The Gentlemen — Ransomware Hunt & Hardening Pack
.i8p14s). Defensive hunt & harden pack — no exploit code.Executive Summary
"The Gentlemen" (Microsoft Storm-2697; PRODAFT Phantom Mantis) is a professionalized, Russian-speaking double-extortion RaaS operation and one of 2026's most active groups — ~478 published victims to date and roughly 10% of all ransomware activity in April 2026. Access of choice is mass-exploitation of edge appliances, chiefly FortiOS/FortiProxy via CVE-2024-55591 plus brute-forced FortiGate VPN credentials, with Cisco and VMware estates also in scope.
After access, operators run internal AD reconnaissance, steal credentials with commodity stealers, disable endpoint defenses (including kernel-level BYOVD EDR-kill via All.exe + ThrottleBlood.sys), clear event logs, and deploy a Go-based, Garble-obfuscated, self-propagating encryptor (extension .i8p14s, note README-GENTLEMEN.txt). Its --spread flag turns it into an SMB worm; --wipe destroys recovery artifacts. Double-extortion data theft runs through rclone to MEGA. The lead operator (LARVA-368) relies heavily on AI for tooling and post-exploitation, and the group runs a multi-channel extortion model (ransom + email + phone).
net group "Domain Admins", nltest /dclist:). Q5 is the highest-fidelity early detection. Q9 (SMB self-propagation) and Q10 (BYOVD EDR-kill) are the "impact is imminent" signals — escalate on any hit.
Source Review & Intel Refresh
This pack was re-hunted on 2026-06-11 against intel published after the original 2026-05-16 build — Microsoft's 28 May encryptor deep-dive, the PRODAFT "Inside the Phantom Mantis Operation" report and Krebs attribution (both 11 Jun), plus Huntress/Group-IB/Check Point/Halcyon/NCC/ZeroFox analyses and the May "Rocket.Chat" leak. Several earlier assumptions were corrected and the coverage gap list shrank.
| Area | Original (2026-05-16) | Updated (2026-06-11) |
|---|---|---|
| Initial access | FortiOS / SonicWall / Cisco ASA (broad) | FortiOS CVE-2024-55591 + VPN brute force is primary; Cisco and VMware Aria Operations confirmed in the leak; SonicWall/Oracle EBS discussed but not corroborated as used. |
| Encryptor | Unknown; extension "TBD" | Known: Go (Garble-obfuscated), 5 builds — Windows, Linux, ESXi, Windows XP+, LVM; ext .i8p14s; X25519 + XChaCha20; --spread (SMB worm) & --wipe (anti-recovery) flags. |
| Tooling | SharpHound, AnyDesk, generic stealers | Adds NetExec, RelayKing, TaskHound, PrivHound, CertiHound (recon/cert/priv-esc), EDRStartupHinder, gfreeze, glinker (evasion), and Velociraptor as C2 (new Q16). |
| Attribution | Unattributed | Storm-2697 / Phantom Mantis; lead LARVA-368 (hastalamuerte, zeta88, ArmCorp, nobody0, santamuerte); named by Krebs as Alexander A. Yapaev (Izhevsk, RU); AI-assisted ops; active since Mar 2025. |
| Dwell time | ~48 hours | 2–6 weeks from initial access to encryption (focus on VMware-heavy estates). |
| Queries | 8 (5 gaps) | 16 — closed event-log clearing, credential access, SMB spread, BYOVD, exfil, and named-toolkit/C2 gaps. |
Source tiers
| Tier | Source | Key Finding |
|---|---|---|
| Primary | Microsoft Security Blog (28 May) | Self-propagating Go encryptor; --spread/--wipe; Garble; tracked as Storm-2697 |
| Primary | PRODAFT — Inside the Phantom Mantis Operation | LARVA-368 attribution, affiliate panel, 5 ransomware builds, 90/10 split, AI-assisted |
| Secondary | Huntress / Group-IB / Check Point | BYOVD (All.exe + ThrottleBlood.sys), log clearing, Defender disable, CVE set, NTLM relay |
| Secondary | Halcyon / NCC Group / ZeroFox | ~10% of April activity, GPO manipulation, multi-channel extortion, same-day patch after decryptor |
| Tertiary | Hunt.io / SocRadar / KELA / Vectra | Proton66 open-dir toolkit (176.120.22.127), Rocket leak analysis, geography |
Confidence: HIGH — corroborated across vendor labs, a national-CERT-grade leak analysis, and Microsoft. Network IOCs are sparse and short-lived (the crew rotates infrastructure and several details derive from a single leak), so behavioral queries (Q1, Q5, Q9, Q10) carry the durable coverage.
