The Gentlemen — Ransomware Hunt & Hardening Pack

FortiOS exploit (CVE-2024-55591) → AD recon → BYOVD EDR-kill → self-propagating Go encryptor (.i8p14s). Defensive hunt & harden pack — no exploit code.
Threat
The Gentlemen · Storm-2697 · Phantom Mantis
Severity
ACTIVE RaaS
Type
Ransomware · double extortion · self-propagating
Primary access
CVE-2024-55591 (FortiOS)
Victims
~478 to date (Ransomware.Live)
Version
v0.3 · 2026-06-11 (re-hunt)
Author
HuntPack
Confidence
HIGH
01

Executive Summary

"The Gentlemen" (Microsoft Storm-2697; PRODAFT Phantom Mantis) is a professionalized, Russian-speaking double-extortion RaaS operation and one of 2026's most active groups — ~478 published victims to date and roughly 10% of all ransomware activity in April 2026. Access of choice is mass-exploitation of edge appliances, chiefly FortiOS/FortiProxy via CVE-2024-55591 plus brute-forced FortiGate VPN credentials, with Cisco and VMware estates also in scope.

After access, operators run internal AD reconnaissance, steal credentials with commodity stealers, disable endpoint defenses (including kernel-level BYOVD EDR-kill via All.exe + ThrottleBlood.sys), clear event logs, and deploy a Go-based, Garble-obfuscated, self-propagating encryptor (extension .i8p14s, note README-GENTLEMEN.txt). Its --spread flag turns it into an SMB worm; --wipe destroys recovery artifacts. Double-extortion data theft runs through rclone to MEGA. The lead operator (LARVA-368) relies heavily on AI for tooling and post-exploitation, and the group runs a multi-channel extortion model (ransom + email + phone).

Earliest endpoint signal: an interactive logon from a VPN-assigned IP followed within ~60 minutes by AD discovery (net group "Domain Admins", nltest /dclist:). Q5 is the highest-fidelity early detection. Q9 (SMB self-propagation) and Q10 (BYOVD EDR-kill) are the "impact is imminent" signals — escalate on any hit.
Defender priority: (1) Patch FortiOS CVE-2024-55591, force VPN MFA, rotate VPN creds. (2) Enable the Microsoft Vulnerable Driver Blocklist (HVCI) + Falcon tamper protection to break BYOVD. (3) Disable SMBv1 and deploy Q5/Q9/Q10 as high-severity detections now. Typical dwell is 2–6 weeks, so historical hunts (30–90 days) are worthwhile.
02

Source Review & Intel Refresh

This pack was re-hunted on 2026-06-11 against intel published after the original 2026-05-16 build — Microsoft's 28 May encryptor deep-dive, the PRODAFT "Inside the Phantom Mantis Operation" report and Krebs attribution (both 11 Jun), plus Huntress/Group-IB/Check Point/Halcyon/NCC/ZeroFox analyses and the May "Rocket.Chat" leak. Several earlier assumptions were corrected and the coverage gap list shrank.

AreaOriginal (2026-05-16)Updated (2026-06-11)
Initial accessFortiOS / SonicWall / Cisco ASA (broad)FortiOS CVE-2024-55591 + VPN brute force is primary; Cisco and VMware Aria Operations confirmed in the leak; SonicWall/Oracle EBS discussed but not corroborated as used.
EncryptorUnknown; extension "TBD"Known: Go (Garble-obfuscated), 5 builds — Windows, Linux, ESXi, Windows XP+, LVM; ext .i8p14s; X25519 + XChaCha20; --spread (SMB worm) & --wipe (anti-recovery) flags.
ToolingSharpHound, AnyDesk, generic stealersAdds NetExec, RelayKing, TaskHound, PrivHound, CertiHound (recon/cert/priv-esc), EDRStartupHinder, gfreeze, glinker (evasion), and Velociraptor as C2 (new Q16).
AttributionUnattributedStorm-2697 / Phantom Mantis; lead LARVA-368 (hastalamuerte, zeta88, ArmCorp, nobody0, santamuerte); named by Krebs as Alexander A. Yapaev (Izhevsk, RU); AI-assisted ops; active since Mar 2025.
Dwell time~48 hours2–6 weeks from initial access to encryption (focus on VMware-heavy estates).
Queries8 (5 gaps)16 — closed event-log clearing, credential access, SMB spread, BYOVD, exfil, and named-toolkit/C2 gaps.

Source tiers

TierSourceKey Finding
PrimaryMicrosoft Security Blog (28 May)Self-propagating Go encryptor; --spread/--wipe; Garble; tracked as Storm-2697
PrimaryPRODAFT — Inside the Phantom Mantis OperationLARVA-368 attribution, affiliate panel, 5 ransomware builds, 90/10 split, AI-assisted
SecondaryHuntress / Group-IB / Check PointBYOVD (All.exe + ThrottleBlood.sys), log clearing, Defender disable, CVE set, NTLM relay
SecondaryHalcyon / NCC Group / ZeroFox~10% of April activity, GPO manipulation, multi-channel extortion, same-day patch after decryptor
TertiaryHunt.io / SocRadar / KELA / VectraProton66 open-dir toolkit (176.120.22.127), Rocket leak analysis, geography

Confidence: HIGH — corroborated across vendor labs, a national-CERT-grade leak analysis, and Microsoft. Network IOCs are sparse and short-lived (the crew rotates infrastructure and several details derive from a single leak), so behavioral queries (Q1, Q5, Q9, Q10) carry the durable coverage.

03

Hunt Brief & Attack Chain

Working hypothesis: If The Gentlemen are active, the earliest endpoint-visible chain is a VPN-pool interactive logon followed by built-in AD enumeration on the same host, escalating over days/weeks into credential theft, BYOVD EDR-kill, event-log clearing, SMB self-propagation, rclone exfil, and .i8p14s encryption.

