How The Gentlemen Ransomware Spreads and Encrypts Entire Networks

Umut Bayram | 8 MIN READ

| July 06, 2026

Key Takeaways

  • The Gentlemen ransomware is a RaaS threat written in Go, obfuscated with Garble, and active since mid-2025.
  • It targets education, transportation, healthcare, and financial sectors across five continents.
  • The ransomware encrypts files using a hybrid Curve25519 and XChaCha20 scheme with unique per-file ephemeral keys.
  • Its self-propagation module attempts up to 21 remote execution techniques per target host on the network.
  • The Picus Platform simulates Gentlemen Ransomware attacks across both network infiltration and email infiltration attack modules.

The Gentlemen ransomware is a ransomware-as-a-service (RaaS) threat, written in Go and obfuscated with Garble, that first emerged around mid-2025 and primarily targets organizations in the education, transportation, healthcare, and financial sectors across North America, South America, Europe, Africa, and Asia.

What sets it apart from typical ransomware is that it pairs strong per-file encryption with an aggressive self-propagation capability, allowing a single infection to spread across an entire network and encrypt every reachable system.

The operators also use double extortion, encrypting data while also stealing sensitive information to pressure victims with the threat of public leaks if the ransom is not paid.

This post breaks down how The Gentlemen ransomware operates and explains how you can validate your security controls against it.

The Gentlemen Ransomware at a Glance

Attribute

Detail

Malware type

Ransomware-as-a-service (RaaS) with worm-like self-propagation

First seen

Around mid-2025 (RaaS affiliate program launched September 2025)

Language and packing

Written in Go, obfuscated with Garble

Target platform

Windows environments

Encryption scheme

Hybrid Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher, using unique per-file ephemeral keys

Encrypted file extension

.umc16h

Ransom note

README-GENTLEMEN.txt

Industries targeted

Education, transportation, healthcare, and financial services

Regions affected

North America, South America, Europe, Africa, and Asia

The Gentlemen RaaS: Operators and Affiliates

The Gentlemen ransomware is a financially motivated RaaS operation. It began as a closed ransomware group around mid-2025, then started offering its platform to affiliates in September 2025.

More recently, the operators established an official partnership with BreachForums to recruit affiliates, including penetration testers and initial access brokers. This partnership is likely to drive increased activity as the program becomes accessible to a broader pool of threat actors.

How Does The Gentlemen Ransomware Work?

The Gentlemen ransomware follows a structured execution flow: it parses operator-supplied command-line arguments, validates a build-specific password, escalates privileges, disables defenses and destroys recovery options, encrypts files, and then attempts to spread across the network [1].

The sections below walk through each stage in detail.

Command-Line Arguments and Operator Control

The operator controls the encryptor through command-line arguments. A password is required for execution. If the provided password does not match, the malware prints bad args and terminates.

An example usage of the ransomware is shown below:

:: Authenticate as operator, run two-phase encryption (local + shares),self-propagate across the network using the current session token, then wipe free space to hinder recovery

gentlemen.exe --password examplePassword --full --spread "" --wipe

Privilege Escalation to SYSTEM

When the --system argument is provided (directly or via --full), the malware creates a scheduled task to re-execute itself as SYSTEM. If a delay is also specified through --T, the scheduled execution time is adjusted accordingly:

:: Create a one-time task that runs the malware as SYSTEM, one minute from now

schtasks /Create /RU SYSTEM /SC ONCE /TN gentlemen_system /TR "/path/to/malware" /ST <current_time + --T argument value>

:: Immediately trigger the task

schtasks /Run /TN gentlemen_system

When running inside this scheduled task context, the malware sets the environment variable LOCKER_BACKGROUND=1. This flag signals that the process is operating as a background encryption worker with elevated privileges, rather than the original operator-invoked instance.

Defense Evasion

Before starting encryption, the malware runs a sequence of commands to disable defensive controls and remove forensic artifacts.

First, it disables Microsoft Defender and adds broad exclusions [1]:

# Turn off real-time protection so encryption is not detected mid-run

Set-MpPreference -DisableRealtimeMonitoring $true -Force

# Whitelist the malware's own process so it is never scanned

Add-MpPreference -ExclusionProcess <malware_name> -Force

# Exclude the entire C:\ volume from scanning to avoid detection during encryption

Add-MpPreference -ExclusionPath C:\ -Force

Next, it destroys backups and clears logs to impede recovery and investigation:

:: Delete all Volume Shadow Copies (two methods for reliability)

vssadmin delete shadows /all /quiet

wmic shadowcopy delete

:: Delete prefetch files that track which programs were executed

del /f /q C:\Windows\Prefetch\*.*

:: Delete Defender support and diagnostic logs

del /f /q C:\ProgramData\Microsoft\Windows Defender\Support\*.*

:: Delete RDP connection logs

del /f /q %SystemRoot%\System32\LogFiles\RDP*\*.*

Finally, it manually deletes PowerShell command history across all user profiles:

C:/Users/*/AppData/Roaming/Microsoft/Windows/PowerShell/PSReadline/ConsoleHost_history.txt

Process and Service Termination

The malware forcibly stops a wide list of running processes to unlock files and disable defenses:

:: Force-kill each targeted process by image name

taskkill /IM <process_name>.exe /F

It also disables and stops a long list of Windows services:

:: Set the service to never start again, then stop it immediately

sc config <service_name> start=disabled

net stop <service_name>

Together, the targeted processes and services span the same categories, including databases, backup and recovery software, endpoint detection and response (EDR) agents, and virtualization platforms, such as sqlservr (SQL Server), VeeamNFSSvc (backup), vmms (Hyper-V), outlook, and excel.

