{
  "name": "The Gentlemen are knocking: \u0441ustom backdoors and evolving tactics",
  "slug": "the-gentlemen-are-knocking-ustom-backdoors-and-evolving-tactics",
  "description": "The Gentlemen ransomware-as-a-service group emerged as a top-10 threat actor in the first half of 2026. The group exploits vulnerabilities in internet-facing devices like VPNs and firewalls, potentially collaborating with initial access brokers. They employ comprehensive reconnaissance using tools like SharpADWS, NetScan, and Advanced IP Scanner, capturing network traffic with netsh. The attackers disable security products through BYOVD techniques using vulnerable drivers, and deploy custom Go-based backdoors and ransomware variants. They spread laterally via GPO deployment and PsExec, encrypt files using Curve25519 and XChaCha20, and recently developed a C-based ransomware variant using AES256-GCM and RSA. The group targets multiple industries worldwide, particularly in Brazil, China, Indonesia, Taiwan, and Thailand, with attacks focusing on manufacturing, IT services, healthcare, and financial sectors.",
  "published": "2026-06-29T11:01:00.897000+00:00",
  "created_at": "2026-07-01T13:10:10.127000+00:00",
  "modified_at": null,
  "created_at_opencti": null,
  "author": "AlienVault",
  "confidence": 100,
  "report_types": [
    "threat-report"
  ],
  "labels": [
    "appleseed",
    "byovd",
    "cobalt strike",
    "coolclient",
    "custom backdoor",
    "encryption tactics",
    "gpo deployment",
    "lateral movement",
    "mgbot",
    "network reconnaissance",
    "powercloud",
    "ransomware-as-a-service",
    "reversesocks",
    "sharkloader",
    "vulnerable drivers",
    "zichatbot"
  ],
  "tags": [],
  "related_entities": {
    "indicators": [
      {
        "id": "a2a72352-aff1-4b03-95e1-afdbca5dc1a6",
        "name": "cb747c0134f99d5033bac6e966864e2435a2a94244ca8e3f614f4992df93ff10"
      },
      {
        "id": "c6799e61-5990-45b5-9fb6-a3f94da691ad",
        "name": "b67958afc982cafbe1c3f114b444d7f4c91a88a3e7a86f89ab8795ac2110d1e6"
      },
      {
        "id": "c1355ad7-e452-42ba-86c6-847babff1068",
        "name": "c7f7b5a6e7d93221344e6368c7ab4abf93e162f7567e1a7bcb8786cb8a183a73"
      },
      {
        "id": "3bfcb3ec-cd40-416f-986b-7e6abdfa320e",
        "name": "5abe477517f51d81061d2e69a9adebdcda80d36667d0afabe103fda4802d33db"
      },
      {
        "id": "fcb3a105-69cc-455c-99e6-a8ce8f30bad6",
        "name": "rsat.activedirectory.ds-lds.tools"
      },
      {
        "id": "da866489-d2b9-4795-a744-0d18f7bebc44",
        "name": "1af419b36a5edefef387409e2b3248c9223f7dc49a4f7b15ea095d371c3a70b2"
      },
      {
        "id": "cb540555-1987-40c4-8265-c5faeefee225",
        "name": "9ddae47ff968343a8c32a5344060257fdc08e2a7bdb9a227c8b3a584ee3c9f1e"
      },
      {
        "id": "82d718b1-4419-4502-b655-58bee2e348b2",
        "name": "5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df"
      },
      {
        "id": "6cc1f742-ef88-42ce-b860-069077e56b1e",
        "name": "f8965fdce668692c3785afa3559159f9a18287bc0d53abb21902895a8ecf221b"
      },
      {
        "id": "1cd4dd53-826e-4dca-a66c-bfcbd8904a9c",
        "name": "5af1dae21425dda8311a2044209c308525135e1733eeff5dd20649946c6e054c"
      },
      {
        "id": "7918da49-bc9f-412b-abe2-48e71ab5051b",
        "name": "81.177.215.15"
      }
    ],
    "intrusion_sets": [
      {
        "id": "c920a404-92c6-423b-9714-146e22302900",
        "name": "The Gentlemen",
        "slug": "the-gentlemen"
      }
    ],
    "attack_patterns": [
      {
        "id": "ab1a2f00-2489-4c89-af29-e767f5fa5a23",
        "name": "T1070.003"
      },
      {
        "id": "5d2af906-6187-4702-ab9f-590fbe5b1ca3",
        "name": "T1021.002"
      },
      {
        "id": "c16977d5-6367-4c7d-91a8-fd1c57bec164",
        "name": "T1484.001"