Identity

CategoryRansomware-as-a-Service (double extortion); active since March 2025 (affiliate/ArmCorp), independent RaaS from July 2025
AttributionStorm-2697 (Microsoft) / Phantom Mantis (PRODAFT). Lead operator LARVA-368 — aliases hastalamuerte, zeta88, ArmCorp, nobody0, santamuerte; named by Brian Krebs as Alexander A. Yapaev (Izhevsk, RU). ~9 operators; 90/10 affiliate split; AI-assisted development
Scale / geography~478 victims (Ransomware.Live); ~10% of all ransomware activity in April 2026. Only ~13% US — top: Thailand, UK, Brazil, Germany, India
ToolingSharpHound/BloodHound, AdFind, NetExec, RelayKing, TaskHound, PrivHound, CertiHound, Velociraptor (C2), G-BOT/SystemBC, Phemedrone v2.3.2, LummaC2, XenAllPasswordPro, DumpBrowserSecrets, EDRStartupHinder, gfreeze, glinker, All.exe + ThrottleBlood.sys (BYOVD), rclone, AnyDesk/ScreenConnect

Initial access vectors

Update (Jun 11): Confirmed edge-device focus is Fortinet FortiGate and Cisco; the Rocket.Chat leak shows the crew weaponizing flaws in Fortinet, Cisco, VMware Aria Operations, and Microsoft software (VMware-heavy estates are favored). SonicWall/Oracle EBS appear in chatter but remain uncorroborated as used. Hunt and harden Fortinet first, then Cisco and VMware.
VectorCVE / MethodNotes
Fortinet FortiOS / FortiProxy (mgmt interface)CVE-2024-55591 — auth bypass (primary)Admin session / foothold
FortiGate SSL VPNCredential brute-force / reuse (~1,000 VPNs; e.g. gentlemen25, gentle26)Valid VPN credential pairs
Secondary (track patched)CVE-2025-32433 (Erlang/OTP SSH), CVE-2025-33073 (NTLM relay/SMB)Lateral / priv-esc enablers
Also weaponized (per leak)VMware Aria Operations, Cisco, Microsoft flawsBackup & management-controller abuse, NTLM relay workflows

Attack chain

#StepTelemetryHunt Angle
1FortiOS exploit / VPN brute-force → internal accessAppliance logs; UserLogonVPN-pool logon (Q5)
2AD recon (net/nltest/dsquery/AdFind/NetExec/SharpHound)ProcessRollup2Q1, Q2, Q3, Q5, Q16
3Credential theft (LSASS, browser stealers)ProcessRollup2Q12
4C2 / persistence (Velociraptor, G-BOT/SystemBC, RMM)ProcessRollup2, NetworkConnectIP4Q4, Q16
5Defense evasion: BYOVD EDR-kill, Defender off, log clear, msimg32 sideloadProcessRollup2, PeFileWrittenQ7, Q10, Q11, Q13
6Self-propagation over SMB (--spread)ProcessRollup2Q9
7Exfil (rclone→MEGA), inhibit recovery (vssadmin, --wipe), encrypt (.i8p14s)ProcessRollup2, file writesQ14, Q6, Q8
04

Consolidated IOC Table

Infrastructure rotates aggressively. Network IOCs are sparse/short-lived and several derive from a single leak — hunt and corroborate, don't blindly block. Bulk-copy versions are in §8.
TypeValueConf.ActionContext
SHA25622b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67HIGHPreventLocker / payload sample
IPv4176.120.22.127MEDDetectProton66 bulletproof host; open-dir operator toolkit (Hunt.io); may be reassigned
File ext.i8p14sHIGHDetectEncrypted-file marker (Q8)
FilenamesREADME-GENTLEMEN.txt, gentlemen.bmp, All.exe, ThrottleBlood.sysHIGHDetectNote / wallpaper / BYOVD kit (Q8, Q10)
DLL artifactmsimg32.dll outside System32/SysWOW64MEDDetectDLL sideloading (Q13)
BehaviorEncryptor run with --spread / --wipeHIGHDetectSMB worm / anti-recovery (Q9, Q6)
YARA strings"Silent mode" · "Encrypt only mapped...shares" · "README-GENTLEMEN.txt" · "gentlemen.bmp" · "[+] Encryption started"HIGHHunt≥4 matches = confirmed locker sample
05

ATT&CK Mapping

TacticTechniqueSub-technique / ToolHunt Q
Initial AccessT1190 / T1110FortiOS CVE-2024-55591 / VPN brute force(appliance logs)
Initial Access / PersistenceT1078Valid Accounts via VPNQ5
DiscoveryT1087.002 / T1069.002 / T1482 / T1018AD account/group/trust/DC discovery; NetExecQ1, Q5, Q16
DiscoveryT1482 + S0521SharpHound / BloodHoundQ2, Q3
Credential AccessT1003.001 / T1555.003 / T1649LSASS minidump / browser stealers / cert abuse (CertiHound)Q12, Q16
Command & ControlT1219 / T1071Velociraptor, G-BOT/SystemBC, RMMQ4, Q16
Defense EvasionT1574.002msimg32.dll DLL sideloadingQ13
Defense EvasionT1562.001 / .004 / .010Defender disable / SMB1 / LSA / firewall; EDRStartupHinder, gfreeze, glinkerQ7, Q10
Defense Evasion / Priv EscT1562.001 + T1068 + T1543.003BYOVD — All.exe + ThrottleBlood.sysQ10
Defense EvasionT1070.001Clear Security/System/Application logsQ11
Lateral MovementT1021.002 / T1570 / T1021.001Self-propagation over SMB (--spread)Q9
ExfiltrationT1567.002 / T1048rclone → MEGAQ14
ImpactT1490vssadmin / wbadmin / bcdedit / --wipeQ6
ImpactT1486Encryption — .i8p14s mass file writesQ8
All (indicators)Known hash / C2 IP sweepQ15
06