Hunt Brief & Attack Chain
Working hypothesis: If The Gentlemen are active, the earliest endpoint-visible chain is a VPN-pool interactive logon followed by built-in AD enumeration on the same host, escalating over days/weeks into credential theft, BYOVD EDR-kill, event-log clearing, SMB self-propagation, rclone exfil, and .i8p14s encryption.
Identity
| Category | Ransomware-as-a-Service (double extortion); active since March 2025 (affiliate/ArmCorp), independent RaaS from July 2025 |
| Attribution | Storm-2697 (Microsoft) / Phantom Mantis (PRODAFT). Lead operator LARVA-368 — aliases hastalamuerte, zeta88, ArmCorp, nobody0, santamuerte; named by Brian Krebs as Alexander A. Yapaev (Izhevsk, RU). ~9 operators; 90/10 affiliate split; AI-assisted development |
| Scale / geography | ~478 victims (Ransomware.Live); ~10% of all ransomware activity in April 2026. Only ~13% US — top: Thailand, UK, Brazil, Germany, India |
| Tooling | SharpHound/BloodHound, AdFind, NetExec, RelayKing, TaskHound, PrivHound, CertiHound, Velociraptor (C2), G-BOT/SystemBC, Phemedrone v2.3.2, LummaC2, XenAllPasswordPro, DumpBrowserSecrets, EDRStartupHinder, gfreeze, glinker, All.exe + ThrottleBlood.sys (BYOVD), rclone, AnyDesk/ScreenConnect |
Initial access vectors
| Vector | CVE / Method | Notes |
|---|---|---|
| Fortinet FortiOS / FortiProxy (mgmt interface) | CVE-2024-55591 — auth bypass (primary) | Admin session / foothold |
| FortiGate SSL VPN | Credential brute-force / reuse (~1,000 VPNs; e.g. gentlemen25, gentle26) | Valid VPN credential pairs |
| Secondary (track patched) | CVE-2025-32433 (Erlang/OTP SSH), CVE-2025-33073 (NTLM relay/SMB) | Lateral / priv-esc enablers |
| Also weaponized (per leak) | VMware Aria Operations, Cisco, Microsoft flaws | Backup & management-controller abuse, NTLM relay workflows |
Attack chain
| # | Step | Telemetry | Hunt Angle |
|---|---|---|---|
| 1 | FortiOS exploit / VPN brute-force → internal access | Appliance logs; UserLogon | VPN-pool logon (Q5) |
| 2 | AD recon (net/nltest/dsquery/AdFind/NetExec/SharpHound) | ProcessRollup2 | Q1, Q2, Q3, Q5, Q16 |
| 3 | Credential theft (LSASS, browser stealers) | ProcessRollup2 | Q12 |
| 4 | C2 / persistence (Velociraptor, G-BOT/SystemBC, RMM) | ProcessRollup2, NetworkConnectIP4 | Q4, Q16 |
| 5 | Defense evasion: BYOVD EDR-kill, Defender off, log clear, msimg32 sideload | ProcessRollup2, PeFileWritten | Q7, Q10, Q11, Q13 |
| 6 | Self-propagation over SMB (--spread) | ProcessRollup2 | Q9 |
| 7 | Exfil (rclone→MEGA), inhibit recovery (vssadmin, --wipe), encrypt (.i8p14s) | ProcessRollup2, file writes | Q14, Q6, Q8 |
Consolidated IOC Table
| Type | Value | Conf. | Action | Context |
|---|---|---|---|---|
| SHA256 | 22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67 | HIGH | Prevent | Locker / payload sample |
| IPv4 | 176.120.22.127 | MED | Detect | Proton66 bulletproof host; open-dir operator toolkit (Hunt.io); may be reassigned |
| File ext | .i8p14s | HIGH | Detect | Encrypted-file marker (Q8) |
| Filenames | README-GENTLEMEN.txt, gentlemen.bmp, All.exe, ThrottleBlood.sys | HIGH | Detect | Note / wallpaper / BYOVD kit (Q8, Q10) |
