How The Gentlemen Ransomware Spreads and Encrypts Entire Networks
| July 06, 2026
Key Takeaways
- The Gentlemen ransomware is a RaaS threat written in Go, obfuscated with Garble, and active since mid-2025.
- It targets education, transportation, healthcare, and financial sectors across five continents.
- The ransomware encrypts files using a hybrid Curve25519 and XChaCha20 scheme with unique per-file ephemeral keys.
- Its self-propagation module attempts up to 21 remote execution techniques per target host on the network.
- The Picus Platform simulates Gentlemen Ransomware attacks across both network infiltration and email infiltration attack modules.
The Gentlemen ransomware is a ransomware-as-a-service (RaaS) threat, written in Go and obfuscated with Garble, that first emerged around mid-2025 and primarily targets organizations in the education, transportation, healthcare, and financial sectors across North America, South America, Europe, Africa, and Asia.
What sets it apart from typical ransomware is that it pairs strong per-file encryption with an aggressive self-propagation capability, allowing a single infection to spread across an entire network and encrypt every reachable system.
The operators also use double extortion, encrypting data while also stealing sensitive information to pressure victims with the threat of public leaks if the ransom is not paid.
This post breaks down how The Gentlemen ransomware operates and explains how you can validate your security controls against it.
The Gentlemen Ransomware at a Glance
|
Attribute |
Detail |
|
Malware type |
Ransomware-as-a-service (RaaS) with worm-like self-propagation |
|
First seen |
Around mid-2025 (RaaS affiliate program launched September 2025) |
|
Language and packing |
Written in Go, obfuscated with Garble |
|
Target platform |
Windows environments |
|
Encryption scheme |
Hybrid Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher, using unique per-file ephemeral keys |
|
Encrypted file extension |
.umc16h |
|
Ransom note |
README-GENTLEMEN.txt |
|
Industries targeted |
Education, transportation, healthcare, and financial services |
|
Regions affected |
North America, South America, Europe, Africa, and Asia |
The Gentlemen RaaS: Operators and Affiliates
The Gentlemen ransomware is a financially motivated RaaS operation. It began as a closed ransomware group around mid-2025, then started offering its platform to affiliates in September 2025.
More recently, the operators established an official partnership with BreachForums to recruit affiliates, including penetration testers and initial access brokers. This partnership is likely to drive increased activity as the program becomes accessible to a broader pool of threat actors.
How Does The Gentlemen Ransomware Work?
The Gentlemen ransomware follows a structured execution flow: it parses operator-supplied command-line arguments, validates a build-specific password, escalates privileges, disables defenses and destroys recovery options, encrypts files, and then attempts to spread across the network [1].
The sections below walk through each stage in detail.
Command-Line Arguments and Operator Control
The operator controls the encryptor through command-line arguments. A password is required for execution. If the provided password does not match, the malware prints bad args and terminates.
An example usage of the ransomware is shown below:
|
:: Authenticate as operator, run two-phase encryption (local + shares),self-propagate across the network using the current session token, then wipe free space to hinder recovery gentlemen.exe --password examplePassword --full --spread "" --wipe |
Privilege Escalation to SYSTEM
When the --system argument is provided (directly or via --full), the malware creates a scheduled task to re-execute itself as SYSTEM. If a delay is also specified through --T, the scheduled execution time is adjusted accordingly:
|
:: Create a one-time task that runs the malware as SYSTEM, one minute from now schtasks /Create /RU SYSTEM /SC ONCE /TN gentlemen_system /TR "/path/to/malware" /ST <current_time + --T argument value> :: Immediately trigger the task schtasks /Run /TN gentlemen_system |
When running inside this scheduled task context, the malware sets the environment variable LOCKER_BACKGROUND=1. This flag signals that the process is operating as a background encryption worker with elevated privileges, rather than the original operator-invoked instance.
Defense Evasion
Before starting encryption, the malware runs a sequence of commands to disable defensive controls and remove forensic artifacts.
First, it disables Microsoft Defender and adds broad exclusions [1]:
|
# Turn off real-time protection so encryption is not detected mid-run Set-MpPreference -DisableRealtimeMonitoring $true -Force # Whitelist the malware's own process so it is never scanned Add-MpPreference -ExclusionProcess <malware_name> -Force # Exclude the entire C:\ volume from scanning to avoid detection during encryption Add-MpPreference -ExclusionPath C:\ -Force |
Next, it destroys backups and clears logs to impede recovery and investigation:
|
:: Delete all Volume Shadow Copies (two methods for reliability) vssadmin delete shadows /all /quiet wmic shadowcopy delete :: Delete prefetch files that track which programs were executed del /f /q C:\Windows\Prefetch\*.* :: Delete Defender support and diagnostic logs del /f /q C:\ProgramData\Microsoft\Windows Defender\Support\*.* :: Delete RDP connection logs del /f /q %SystemRoot%\System32\LogFiles\RDP*\*.* |
Finally, it manually deletes PowerShell command history across all user profiles:
|
C:/Users/*/AppData/Roaming/Microsoft/Windows/PowerShell/PSReadline/ConsoleHost_history.txt |
Process and Service Termination
The malware forcibly stops a wide list of running processes to unlock files and disable defenses:
|
:: Force-kill each targeted process by image name taskkill /IM <process_name>.exe /F |
It also disables and stops a long list of Windows services:
|
:: Set the service to never start again, then stop it immediately sc config <service_name> start=disabled net stop <service_name> |
Together, the targeted processes and services span the same categories, including databases, backup and recovery software, endpoint detection and response (EDR) agents, and virtualization platforms, such as sqlservr (SQL Server), VeeamNFSSvc (backup), vmms (Hyper-V), outlook, and excel.