CrowdStrike LogScale CQL Hunt Queries

Pick your tenant's cloud first — every "Open in Falcon" button below uses this selection.
Field names validated against the Falcon event reference; process hunts include SyntheticProcessRollup2. Run over 7–30 days first (dwell is 2–6 weeks, so 30–90 days for historical sweeps), tune FP notes, and validate before promoting any IOA to Prevent. Q5 and Q9 require an env edit (your VPN CIDRs / deploy allow-list).
Q1 · AD discovery — Domain Admin / DC / trust enumeration
CONF MEDFP MEDCOST LOW

Looks for: built-in AD enumeration (privileged groups, DCs, trusts) post-compromise. FP: sysadmin scripts, helpdesk, AD health checks from PAW/JIT — allow-list known admin AIDs.

// HUNT: The Gentlemen — AD discovery (T1087.002/T1069.002/T1482/T1018)
// CONF: medium  FP: medium  COST: low | TIMEFRAME: last 7d
// FP NOTES: net.exe by admins from PAW/JIT; nltest in AD health scripts; documented dsquery modules
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| in(field=FileName, values=["net.exe","net1.exe","nltest.exe","dsquery.exe","whoami.exe","adfind.exe"], ignoreCase=true)
| CommandLine = /(group\s+"?Domain Admins"?|group\s+"?Enterprise Admins"?|\/domain\b|\/dclist|\/domain_trusts|\/groups|\/all|enterprise admins|domain admins)/i
| groupBy([aid, ComputerName, UserName], function=[count(), collect([ImageFileName, CommandLine], limit=20)])
| sort(_count, order=desc)
Q2 · SharpHound / BloodHound execution
CONF HIGHFP LOWCOST LOW

Looks for: SharpHound/Invoke-BloodHound AD-path mapping — tool-specific strings are high-fidelity. FP: authorized red-team — allow-list operator AIDs.

// HUNT: The Gentlemen — SharpHound/BloodHound (T1482, S0521)
// CONF: high  FP: low  COST: low | TIMEFRAME: last 14d
// FP NOTES: authorized internal red-team / pentest (allow-list operator AIDs)
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| (ImageFileName = /\\sharphound(\.exe|\.ps1)?$/i
   or CommandLine = /(Invoke-BloodHound|SharpHound\s|-CollectionMethod\s+(All|Default|DCOnly|LoggedOn|Session|ACL|Trusts)|-ZipFileName|-OutputDirectory\s+.*bloodhound)/i)
| table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
| sort(@timestamp, order=desc)
Q3 · BloodHound output file artifacts
CONF HIGHFP LOWCOST LOW

Looks for: canonical SharpHound JSON/ZIP output names — diagnostic even when the binary is renamed. FP: authorized red-team only.

// HUNT: The Gentlemen — BloodHound output artifacts (T1213, T1482)
// CONF: high  FP: very low  COST: low | TIMEFRAME: last 14d
// FP NOTES: authorized red-team only
#event_simpleName = /NewExecutableWritten|PeFileWritten|NewScriptWritten/
| TargetFileName = /(_computers\.json|_groups\.json|_users\.json|_domains\.json|_gpos\.json|_ous\.json|_sessions\.json|_containers\.json|BloodHound\.zip|\d{14}_BloodHound\.zip)$/i
| table([@timestamp, aid, ComputerName, UserName, TargetFileName, ContextBaseFileName], limit=200)
| sort(@timestamp, order=desc)
Q4 · Unauthorized RMM / C2 staging
CONF MEDFP HIGHCOST LOW

Looks for: commodity RMM agents used as persistence redundant to G-BOT/SystemBC/Velociraptor C2. FP: legitimate IT/MSP tooling — edit the allow-list for your sanctioned RMM and vendor support AIDs.

// HUNT: The Gentlemen — Unauthorized RMM (T1219)
// CONF: medium  FP: high  COST: low | TIMEFRAME: last 30d
// FP NOTES: allow-list sanctioned RMM (NinjaOne, Kaseya, ConnectWise) + vendor support
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| in(field=FileName, values=[
    "AnyDesk.exe","ScreenConnect.ClientService.exe","ScreenConnect.WindowsClient.exe",
    "AteraAgent.exe","Splashtop-streamer.exe","SRService.exe","TeamViewer.exe",
    "TeamViewer_Service.exe","rustdesk.exe","Action1_agent.exe","PulsewayMonitor.exe",
    "FleetDeskAgent.exe","SyncroService.exe","ZA_Connect.exe","ITarian_Service.exe",
    "AeroAdmin.exe","ammyy.exe","Supremo.exe","LogMeIn.exe","GoToAssist.exe",
    "rport.exe","MeshAgent.exe","ngrok.exe","TacticalRMM.exe","RemotePCService.exe",
    "DWAgent.exe","DWRCS.exe","Quasar.exe","Optitune.exe"
  ], ignoreCase=true)
| groupBy([aid, ComputerName, FileName, UserName], function=[count(), selectFromMin(field=@timestamp, include=[CommandLine, ParentBaseFileName, ImageFileName])])
| sort(_count, order=desc)
Q5 · ⭐ VPN-pool logon → AD recon within 60 min (correlated)
CONF HIGHFP MEDCOST MED

Looks for: a Type-10 logon from a VPN-pool IP followed within 60 min by AD enumeration on the same aid — the earliest Gentlemen chain. Correlation cuts FPs 10–50× vs. either signal alone. FP: legitimate remote admin — allow-list jump hosts.