| DLL artifact | msimg32.dll outside System32/SysWOW64 | MED | Detect | DLL sideloading (Q13) |
| Behavior | Encryptor run with --spread / --wipe | HIGH | Detect | SMB worm / anti-recovery (Q9, Q6) |
| YARA strings | "Silent mode" · "Encrypt only mapped...shares" · "README-GENTLEMEN.txt" · "gentlemen.bmp" · "[+] Encryption started" | HIGH | Hunt | ≥4 matches = confirmed locker sample |
ATT&CK Mapping
| Tactic | Technique | Sub-technique / Tool | Hunt Q |
|---|---|---|---|
| Initial Access | T1190 / T1110 | FortiOS CVE-2024-55591 / VPN brute force | (appliance logs) |
| Initial Access / Persistence | T1078 | Valid Accounts via VPN | Q5 |
| Discovery | T1087.002 / T1069.002 / T1482 / T1018 | AD account/group/trust/DC discovery; NetExec | Q1, Q5, Q16 |
| Discovery | T1482 + S0521 | SharpHound / BloodHound | Q2, Q3 |
| Credential Access | T1003.001 / T1555.003 / T1649 | LSASS minidump / browser stealers / cert abuse (CertiHound) | Q12, Q16 |
| Command & Control | T1219 / T1071 | Velociraptor, G-BOT/SystemBC, RMM | Q4, Q16 |
| Defense Evasion | T1574.002 | msimg32.dll DLL sideloading | Q13 |
| Defense Evasion | T1562.001 / .004 / .010 | Defender disable / SMB1 / LSA / firewall; EDRStartupHinder, gfreeze, glinker | Q7, Q10 |
| Defense Evasion / Priv Esc | T1562.001 + T1068 + T1543.003 | BYOVD — All.exe + ThrottleBlood.sys | Q10 |
| Defense Evasion | T1070.001 | Clear Security/System/Application logs | Q11 |
| Lateral Movement | T1021.002 / T1570 / T1021.001 | Self-propagation over SMB (--spread) | Q9 |
| Exfiltration | T1567.002 / T1048 | rclone → MEGA | Q14 |
| Impact | T1490 | vssadmin / wbadmin / bcdedit / --wipe | Q6 |
| Impact | T1486 | Encryption — .i8p14s mass file writes | Q8 |
| All (indicators) | — | Known hash / C2 IP sweep | Q15 |
CrowdStrike LogScale CQL Hunt Queries
SyntheticProcessRollup2. Run over 7–30 days first (dwell is 2–6 weeks, so 30–90 days for historical sweeps), tune FP notes, and validate before promoting any IOA to Prevent. Q5 and Q9 require an env edit (your VPN CIDRs / deploy allow-list).Looks for: built-in AD enumeration (privileged groups, DCs, trusts) post-compromise. FP: sysadmin scripts, helpdesk, AD health checks from PAW/JIT — allow-list known admin AIDs.
// HUNT: The Gentlemen — AD discovery (T1087.002/T1069.002/T1482/T1018) // CONF: medium FP: medium COST: low | TIMEFRAME: last 7d // FP NOTES: net.exe by admins from PAW/JIT; nltest in AD health scripts; documented dsquery modules #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | in(field=FileName, values=["net.exe","net1.exe","nltest.exe","dsquery.exe","whoami.exe","adfind.exe"], ignoreCase=true) | CommandLine = /(group\s+"?Domain Admins"?|group\s+"?Enterprise Admins"?|\/domain\b|\/dclist|\/domain_trusts|\/groups|\/all|enterprise admins|domain admins)/i | groupBy([aid, ComputerName, UserName], function=[count(), collect([ImageFileName, CommandLine], limit=20)]) | sort(_count, order=desc)
Looks for: SharpHound/Invoke-BloodHound AD-path mapping — tool-specific strings are high-fidelity. FP: authorized red-team — allow-list operator AIDs.