Terminating these processes and services serves two purposes:

  • It improves file access and encryption reliability, since these processes and services hold active file locks that would otherwise block encryption.
  • It disrupts defense and recovery by stopping backup services, endpoint protection agents, and remote access tools, reducing the chance of real-time detection or restoration from backups.

Persistence

The encryptor establishes persistence through two mechanisms: scheduled tasks and registry Run keys [1]:

:: Remove any old scheduled task, then create one that runs the malware at every startup

schtasks /Delete /TN UpdateUser /F

schtasks /Create /SC ONSTART /TN UpdateUser /TR "path/to/malware"

:: Add a Run key so the malware autoruns

reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v GupdateU /t REG_SZ /d "path/to/malware" /f

Self-Propagation

The self-propagation module is the most distinctive component of The Gentlemen ransomware. When enabled with --spread, it turns the malware from a single-host encryptor into a self-propagating worm that attempts to deploy the encryptor to every reachable system on the network.

The --spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session's authentication token.

Once spreading begins, the malware turns the infected host into a distribution point: it copies its binary into C:\Temp, publishes it over a hidden SMB share (\\<self>\share$) configured for anonymous access, and drops (or downloads) a copy of PsExec. It then enumerates reachable hosts, including workstations, servers, and domain controllers, and treats each as a target.

Against every target, the malware first runs a PowerShell "defense evasion blob" to strip down the remote host's protections in a single command [1]:

# Disable Defender, Firewall and add broad exclusions

Set-MpPreference -DisableRealtimeMonitoring $true;

Add-MpPreference -ExclusionPath 'C:\';

Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled False;

# Enable legacy SMB1

Enable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestart;

# Loosen anonymous-access restrictions on the target

reg add 'HKLM\SYSTEM\CurrentControlSet\Control\Lsa' /v EveryoneIncludesAnonymous /t REG_DWORD /d 1 /f

It then attempts to execute the payload through many independent techniques, including remote file copy over the C$ share, PsExec, WMIC, scheduled tasks, Windows services, PowerShell remoting, and direct WMI process creation.

In total, the malware attempts 21 remote execution operations per target host. This redundancy is the core of its strategy: even in hardened environments, a single successful execution on one additional host is enough to keep the worm spreading.

Encryption

Before encrypting a file, the malware modifies its ownership and permissions to guarantee unrestricted write access [1]:

:: Take recursive ownership of the target file or directory

takeown /f <file_path> /r /d y

:: Grant full control to Everyone (SID S-1-1-0) with inheritance to child objects

icacls <file_path> /grant *S-1-1-0:(OI)(CI)F /T

:: Remove the read-only attribute

attrib -R <file_path>

The Gentlemen ransomware uses a hybrid design combining Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher. For each file, it:

  1. Generates a unique ephemeral Curve25519 key pair (a random private key and its corresponding public key)
  2. Computes the Elliptic-curve Diffie-Hellman (ECDH) shared secret between the ephemeral private key and the operator's embedded public key
  3. Uses the shared secret as the XChaCha20 key and derives the nonce from the first 24 bytes of the ephemeral public key
  4. Encrypts the file contents with XChaCha20 using this key and nonce
  5. Appends the Base64-encoded ephemeral public key to the file footer to enable later decryption

Small files are fully encrypted, while large files get three distributed chunks encrypted in 64 KB XChaCha20 blocks, with a per-chunk nonce mutation to prevent keystream reuse. The speed flag sets the amount, from 0.3% to 9% per chunk.

Each file gets the .umc16h extension, and a footer stores the ephemeral public key for decryption later.

How Picus Simulates Gentlemen Ransomware Attacks?

We strongly suggest simulating Gentlemen Ransomware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other ransomware variants, such as Warlock, BlackCat, Black Basta, and Akira, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the Gentlemen Ransomware Attacks:

Threat ID

Threat Name

Attack Module

92505

The Gentlemen Ransomware Download Threat

Network Infiltration

32931

The Gentlemen Ransomware Email Threat

E-mail Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.

References

[1] M. T. Intelligence, “The Gentlemen ransomware: Dissecting a self-propagating Go encryptor,” Microsoft Security Blog. Accessed: Jul. 02, 2026. [Online]. Available: https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/

 
The Gentlemen ransomware is a Windows-targeting ransomware-as-a-service (RaaS) threat, written in Go and obfuscated with Garble, that combines strong per-file encryption with worm-like self-propagation. It first emerged around mid-2025 and began offering its platform to affiliates in September 2025.
It emerged around mid-2025 as a closed group and started recruiting affiliates for its RaaS platform in September 2025.
It uses a hybrid scheme combining Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher. Each file gets a unique ephemeral Curve25519 key pair, and the ECDH shared secret with the operator's embedded public key becomes the XChaCha20 key. This makes decryption without the operator's private key infeasible.
Encrypted files are renamed with the appended extension .umc16h.
When run with the --spread argument, it becomes a self-propagating worm. It stages its binary on an SMB share, drops or downloads PsExec, enumerates network hosts, and attempts up to 21 remote execution operations per target using remote file copy, PsExec, WMIC, scheduled tasks (user and SYSTEM), services, PowerShell remoting, and PowerShell WMI. Each method runs independently, so a single success is enough to keep spreading.
The cryptographic design uses per-file ephemeral keys and ECDH with the operator's public key, so decryption requires the operator's private key. Recovery generally depends on offline backups, since the malware also deletes Volume Shadow Copies and can wipe free disk space. Third-party recovery tools are not effective against the encryption itself.
The Picus Platform includes simulations of Gentlemen Ransomware attacks through two attack modules: Network Infiltration (Threat ID 92505) and Email Infiltration (Threat ID 32931). Organizations can use the Picus Threat Library to validate security controls against the Gentlemen ransomware and hundreds of other ransomware variants.

Table of Contents

Ready to start? Request a demo