EDIT BEFORE RUNNING: replace 10.200.0.0/16 and 172.16.50.0/24 with your actual VPN-assigned client pool subnet(s).
// HUNT: The Gentlemen — VPN-pool logon then AD recon (T1078 + T1087.002)
// CONF: high  FP: medium  COST: medium | TIMEFRAME: last 7d
// FP NOTES: legit remote admin; REPLACE the CIDRs with your VPN client pool(s); allow-list jump hosts
#event_simpleName = UserLogon
| LogonType = 10
| cidr(RemoteAddressIP4, subnet=["10.200.0.0/16","172.16.50.0/24"])
| logonTime := @timestamp
| logonHost := ComputerName
| logonUser := UserName
| logonSrc  := RemoteAddressIP4
| join(query={
    #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
    | in(field=FileName, values=["net.exe","net1.exe","nltest.exe","whoami.exe","dsquery.exe","adfind.exe"], ignoreCase=true)
    | CommandLine = /(Domain Admins|Enterprise Admins|\/dclist|\/domain_trusts|\/groups|\/all)/i
    | reconTime := @timestamp
    | reconCmd  := CommandLine
    | reconFile := FileName
  }, field=[aid], include=[reconTime, reconCmd, reconFile])
| test((reconTime - logonTime) <= 3600000)
| test((reconTime - logonTime) >= 0)
| table([logonTime, logonHost, logonUser, logonSrc, reconFile, reconCmd, reconTime], limit=200)
| sort(logonTime, order=desc)
Q6 · Inhibit recovery — shadow copy / backup deletion / --wipe
CONF HIGHFP LOWCOST LOW

Looks for: pre-encryption recovery destruction — VSS/backup/catalog deletion, recovery disable, and the encryptor's own --wipe flag. FP: some backup tools call vssadmin — allow-list backup-server AIDs.

// HUNT: The Gentlemen — Inhibit System Recovery (T1490)
// CONF: high  FP: low  COST: low | TIMEFRAME: last 30d
// FP NOTES: some backup tools call vssadmin (allow-list backup-server AIDs)
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| (CommandLine = /vssadmin(\.exe)?\s+delete\s+shadows/i
   or CommandLine = /wmic\s+shadowcopy\s+delete/i
   or CommandLine = /wbadmin\s+delete\s+(catalog|systemstatebackup|backup)/i
   or CommandLine = /bcdedit.*\/set.*(recoveryenabled\s+no|bootstatuspolicy\s+ignoreallfailures)/i
   or CommandLine = /Diskshadow.*delete\s+shadows/i
   or CommandLine = /\s--wipe\b/i)
| table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
| sort(@timestamp, order=desc)
Q7 · AV/EDR tamper + host weakening (Defender / SMB1 / LSA / firewall)
CONF MED-HIGHFP MEDCOST LOW

Looks for: Defender disable / broad exclusions, AV/EDR service stop, and host weakening — SMB1 re-enable, LSA anonymous loosening, firewall off — that precedes spread/encryption. FP: authorized AV change windows, SCCM/Intune scripts — allow-list management hosts.

// HUNT: The Gentlemen — Disable tools + weaken host (T1562.001/.004/.010)
// CONF: medium-high  FP: medium  COST: low | TIMEFRAME: last 14d
// FP NOTES: authorized AV change windows; SCCM/Intune compliance scripts (allow-list mgmt AIDs)
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| (CommandLine = /Set-MpPreference\s+-DisableRealtimeMonitoring\s+\$?(true|1)/i
   or CommandLine = /Add-MpPreference\s+-ExclusionPath/i
   or CommandLine = /Set-MpPreference\s+-(DisableIOAVProtection|DisableScriptScanning|DisableBehaviorMonitoring|MAPSReporting\s+0)/i
   or CommandLine = /sc(\.exe)?\s+(stop|delete|config).*(WinDefend|Sense|MsSecFlt|wuauserv|BITS|CSFalconService|SentinelAgent|elastic-agent|XAgentSvc)/i
   or CommandLine = /taskkill.*\/IM\s+(MsMpEng|CSFalconService|SentinelAgent|Cyserver|elastic-agent|XAgent)\.exe/i
   or CommandLine = /reg\s+(add|delete).*DisableAntiSpyware/i
   or CommandLine = /netsh\s+advfirewall\s+set\s+(allprofiles|currentprofile)\s+state\s+off/i
   or CommandLine = /(Enable-WindowsOptionalFeature.*SMB1|sc(\.exe)?\s+config\s+(mrxsmb10|lanmanserver).*SMB1|reg\s+add.*LanmanServer\\Parameters.*SMB1.*\/d\s+1)/i
   or CommandLine = /reg\s+add.*\\Lsa\b.*(RestrictAnonymous|everyoneincludesanonymous|LimitBlankPasswordUse)/i)
| table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
| sort(@timestamp, order=desc)
Q8 · Encryption — .i8p14s mass file write + ransom note
CONF HIGHFP LOWCOST LOW

Looks for: the encryptor's published artifacts — .i8p14s extension, README-GENTLEMEN.txt, gentlemen.bmp. Campaign-specific, so high confidence (no longer a tripwire). FP: mass-write thresholds may match backup/archive tools — allow-list those AIDs.

// HUNT: The Gentlemen — Encryption artifacts (.i8p14s + note) (T1486)
// CONF: high  FP: low  COST: low | TIMEFRAME: rolling 24h
// FP NOTES: note/wallpaper names are campaign-specific; backup tools bulk-write other extensions
#event_simpleName = /NewExecutableWritten|PeFileWritten|NewScriptWritten/
| (TargetFileName = /\.i8p14s$/i
   or TargetFileName = /\\README-GENTLEMEN\.txt$/i
   or TargetFileName = /\\gentlemen\.bmp$/i)
| groupBy([aid, ComputerName, ContextBaseFileName], function=[count(), selectFromMin(field=@timestamp, include=[TargetFileName, UserName])])
| sort(_count, order=desc)
Q9 · ⭐ Self-propagation — remote SMB copy / Admin$ transfer / --spread
CONF MED-HIGHFP MEDCOST MED

Looks for: the Go encryptor authenticating with harvested creds and copying itself to remote ADMIN$/C$ over SMB, then executing remotely — plus the explicit --spread worm flag. FP: software-deployment tooling (PsExec/SCCM) copies to admin shares — allow-list deploy-server AIDs.