// HUNT: The Gentlemen — SharpHound/BloodHound (T1482, S0521) // CONF: high FP: low COST: low | TIMEFRAME: last 14d // FP NOTES: authorized internal red-team / pentest (allow-list operator AIDs) #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | (ImageFileName = /\\sharphound(\.exe|\.ps1)?$/i or CommandLine = /(Invoke-BloodHound|SharpHound\s|-CollectionMethod\s+(All|Default|DCOnly|LoggedOn|Session|ACL|Trusts)|-ZipFileName|-OutputDirectory\s+.*bloodhound)/i) | table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200) | sort(@timestamp, order=desc)
Looks for: canonical SharpHound JSON/ZIP output names — diagnostic even when the binary is renamed. FP: authorized red-team only.
// HUNT: The Gentlemen — BloodHound output artifacts (T1213, T1482) // CONF: high FP: very low COST: low | TIMEFRAME: last 14d // FP NOTES: authorized red-team only #event_simpleName = /NewExecutableWritten|PeFileWritten|NewScriptWritten/ | TargetFileName = /(_computers\.json|_groups\.json|_users\.json|_domains\.json|_gpos\.json|_ous\.json|_sessions\.json|_containers\.json|BloodHound\.zip|\d{14}_BloodHound\.zip)$/i | table([@timestamp, aid, ComputerName, UserName, TargetFileName, ContextBaseFileName], limit=200) | sort(@timestamp, order=desc)
Looks for: commodity RMM agents used as persistence redundant to G-BOT/SystemBC/Velociraptor C2. FP: legitimate IT/MSP tooling — edit the allow-list for your sanctioned RMM and vendor support AIDs.
// HUNT: The Gentlemen — Unauthorized RMM (T1219) // CONF: medium FP: high COST: low | TIMEFRAME: last 30d // FP NOTES: allow-list sanctioned RMM (NinjaOne, Kaseya, ConnectWise) + vendor support #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | in(field=FileName, values=[ "AnyDesk.exe","ScreenConnect.ClientService.exe","ScreenConnect.WindowsClient.exe", "AteraAgent.exe","Splashtop-streamer.exe","SRService.exe","TeamViewer.exe", "TeamViewer_Service.exe","rustdesk.exe","Action1_agent.exe","PulsewayMonitor.exe", "FleetDeskAgent.exe","SyncroService.exe","ZA_Connect.exe","ITarian_Service.exe", "AeroAdmin.exe","ammyy.exe","Supremo.exe","LogMeIn.exe","GoToAssist.exe", "rport.exe","MeshAgent.exe","ngrok.exe","TacticalRMM.exe","RemotePCService.exe", "DWAgent.exe","DWRCS.exe","Quasar.exe","Optitune.exe" ], ignoreCase=true) | groupBy([aid, ComputerName, FileName, UserName], function=[count(), selectFromMin(field=@timestamp, include=[CommandLine, ParentBaseFileName, ImageFileName])]) | sort(_count, order=desc)
Looks for: a Type-10 logon from a VPN-pool IP followed within 60 min by AD enumeration on the same aid — the earliest Gentlemen chain. Correlation cuts FPs 10–50× vs. either signal alone. FP: legitimate remote admin — allow-list jump hosts.