      },
      {
        "id": "9f11a241-9abc-4c57-95dd-33955ab08826",
        "name": "T1078"
      },
      {
        "id": "0da3020a-9d7a-4c48-816a-bbd47a861398",
        "name": "T1562.002"
      },
      {
        "id": "ed82bdd1-d346-48d1-98de-36a9a0a96489",
        "name": "T1040"
      },
      {
        "id": "ecaaa4cc-d487-4002-bcb2-f769acfcc38f",
        "name": "T1490"
      },
      {
        "id": "32b33067-6566-4b8d-be80-e96f765d84de",
        "name": "T1059.001"
      },
      {
        "id": "f1bb7823-4f4b-4565-b472-bf0cfca467b1",
        "name": "T1486"
      },
      {
        "id": "f6ceeba2-b50c-47dc-8642-ab9842ca76d7",
        "name": "T1018"
      },
      {
        "id": "0c836307-129e-4ff7-a532-180c633cacba",
        "name": "T1027"
      },
      {
        "id": "6c8f8a40-2746-4a37-86bd-81e82afa6e62",
        "name": "T1190"
      },
      {
        "id": "53c193a7-f726-4bd2-ae88-4019e2604adf",
        "name": "T1046"
      },
      {
        "id": "6efb8bea-11d7-418d-a429-9f4a3e6c50f6",
        "name": "T1087"
      },
      {
        "id": "5999052b-e9ae-49e8-9235-d9bf975c22af",
        "name": "T1547.001"
      },
      {
        "id": "7364ca96-72bf-4b7f-afef-ce2583b1ed58",
        "name": "T1562.001"
      },
      {
        "id": "b15c00da-c412-4429-900c-659de612baf5",
        "name": "T1543.003"
      },
      {
        "id": "da44e22e-1925-42e4-b30d-ac38860d39bb",
        "name": "T1070.001"
      },
      {
        "id": "1eef7f88-3992-4add-899e-a7cc9fcdd5b3",
        "name": "T1569.002"
      },
      {
        "id": "d5c953ff-b143-41b6-bf2d-87b829132ea5",
        "name": "T1135"
      }
    ],
    "malware": [
      {
        "id": "316f008f-d739-4911-8eb6-ff5c3bfa7657",
        "name": "CoolClient",
        "slug": "coolclient"
      },
      {
        "id": "209f47b2-56aa-474d-ae60-b484f9bf1ec1",
        "name": "AppleSeed - S0622",
        "slug": "appleseed-s0622"
      },
      {
        "id": "7fdfd6c4-dd27-4e78-aa8a-08fa586356e1",
        "name": "ZiChatBot",
        "slug": "zichatbot"
      },
      {
        "id": "ab138766-9b64-4880-87fb-1942a709d778",
        "name": "Cobalt Strike - S0154",
        "slug": "cobalt-strike-s0154"
      },
      {
        "id": "e3b738c2-0b2c-464d-bd74-ed518a6b7547",
        "name": "PowerCloud",
        "slug": "powercloud"
      },
      {
        "id": "d15e9273-7699-43e4-bc98-2e2225a90666",
        "name": "SharkLoader"
      },
      {
        "id": "3d8b73d7-eae1-4e96-912f-77f1d626a347",
        "name": "MgBot",
        "slug": "mgbot"
      },
      {
        "id": "604b50b2-1e90-40c4-81ed-f4bc32efdf2b",
        "name": "ReverseSocks",
        "slug": "reversesocks"
      }
    ],
    "observables": [
      {
        "id": "e988fbde-a45a-4b87-9a13-b8ff2957af66",
        "name": "rsat.activedirectory.ds-lds.tools"
      },
      {
        "id": "84599b36-dda3-4abc-b10b-5f146e720bca",
        "name": "81.177.215.15"
      }
    ]
  },
  "external_refs": [
    {
      "id": "91271b7e-8d2e-4c7c-af10-f11e263dd335",
      "standard_id": "external-reference--639e1e7a-0c45-5281-9fca-bee817702d78",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://securelist.com/the-gentlemen-raas/120447/",
      "hash": null,
      "external_id": null,
      "created": "2026-06-30T06:52:58.782Z",
      "modified": "2026-06-30T06:52:58.782Z",
      "createdById": null
    },
    {
      "id": "56b82b78-715d-4295-aa2f-539fa1bdbb7b",
      "standard_id": "external-reference--f84b8321-2a47-513d-9981-20f565c2f69c",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://otx.alienvault.com/pulse/6a42506c95cc259404196a5b",
      "hash": null,
      "external_id": "6a42506c95cc259404196a5b",
      "created": "2026-06-30T06:52:58.756Z",
      "modified": "2026-06-30T06:52:58.756Z",
      "createdById": null
    }
  ]
}