// HUNT: The Gentlemen — Self-propagation over SMB (T1021.002 / T1570)
// CONF: medium-high  FP: medium  COST: medium | TIMEFRAME: last 7d
// FP NOTES: SCCM / PDQ Deploy / PsExec admin tooling (allow-list deploy AIDs)
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| (CommandLine = /(copy|xcopy|robocopy|cmd\s+\/c\s+copy).*\\\\[^\\]+\\(admin\$|c\$|ipc\$)/i
   or CommandLine = /net\s+use\s+\\\\[^\\]+\\(admin\$|c\$|ipc\$)/i
   or CommandLine = /(psexec|paexec|psexesvc).*\\\\[^\\]+/i
   or CommandLine = /wmic\s+\/node:.*process\s+call\s+create/i
   or CommandLine = /\\\\[^\\]+\\(admin\$|c\$)\\.*\.exe/i
   or CommandLine = /\s--spread\b/i)
| groupBy([aid, ComputerName, UserName], function=[count(), collect([CommandLine, ImageFileName, ParentBaseFileName], limit=25)])
| sort(_count, order=desc)
Q10 · ⭐ BYOVD EDR-kill — All.exe / ThrottleBlood.sys + evasion tools
CONF HIGHFP LOWCOST LOW

Looks for: the custom kill tool (All.exe) + vulnerable driver (ThrottleBlood.sys) and the group's named evasion utilities (EDRStartupHinder, gfreeze, glinker), plus a .sys service launched from a user-writable path. FP: very low — legit drivers install to System32\drivers via signed installers.

// HUNT: The Gentlemen — BYOVD EDR-kill (T1562.001 / T1068 / T1543.003)
// CONF: high  FP: low  COST: low | TIMEFRAME: last 30d
// FP NOTES: a .sys service from TEMP/ProgramData/user path is almost always malicious
// Branch A — named tooling / driver as process or in command line
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| (FileName = /^(All|EDRStartupHinder|gfreeze|glinker)\.exe$/i
   or CommandLine = /(ThrottleBlood\.sys|\\All\.exe)/i
   or CommandLine = /sc(\.exe)?\s+create.*binPath=.*\\(temp|programdata|users|appdata)\\.*\.sys/i
   or CommandLine = /(fltMC|sc(\.exe)?\s+stop).*(CSAgent|CSFalcon|SentinelAgent|WdFilter|elastic)/i)
| table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
| sort(@timestamp, order=desc)

// Branch B (run separately) — driver written outside the standard driver store
// #event_simpleName = /NewExecutableWritten|PeFileWritten/
// | TargetFileName = /\.sys$/i
// | TargetFileName != /\\Windows\\System32\\drivers\\/i
// | TargetFileName != /\\Windows\\System32\\DriverStore\\/i
// | table([@timestamp, aid, ComputerName, TargetFileName, ContextBaseFileName], limit=200)
Q11 · Event log clearing (Security / System / Application)
CONF HIGHFP LOWCOST LOW

Looks for: wevtutil cl, Clear-EventLog, or WMI event-log clears — confirmed Gentlemen cleanup. FP: rare in production; allow-list imaging/provisioning AIDs.

// HUNT: The Gentlemen — Clear Windows Event Logs (T1070.001)
// CONF: high  FP: low  COST: low | TIMEFRAME: last 14d
// FP NOTES: golden-image / provisioning pipelines may clear logs (allow-list)
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| (CommandLine = /wevtutil\s+(cl|clear-log)\b/i
   or CommandLine = /Clear-EventLog\b/i
   or CommandLine = /wmic\s+nteventlog.*ClearEventlog/i
   or CommandLine = /(Get-WinEvent|Get-EventLog).*\|\s*.*Clear/i)
| table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
| sort(@timestamp, order=desc)
Q12 · Credential access — LSASS minidump & browser stealers
CONF MED-HIGHFP MEDCOST LOW

Looks for: comsvcs.dll MiniDump of LSASS and commodity browser stealers (Phemedrone, LummaC2, XenAllPasswordPro, DumpBrowserSecrets). FP: rare IT diagnostics dump processes — pair with Falcon native CredentialDumping detections.

// HUNT: The Gentlemen — Cred access LSASS + browsers (T1003.001 / T1555.003)
// CONF: medium-high  FP: medium  COST: low | TIMEFRAME: last 14d
// FP NOTES: comsvcs MiniDump rarely legit; stealer names = high TP; pair with Falcon native
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| (CommandLine = /comsvcs\.dll.*MiniDump/i
   or CommandLine = /rundll32.*comsvcs.*\s+\d+\s+.*\.dmp/i
   or CommandLine = /(procdump(64)?\.exe).*lsass/i
   or CommandLine = /lsass.*\.dmp/i
   or FileName = /^(Phemedrone|XenAllPasswordPro|DumpBrowserSecrets|ChromeAppBound|LummaC2|mimikatz|nanodump)\.exe$/i)
| table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
| sort(@timestamp, order=desc)
Q13 · DLL sideloading — msimg32.dll outside System32
CONF HIGHFP LOWCOST LOW

Looks for: a msimg32.dll written anywhere outside System32/SysWOW64 — search-order hijack IOC. FP: a few apps ship their own copy — verify the writing process and signer.