10.200.0.0/16 and 172.16.50.0/24 with your actual VPN-assigned client pool subnet(s).// HUNT: The Gentlemen — VPN-pool logon then AD recon (T1078 + T1087.002) // CONF: high FP: medium COST: medium | TIMEFRAME: last 7d // FP NOTES: legit remote admin; REPLACE the CIDRs with your VPN client pool(s); allow-list jump hosts #event_simpleName = UserLogon | LogonType = 10 | cidr(RemoteAddressIP4, subnet=["10.200.0.0/16","172.16.50.0/24"]) | logonTime := @timestamp | logonHost := ComputerName | logonUser := UserName | logonSrc := RemoteAddressIP4 | join(query={ #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | in(field=FileName, values=["net.exe","net1.exe","nltest.exe","whoami.exe","dsquery.exe","adfind.exe"], ignoreCase=true) | CommandLine = /(Domain Admins|Enterprise Admins|\/dclist|\/domain_trusts|\/groups|\/all)/i | reconTime := @timestamp | reconCmd := CommandLine | reconFile := FileName }, field=[aid], include=[reconTime, reconCmd, reconFile]) | test((reconTime - logonTime) <= 3600000) | test((reconTime - logonTime) >= 0) | table([logonTime, logonHost, logonUser, logonSrc, reconFile, reconCmd, reconTime], limit=200) | sort(logonTime, order=desc)
Looks for: pre-encryption recovery destruction — VSS/backup/catalog deletion, recovery disable, and the encryptor's own --wipe flag. FP: some backup tools call vssadmin — allow-list backup-server AIDs.
// HUNT: The Gentlemen — Inhibit System Recovery (T1490) // CONF: high FP: low COST: low | TIMEFRAME: last 30d // FP NOTES: some backup tools call vssadmin (allow-list backup-server AIDs) #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | (CommandLine = /vssadmin(\.exe)?\s+delete\s+shadows/i or CommandLine = /wmic\s+shadowcopy\s+delete/i or CommandLine = /wbadmin\s+delete\s+(catalog|systemstatebackup|backup)/i or CommandLine = /bcdedit.*\/set.*(recoveryenabled\s+no|bootstatuspolicy\s+ignoreallfailures)/i or CommandLine = /Diskshadow.*delete\s+shadows/i or CommandLine = /\s--wipe\b/i) | table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200) | sort(@timestamp, order=desc)
Looks for: Defender disable / broad exclusions, AV/EDR service stop, and host weakening — SMB1 re-enable, LSA anonymous loosening, firewall off — that precedes spread/encryption. FP: authorized AV change windows, SCCM/Intune scripts — allow-list management hosts.
// HUNT: The Gentlemen — Disable tools + weaken host (T1562.001/.004/.010) // CONF: medium-high FP: medium COST: low | TIMEFRAME: last 14d // FP NOTES: authorized AV change windows; SCCM/Intune compliance scripts (allow-list mgmt AIDs) #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | (CommandLine = /Set-MpPreference\s+-DisableRealtimeMonitoring\s+\$?(true|1)/i or CommandLine = /Add-MpPreference\s+-ExclusionPath/i or CommandLine = /Set-MpPreference\s+-(DisableIOAVProtection|DisableScriptScanning|DisableBehaviorMonitoring|MAPSReporting\s+0)/i or CommandLine = /sc(\.exe)?\s+(stop|delete|config).*(WinDefend|Sense|MsSecFlt|wuauserv|BITS|CSFalconService|SentinelAgent|elastic-agent|XAgentSvc)/i or CommandLine = /taskkill.*\/IM\s+(MsMpEng|CSFalconService|SentinelAgent|Cyserver|elastic-agent|XAgent)\.exe/i or CommandLine = /reg\s+(add|delete).*DisableAntiSpyware/i or CommandLine = /netsh\s+advfirewall\s+set\s+(allprofiles|currentprofile)\s+state\s+off/i or CommandLine = /(Enable-WindowsOptionalFeature.*SMB1|sc(\.exe)?\s+config\s+(mrxsmb10|lanmanserver).*SMB1|reg\s+add.*LanmanServer\\Parameters.*SMB1.*\/d\s+1)/i or CommandLine = /reg\s+add.*\\Lsa\b.*(RestrictAnonymous|everyoneincludesanonymous|LimitBlankPasswordUse)/i) | table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200) | sort(@timestamp, order=desc)
Looks for: the encryptor's published artifacts — .i8p14s extension, README-GENTLEMEN.txt, gentlemen.bmp. Campaign-specific, so high confidence (no longer a tripwire). FP: mass-write thresholds may match backup/archive tools — allow-list those AIDs.