Terminating these processes and services serves two purposes:
- It improves file access and encryption reliability, since these processes and services hold active file locks that would otherwise block encryption.
- It disrupts defense and recovery by stopping backup services, endpoint protection agents, and remote access tools, reducing the chance of real-time detection or restoration from backups.
Persistence
The encryptor establishes persistence through two mechanisms: scheduled tasks and registry Run keys [1]:
|
:: Remove any old scheduled task, then create one that runs the malware at every startup schtasks /Delete /TN UpdateUser /F schtasks /Create /SC ONSTART /TN UpdateUser /TR "path/to/malware" :: Add a Run key so the malware autoruns reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v GupdateU /t REG_SZ /d "path/to/malware" /f |
Self-Propagation
The self-propagation module is the most distinctive component of The Gentlemen ransomware. When enabled with --spread, it turns the malware from a single-host encryptor into a self-propagating worm that attempts to deploy the encryptor to every reachable system on the network.
The --spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session's authentication token.
Once spreading begins, the malware turns the infected host into a distribution point: it copies its binary into C:\Temp, publishes it over a hidden SMB share (\\<self>\share$) configured for anonymous access, and drops (or downloads) a copy of PsExec. It then enumerates reachable hosts, including workstations, servers, and domain controllers, and treats each as a target.
Against every target, the malware first runs a PowerShell "defense evasion blob" to strip down the remote host's protections in a single command [1]:
|
# Disable Defender, Firewall and add broad exclusions Set-MpPreference -DisableRealtimeMonitoring $true; Add-MpPreference -ExclusionPath 'C:\'; Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled False; # Enable legacy SMB1 Enable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestart; # Loosen anonymous-access restrictions on the target reg add 'HKLM\SYSTEM\CurrentControlSet\Control\Lsa' /v EveryoneIncludesAnonymous /t REG_DWORD /d 1 /f |
It then attempts to execute the payload through many independent techniques, including remote file copy over the C$ share, PsExec, WMIC, scheduled tasks, Windows services, PowerShell remoting, and direct WMI process creation.
In total, the malware attempts 21 remote execution operations per target host. This redundancy is the core of its strategy: even in hardened environments, a single successful execution on one additional host is enough to keep the worm spreading.
Encryption
Before encrypting a file, the malware modifies its ownership and permissions to guarantee unrestricted write access [1]:
|
:: Take recursive ownership of the target file or directory takeown /f <file_path> /r /d y :: Grant full control to Everyone (SID S-1-1-0) with inheritance to child objects icacls <file_path> /grant *S-1-1-0:(OI)(CI)F /T :: Remove the read-only attribute attrib -R <file_path> |
The Gentlemen ransomware uses a hybrid design combining Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher. For each file, it:
- Generates a unique ephemeral Curve25519 key pair (a random private key and its corresponding public key)
- Computes the Elliptic-curve Diffie-Hellman (ECDH) shared secret between the ephemeral private key and the operator's embedded public key
- Uses the shared secret as the XChaCha20 key and derives the nonce from the first 24 bytes of the ephemeral public key
- Encrypts the file contents with XChaCha20 using this key and nonce
- Appends the Base64-encoded ephemeral public key to the file footer to enable later decryption
Small files are fully encrypted, while large files get three distributed chunks encrypted in 64 KB XChaCha20 blocks, with a per-chunk nonce mutation to prevent keystream reuse. The speed flag sets the amount, from 0.3% to 9% per chunk.
Each file gets the .umc16h extension, and a footer stores the ephemeral public key for decryption later.
How Picus Simulates Gentlemen Ransomware Attacks?
We strongly suggest simulating Gentlemen Ransomware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other ransomware variants, such as Warlock, BlackCat, Black Basta, and Akira, within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for the Gentlemen Ransomware Attacks:
|
Threat ID |
Threat Name |
Attack Module |
|
92505 |
The Gentlemen Ransomware Download Threat |
Network Infiltration |
|
32931 |
The Gentlemen Ransomware Email Threat |
E-mail Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.
References
[1] M. T. Intelligence, “The Gentlemen ransomware: Dissecting a self-propagating Go encryptor,” Microsoft Security Blog. Accessed: Jul. 02, 2026. [Online]. Available: https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/