// HUNT: The Gentlemen — msimg32.dll DLL sideloading (T1574.002)
// CONF: high  FP: low  COST: low | TIMEFRAME: last 30d
// FP NOTES: verify writing process and DLL signature before escalating
#event_simpleName = /NewExecutableWritten|PeFileWritten/
| TargetFileName = /\\msimg32\.dll$/i
| TargetFileName != /\\Windows\\System32\\/i
| TargetFileName != /\\Windows\\SysWOW64\\/i
| TargetFileName != /\\Windows\\WinSxS\\/i
| table([@timestamp, aid, ComputerName, UserName, TargetFileName, ContextBaseFileName], limit=200)
| sort(@timestamp, order=desc)
Q14 · Exfiltration — rclone to MEGA / cloud
CONF MED-HIGHFP MEDCOST LOW

Looks for: rclone command-line flags and MEGA remotes used to stage double-extortion theft — diagnostic even if the binary is renamed. FP: some IT uses rclone for cloud sync — allow-list sanctioned backup jobs.

// HUNT: The Gentlemen — Exfil via rclone to MEGA (T1567.002 / T1048)
// CONF: medium-high  FP: medium  COST: low | TIMEFRAME: last 14d
// FP NOTES: allow-list sanctioned backup jobs/AIDs; mega remote + copy/sync = high TP
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| (FileName = /^rclone\.exe$/i
   or CommandLine = /rclone\s+(copy|sync|move|lsd|config)/i
   or CommandLine = /(mega\.nz|mega:|--config\s+.*rclone\.conf)/i
   or CommandLine = /\b(copy|sync)\b.*\b(mega|b2|s3|gdrive|dropbox|onedrive):/i)
| groupBy([aid, ComputerName, UserName], function=[count(), collect([CommandLine, ImageFileName, ParentBaseFileName], limit=20)])
| sort(_count, order=desc)
Q15 · Known-indicator sweep (hash + C2 IP)
CONF HIGHFP LOWCOST LOW

Looks for: direct match on the published encryptor hash and the Proton66 C2 IP. Indicators rotate, so absence is inconclusive — keep refreshing from §4/§8. FP: hash is definitive; the IP may be reassigned — corroborate context.

// HUNT: The Gentlemen — indicator sweep (hash + historic C2 IP)
// CONF: high  FP: very low (hash) / low (IP) | TIMEFRAME: last 30-90d
// Branch A — encryptor hash
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| SHA256HashData = "22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67"
| table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, SHA256HashData], limit=200)

// Branch B (run separately) — Proton66 C2 IP
// #event_simpleName = NetworkConnectIP4
// | RemoteAddressIP4 = "176.120.22.127"
// | table([@timestamp, aid, ComputerName, ContextBaseFileName, RemoteAddressIP4, RemotePort], limit=200)
Q16 · Named toolkit & Velociraptor C2 sweep
CONF HIGHFP LOW-MEDCOST LOW

Looks for: the group's named utilities — recon/cert/priv-esc (NetExec, RelayKing, TaskHound, PrivHound, CertiHound), and Velociraptor abused as C2. FP: Velociraptor is a legitimate DFIR tool — allow-list sanctioned IR/forensics AIDs; NetExec/CME may appear in authorized pentests.

// HUNT: The Gentlemen — named toolkit + Velociraptor C2 (T1219/T1018/T1649)
// CONF: high  FP: low-medium  COST: low | TIMEFRAME: last 30d
// FP NOTES: Velociraptor is legit DFIR (allow-list IR AIDs); NetExec/CME in authorized pentests
#event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/
| (FileName = /^(nxc|netexec|crackmapexec|RelayKing|TaskHound|PrivHound|CertiHound|velociraptor)\.exe$/i
   or CommandLine = /(netexec|crackmapexec|\bnxc\b|RelayKing|TaskHound|PrivHound|CertiHound)/i
   or CommandLine = /velociraptor.*(\-\-config|client|gui|artifacts collect)/i)
| groupBy([aid, ComputerName, UserName], function=[count(), collect([FileName, CommandLine, ParentBaseFileName], limit=25)])
| sort(_count, order=desc)
07

CrowdStrike Custom IOA Recommendations

Build in Endpoint Security → Custom IOA Rules. Start in Detect; promote to Prevent after 14 days at <5% FP on a canary group. Custom IOA fields use PCRE.

IOAField Patterns (PCRE)MITREAction / Severity
IOA-1 · vssadmin delete shadowsImage .*\\vssadmin\.exe$; CmdLine .*delete\s+shadows.*T1490Detect → Block · High
IOA-2 · Defender disabled via PowerShellImage .*\\(powershell|pwsh)\.exe$; CmdLine .*Set-MpPreference\s+-DisableRealtimeMonitoring\s+\$?(true|1).*T1562.001Detect · High
IOA-3 · net.exe enumerating Domain AdminsImage .*\\(net|net1)\.exe$; CmdLine .*group\s+"?(Domain Admins|Enterprise Admins)"?\s+/domain.*T1069.002Detect only · Med
IOA-4 · RMM from non-Program-FilesImage .*\\(AnyDesk|rustdesk|AteraAgent|ScreenConnect\.ClientService|MeshAgent)\.exe$; exclude ^C:\\Program Files.*T1219Detect · High
IOA-5 · BYOVD driver service (non-standard path)Image .*\\sc\.exe$; CmdLine .*create.*binPath=.*\\(Temp|ProgramData|Users|AppData)\\.*\.sys.*T1068 / T1543.003Detect → Block · Critical
IOA-6 · Event log cleared via wevtutilImage .*\\wevtutil\.exe$; CmdLine .*\s(cl|clear-log)\s+(Security|System|Application).*T1070.001Detect · High
IOA-1, IOA-5, IOA-6 are strong Block candidates after a clean 7-day Detect window (rarely legitimate). Keep IOA-3 in Detect long-term (high admin overlap). Never auto-promote to Prevent without a measured FP rate.
08

Machine-Readable IOC Appendix

Grouped IOC Quick-Copy

One-click blocks for Falcon IOC Management, scheduled searches, or egress rules. Network IOCs are short-lived — hunt and corroborate.