// HUNT: The Gentlemen — Encryption artifacts (.i8p14s + note) (T1486) // CONF: high FP: low COST: low | TIMEFRAME: rolling 24h // FP NOTES: note/wallpaper names are campaign-specific; backup tools bulk-write other extensions #event_simpleName = /NewExecutableWritten|PeFileWritten|NewScriptWritten/ | (TargetFileName = /\.i8p14s$/i or TargetFileName = /\\README-GENTLEMEN\.txt$/i or TargetFileName = /\\gentlemen\.bmp$/i) | groupBy([aid, ComputerName, ContextBaseFileName], function=[count(), selectFromMin(field=@timestamp, include=[TargetFileName, UserName])]) | sort(_count, order=desc)
Looks for: the Go encryptor authenticating with harvested creds and copying itself to remote ADMIN$/C$ over SMB, then executing remotely — plus the explicit --spread worm flag. FP: software-deployment tooling (PsExec/SCCM) copies to admin shares — allow-list deploy-server AIDs.
// HUNT: The Gentlemen — Self-propagation over SMB (T1021.002 / T1570) // CONF: medium-high FP: medium COST: medium | TIMEFRAME: last 7d // FP NOTES: SCCM / PDQ Deploy / PsExec admin tooling (allow-list deploy AIDs) #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | (CommandLine = /(copy|xcopy|robocopy|cmd\s+\/c\s+copy).*\\\\[^\\]+\\(admin\$|c\$|ipc\$)/i or CommandLine = /net\s+use\s+\\\\[^\\]+\\(admin\$|c\$|ipc\$)/i or CommandLine = /(psexec|paexec|psexesvc).*\\\\[^\\]+/i or CommandLine = /wmic\s+\/node:.*process\s+call\s+create/i or CommandLine = /\\\\[^\\]+\\(admin\$|c\$)\\.*\.exe/i or CommandLine = /\s--spread\b/i) | groupBy([aid, ComputerName, UserName], function=[count(), collect([CommandLine, ImageFileName, ParentBaseFileName], limit=25)]) | sort(_count, order=desc)
Looks for: the custom kill tool (All.exe) + vulnerable driver (ThrottleBlood.sys) and the group's named evasion utilities (EDRStartupHinder, gfreeze, glinker), plus a .sys service launched from a user-writable path. FP: very low — legit drivers install to System32\drivers via signed installers.
// HUNT: The Gentlemen — BYOVD EDR-kill (T1562.001 / T1068 / T1543.003) // CONF: high FP: low COST: low | TIMEFRAME: last 30d // FP NOTES: a .sys service from TEMP/ProgramData/user path is almost always malicious // Branch A — named tooling / driver as process or in command line #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | (FileName = /^(All|EDRStartupHinder|gfreeze|glinker)\.exe$/i or CommandLine = /(ThrottleBlood\.sys|\\All\.exe)/i or CommandLine = /sc(\.exe)?\s+create.*binPath=.*\\(temp|programdata|users|appdata)\\.*\.sys/i or CommandLine = /(fltMC|sc(\.exe)?\s+stop).*(CSAgent|CSFalcon|SentinelAgent|WdFilter|elastic)/i) | table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, CommandLine, ParentBaseFileName], limit=200) | sort(@timestamp, order=desc) // Branch B (run separately) — driver written outside the standard driver store // #event_simpleName = /NewExecutableWritten|PeFileWritten/ // | TargetFileName = /\.sys$/i // | TargetFileName != /\\Windows\\System32\\drivers\\/i // | TargetFileName != /\\Windows\\System32\\DriverStore\\/i // | table([@timestamp, aid, ComputerName, TargetFileName, ContextBaseFileName], limit=200)
Looks for: wevtutil cl, Clear-EventLog, or WMI event-log clears — confirmed Gentlemen cleanup. FP: rare in production; allow-list imaging/provisioning AIDs.
// HUNT: The Gentlemen — Clear Windows Event Logs (T1070.001) // CONF: high FP: low COST: low | TIMEFRAME: last 14d // FP NOTES: golden-image / provisioning pipelines may clear logs (allow-list) #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | (CommandLine = /wevtutil\s+(cl|clear-log)\b/i or CommandLine = /Clear-EventLog\b/i or CommandLine = /wmic\s+nteventlog.*ClearEventlog/i or CommandLine = /(Get-WinEvent|Get-EventLog).*\|\s*.*Clear/i) | table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200) | sort(@timestamp, order=desc)
Looks for: comsvcs.dll MiniDump of LSASS and commodity browser stealers (Phemedrone, LummaC2, XenAllPasswordPro, DumpBrowserSecrets). FP: rare IT diagnostics dump processes — pair with Falcon native CredentialDumping detections.
