasks socks proxy the gentlemen trojan:win32/mptamperbulkexcl.h
- Tags
- 2026-05-21 CVE-2024-55591 defense evasion event log clearing microsoft defender tampering powershell qilin ransomware-as-a-service rdp compromise scheduled tasks socks proxy the gentlemen trojan:win32/mptamperbulkexcl.h
- Related entities
- 1 vulnerabilities (cve), 3 indicators, 3 observables, 1 intrusion sets (apt), 20 techniques (mitre), 3 malware, 2 others
Description
In April and May 2026, investigations revealed two incidents involving The Gentlemen ransomware-as-a-service operation, which has claimed over 400 victims across 70 countries since mid-2025. Both incidents demonstrated common tactics including Scheduled Tasks, PowerShell commands, and defense evasion techniques such as clearing Security, System, and Application Event Logs, disabling Microsoft Defender, and adding antivirus exclusions. A leaked internal database in early May exposed the operation's infrastructure, affiliate structure, and targeting of vulnerabilities like CVE-2024-55591. The attacks showed threat actors using RDP connections, disguised executables, SOCKS proxy connections for persistence, and domain-wide deployment via NETLOGON shares. Despite attempts to evade detection, sufficient forensic telemetry remained for analysis, revealing workstation names previously associated with Qilin ransomware and Lazarus infrastructure.