Falcon IOC Management CSVbulk import
type,value,action,severity,expiration,description,tags
sha256,22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67,prevent,critical,2027-06-11,The Gentlemen - locker/payload,campaign:TheGentlemen
ipv4,176.120.22.127,detect,medium,2026-07-11,The Gentlemen - Proton66 C2 (30d; may be reassigned),campaign:TheGentlemen
sha256,REPLACE_WITH_SHA256,prevent,critical,2027-06-11,The Gentlemen - encryptor variant,campaign:TheGentlemen
domain,REPLACE_WITH_LEAK_SITE,detect,high,2026-09-09,The Gentlemen - data-leak site,campaign:TheGentlemen
Behavioral Signaturesdetection logic
Encryptor run with --spread (SMB worm) or --wipe (anti-recovery)
copy/robocopy/psexec to \\host\ADMIN$ or \\host\C$ (self-propagation)
All.exe + ThrottleBlood.sys / sc create binPath=...\Temp\...\.sys (BYOVD)
wevtutil cl Security|System|Application (log clearing)
comsvcs.dll MiniDump / browser stealer exec (cred access)
msimg32.dll written outside System32 (DLL sideload)
rclone copy/sync to mega: (exfil)
.i8p14s file writes + README-GENTLEMEN.txt + gentlemen.bmp (encryption)
Named Toolingprocess names
All.exe              # BYOVD EDR killer
ThrottleBlood.sys    # vulnerable driver
EDRStartupHinder.exe # EDR evasion
gfreeze.exe          # evasion
glinker.exe          # evasion
NetExec / nxc        # AD discovery / share enum
RelayKing.exe        # NTLM relay
TaskHound.exe        # scheduled-task abuse
PrivHound.exe        # priv-esc path mapping
CertiHound.exe       # AD CS / cert abuse
velociraptor.exe     # abused as C2
DumpBrowserSecrets.exe; Phemedrone; LummaC2; XenAllPasswordPro
Patch Audit — CVEs & egressedge + network
CVE-2024-55591   # FortiOS/FortiProxy auth bypass (PRIMARY)
CVE-2025-32433   # Erlang/OTP SSH
CVE-2025-33073   # NTLM relay / SMB
# Also weaponized per leak: VMware Aria Operations, Cisco, Microsoft
# Egress: block MEGA (mega.nz) + unsanctioned cloud storage
# Disable SMBv1 fleet-wide; alert on re-enable
09

Hardening Recommendations

Immediate — Edge appliance (Fortinet first)

Patch CVE-2024-55591 now

  • Confirm FortiOS/FortiProxy firmware vs. Fortinet PSIRT; verify CVE-2025-32433 and CVE-2025-33073 remediated; review Cisco and VMware Aria Operations exposure.
  • Force MFA on all VPN auth (FIDO2 preferred); SMS is inadequate against cookie theft and brute force.
  • Rotate all FortiGate VPN + local appliance credentials; block reuse-password patterns (e.g. gentlemen25, gentle26).
  • Restrict appliance mgmt/admin UI to a management VLAN — never expose /remote/login or the mgmt interface (the CVE-2024-55591 surface).
  • Rate-limit / geo-fence SSL VPN logins; alert on VPN brute-force; forward appliance logs to SIEM (≥90-day retention).
Immediate — Blunt evasion & spread
  • Enable Microsoft Vulnerable Driver Blocklist (HVCI) + Falcon vulnerable-driver protection to break BYOVD (ThrottleBlood.sys et al.).
  • Disable SMBv1 fleet-wide and alert on re-enable — the encryptor self-propagates over SMB.
  • Enable Falcon Tamper Protection; confirm the sensor can't be stopped via sc/taskkill without the maintenance token.
  • Restrict ADMIN$/C$ access from non-management hosts; monitor remote service creation (Q9). Block MEGA + unsanctioned cloud egress to disrupt rclone.
Detect — Identity & endpoint telemetry
  • Turn on Falcon Identity Protection — the built-in-binary recon chain lights up identity policies immediately.
  • Enable PowerShell ScriptBlock (4104) + Module logging via GPO → LogScale; Sysmon on Tier-0/DCs.
  • Audit policy: Distribution/Security Group Management + Sensitive Privilege Use on DCs; alert on event-log clears (1102/104); watch GPO changes (Gentlemen manipulate GPOs).
Strategic — Reduce attack surface
  • App allow-listing (AppLocker/WDAC) blocking AnyDesk/ScreenConnect/RustDesk/Atera unless sanctioned; restrict Velociraptor to IR hosts.
  • LSA Protection (RunAsPPL) + Credential Guard to neuter LSASS dumping/browser-cred theft; don't allow RestrictAnonymous to be loosened.
  • LAPS, Tier 0/1/2 admin model, disable LLMNR/NBT-NS/WPAD.
  • Immutable / offline backups (3-2-1) not deletable by a Domain Admin credential; monitor new local-admin creation (4720/4732); limit VPN-pool interactive logons via Auth Policy Silos.
10

Detection Coverage Map

TechniqueNameCQLIOACoverage
T1190 / T1110Exploit FortiOS / VPN brute forceGAP patch + appliance logs
T1078Valid Accounts (VPN)Q5Partial needs VPN CIDRs
T1087.002 / T1069.002 / T1482 / T1018AD discoveryQ1, Q5, Q16IOA-3Good
T1482 + S0521SharpHound / BloodHoundQ2, Q3Good
T1003.001 / T1555.003 / T1649Cred access / cert abuseQ12, Q16Good (+ native)
T1219 / T1071RMM / Velociraptor C2Q4, Q16IOA-4Good
T1574.002DLL sideloading (msimg32)Q13Good
T1562.001 / .004 / .010Disable/modify toolsQ7IOA-2Good
T1068 / T1543.003BYOVD vulnerable driverQ10IOA-5Good
T1070.001Clear event logsQ11IOA-6Good
T1021.002 / T1570Self-propagation over SMBQ9Partial tune deploy allow-list
T1490Inhibit recovery / --wipeQ6IOA-1Good
T1567.002 / T1048Exfil rclone→MEGAQ14Good (+ egress block)
T1486Data encrypted (.i8p14s)Q8Good extension known

Coverage: 13 of 14 technique groups have at least partial coverage (up from 8/13). The remaining gap — the FortiOS exploit / VPN brute-force phase (T1190/T1110) — is inherently pre-endpoint; defend with patching, MFA, and appliance log review.