// HUNT: The Gentlemen — Cred access LSASS + browsers (T1003.001 / T1555.003) // CONF: medium-high FP: medium COST: low | TIMEFRAME: last 14d // FP NOTES: comsvcs MiniDump rarely legit; stealer names = high TP; pair with Falcon native #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | (CommandLine = /comsvcs\.dll.*MiniDump/i or CommandLine = /rundll32.*comsvcs.*\s+\d+\s+.*\.dmp/i or CommandLine = /(procdump(64)?\.exe).*lsass/i or CommandLine = /lsass.*\.dmp/i or FileName = /^(Phemedrone|XenAllPasswordPro|DumpBrowserSecrets|ChromeAppBound|LummaC2|mimikatz|nanodump)\.exe$/i) | table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, CommandLine, ParentBaseFileName], limit=200) | sort(@timestamp, order=desc)
Looks for: a msimg32.dll written anywhere outside System32/SysWOW64 — search-order hijack IOC. FP: a few apps ship their own copy — verify the writing process and signer.
// HUNT: The Gentlemen — msimg32.dll DLL sideloading (T1574.002) // CONF: high FP: low COST: low | TIMEFRAME: last 30d // FP NOTES: verify writing process and DLL signature before escalating #event_simpleName = /NewExecutableWritten|PeFileWritten/ | TargetFileName = /\\msimg32\.dll$/i | TargetFileName != /\\Windows\\System32\\/i | TargetFileName != /\\Windows\\SysWOW64\\/i | TargetFileName != /\\Windows\\WinSxS\\/i | table([@timestamp, aid, ComputerName, UserName, TargetFileName, ContextBaseFileName], limit=200) | sort(@timestamp, order=desc)
Looks for: rclone command-line flags and MEGA remotes used to stage double-extortion theft — diagnostic even if the binary is renamed. FP: some IT uses rclone for cloud sync — allow-list sanctioned backup jobs.
// HUNT: The Gentlemen — Exfil via rclone to MEGA (T1567.002 / T1048) // CONF: medium-high FP: medium COST: low | TIMEFRAME: last 14d // FP NOTES: allow-list sanctioned backup jobs/AIDs; mega remote + copy/sync = high TP #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | (FileName = /^rclone\.exe$/i or CommandLine = /rclone\s+(copy|sync|move|lsd|config)/i or CommandLine = /(mega\.nz|mega:|--config\s+.*rclone\.conf)/i or CommandLine = /\b(copy|sync)\b.*\b(mega|b2|s3|gdrive|dropbox|onedrive):/i) | groupBy([aid, ComputerName, UserName], function=[count(), collect([CommandLine, ImageFileName, ParentBaseFileName], limit=20)]) | sort(_count, order=desc)
Looks for: direct match on the published encryptor hash and the Proton66 C2 IP. Indicators rotate, so absence is inconclusive — keep refreshing from §4/§8. FP: hash is definitive; the IP may be reassigned — corroborate context.
// HUNT: The Gentlemen — indicator sweep (hash + historic C2 IP) // CONF: high FP: very low (hash) / low (IP) | TIMEFRAME: last 30-90d // Branch A — encryptor hash #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | SHA256HashData = "22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67" | table([@timestamp, aid, ComputerName, UserName, ImageFileName, CommandLine, SHA256HashData], limit=200) // Branch B (run separately) — Proton66 C2 IP // #event_simpleName = NetworkConnectIP4 // | RemoteAddressIP4 = "176.120.22.127" // | table([@timestamp, aid, ComputerName, ContextBaseFileName, RemoteAddressIP4, RemotePort], limit=200)
Looks for: the group's named utilities — recon/cert/priv-esc (NetExec, RelayKing, TaskHound, PrivHound, CertiHound), and Velociraptor abused as C2. FP: Velociraptor is a legitimate DFIR tool — allow-list sanctioned IR/forensics AIDs; NetExec/CME may appear in authorized pentests.