11

Hunt Summary Ticket

TITLE:        Hunt — The Gentlemen Ransomware (Storm-2697 / Phantom Mantis)
SEVERITY:     Critical (active RaaS, ~10% of April 2026 ransomware activity)
SCOPE:        FortiGate/Cisco/VMware-exposed orgs; Windows/Linux/ESXi estates
HYPOTHESIS:   FortiOS CVE-2024-55591 / VPN brute-force access -> AD recon -> cred theft ->
              BYOVD EDR-kill -> log clear -> SMB self-propagation -> rclone exfil -> .i8p14s encrypt.
DWELL:        2-6 weeks initial access -> encryption (hunt 30-90d historical)
QUERIES RUN:  Q1 AD disc | Q2/Q3 BloodHound | Q4 RMM | Q5 VPN->recon* | Q6 recovery/--wipe |
              Q7 tamper | Q8 .i8p14s | Q9 SMB spread* | Q10 BYOVD | Q11 log clear |
              Q12 cred access | Q13 msimg32 | Q14 rclone | Q15 IOC sweep | Q16 toolkit/Velociraptor
              (* = requires env edit)
DO FIRST:     Q5, Q9, Q10, Q6, Q8, Q11 — escalate any hit immediately
FINDINGS:     <pending analyst execution>
GAPS:         T1190/T1110 pre-endpoint (patch + appliance logs); network IOCs short-lived
ACTIONS:      Patch CVE-2024-55591 + VPN MFA + cred rotation; HVCI vuln-driver blocklist;
              disable SMBv1; deploy Q5/Q9/Q10 IOAs in Detect
OWNER:        HuntPack
VERSION:      v0.3 - 2026-06-11 (re-hunt)
12

Changelog

v0.52026-07-24CQL correctness pass. All table() calls now carry an explicit row limit: the default is 200 and truncation is silent, so a capped result was indistinguishable from a complete one. Atomic-IOC sweeps (filters over 5+ hashes or C2 IPs) use limit=max so a wide infection is never silently under-scoped; behavioural hunts use limit=200, where exceeding the cap indicates the query needs tuning. Where present, event names that do not exist in the Falcon data model were corrected (e.g. ServiceInstalled is a Sysmon concept, not a Falcon event; ElfFileWritten is ELFFileWritten) — such queries could never return a row. No detection logic, fields, or IOCs changed.
v0.42026-06-29CQL syntax review (crowdstrike-logscale-v3): converted in() inside or-groups to regex alternation (avoids FunctionCallsNotSupportedInFilterExpressions) (Q12, Q16).
v0.32026-06-11Reformatted to the review-v2 fixed left-sidebar layout (scrollspy nav, collapsible TOC, cloud selector inside the CQL section, per-card Copy/Open-in-Falcon, IOC quick-copy grid). Folded in 11 Jun PRODAFT/Krebs/THN intel: --spread/--wipe flags, Garble, 5 builds, named toolkit + Velociraptor C2 (new Q16), Cisco/VMware Aria targets, dwell corrected to 2–6 weeks, ~478 victims, AI-assisted ops, LARVA-368 attribution.
v0.22026-06-11Re-hunt: refreshed encryptor (Go, .i8p14s, self-propagation), corrected initial access to FortiOS CVE-2024-55591, added BYOVD/event-log/cred-access/SMB/exfil queries (8→15), real seed IOCs, Storm-2697 attribution.
v0.12026-05-16Initial HuntPack: 8 CQL queries, 4 IOA candidates, hardening, coverage map. Broad appliance framing (FortiOS/SonicWall/Cisco ASA), encryptor extension unknown.
13

References

TierSourceUsed For
1Microsoft — Self-propagating Go encryptor (Storm-2697)Encryptor internals, --spread/--wipe, Garble
1PRODAFT — Inside the Phantom Mantis OperationLARVA-368 attribution, affiliate panel, 5 builds, AI-assisted
1The Hacker News (11 Jun 2026) — 478 victims, worm-like spreadConsolidated TTP roundup, toolkit, geography
1KrebsOnSecurity — Who Runs The GentlemenOperator attribution (A. Yapaev)
2Huntress — Defense Evasion TTPsBYOVD (All.exe/ThrottleBlood.sys), log clearing, Defender disable
2Group-IB — How Hastalamuerte OperatesAttack methods, tooling
2Check Point — Thus Spoke…The GentlemenCVE set, NTLM relay, exploitation pipeline
2Halcyon · NCC Group · ZeroFoxScale, GPO manipulation, multi-channel extortion, same-day patch
3Hunt.io — Proton66 toolkit · SocRadar — Rocket leak176.120.22.127, geography, leak analysis
3Bedrock-Safeguard — gentlemen-decryptor · CISA KEV · MITRE ATT&CKApril decryptor, CVE-2024-55591, technique reference

HuntPack v0.3 · The Gentlemen / Storm-2697 · Generated 2026-06-11 · Defensive use only — no exploit code or offensive tradecraft. Validate field names and tune exclusions in your tenant before promoting any query to alerting. Network IOCs rotate quickly — re-hunt weekly while this campaign remains active.