// HUNT: The Gentlemen — named toolkit + Velociraptor C2 (T1219/T1018/T1649) // CONF: high FP: low-medium COST: low | TIMEFRAME: last 30d // FP NOTES: Velociraptor is legit DFIR (allow-list IR AIDs); NetExec/CME in authorized pentests #event_simpleName = /ProcessRollup2|SyntheticProcessRollup2/ | (FileName = /^(nxc|netexec|crackmapexec|RelayKing|TaskHound|PrivHound|CertiHound|velociraptor)\.exe$/i or CommandLine = /(netexec|crackmapexec|\bnxc\b|RelayKing|TaskHound|PrivHound|CertiHound)/i or CommandLine = /velociraptor.*(\-\-config|client|gui|artifacts collect)/i) | groupBy([aid, ComputerName, UserName], function=[count(), collect([FileName, CommandLine, ParentBaseFileName], limit=25)]) | sort(_count, order=desc)
CrowdStrike Custom IOA Recommendations
Build in Endpoint Security → Custom IOA Rules. Start in Detect; promote to Prevent after 14 days at <5% FP on a canary group. Custom IOA fields use PCRE.
| IOA | Field Patterns (PCRE) | MITRE | Action / Severity |
|---|---|---|---|
| IOA-1 · vssadmin delete shadows | Image .*\\vssadmin\.exe$; CmdLine .*delete\s+shadows.* | T1490 | Detect → Block · High |
| IOA-2 · Defender disabled via PowerShell | Image .*\\(powershell|pwsh)\.exe$; CmdLine .*Set-MpPreference\s+-DisableRealtimeMonitoring\s+\$?(true|1).* | T1562.001 | Detect · High |
| IOA-3 · net.exe enumerating Domain Admins | Image .*\\(net|net1)\.exe$; CmdLine .*group\s+"?(Domain Admins|Enterprise Admins)"?\s+/domain.* | T1069.002 | Detect only · Med |
| IOA-4 · RMM from non-Program-Files | Image .*\\(AnyDesk|rustdesk|AteraAgent|ScreenConnect\.ClientService|MeshAgent)\.exe$; exclude ^C:\\Program Files.* | T1219 | Detect · High |
| IOA-5 · BYOVD driver service (non-standard path) | Image .*\\sc\.exe$; CmdLine .*create.*binPath=.*\\(Temp|ProgramData|Users|AppData)\\.*\.sys.* | T1068 / T1543.003 | Detect → Block · Critical |
| IOA-6 · Event log cleared via wevtutil | Image .*\\wevtutil\.exe$; CmdLine .*\s(cl|clear-log)\s+(Security|System|Application).* | T1070.001 | Detect · High |
Machine-Readable IOC Appendix
Grouped IOC Quick-Copy
One-click blocks for Falcon IOC Management, scheduled searches, or egress rules. Network IOCs are short-lived — hunt and corroborate.
type,value,action,severity,expiration,description,tags sha256,22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67,prevent,critical,2027-06-11,The Gentlemen - locker/payload,campaign:TheGentlemen ipv4,176.120.22.127,detect,medium,2026-07-11,The Gentlemen - Proton66 C2 (30d; may be reassigned),campaign:TheGentlemen sha256,REPLACE_WITH_SHA256,prevent,critical,2027-06-11,The Gentlemen - encryptor variant,campaign:TheGentlemen domain,REPLACE_WITH_LEAK_SITE,detect,high,2026-09-09,The Gentlemen - data-leak site,campaign:TheGentlemen
Encryptor run with --spread (SMB worm) or --wipe (anti-recovery) copy/robocopy/psexec to \\host\ADMIN$ or \\host\C$ (self-propagation) All.exe + ThrottleBlood.sys / sc create binPath=...\Temp\...\.sys (BYOVD) wevtutil cl Security|System|Application (log clearing) comsvcs.dll MiniDump / browser stealer exec (cred access) msimg32.dll written outside System32 (DLL sideload) rclone copy/sync to mega: (exfil) .i8p14s file writes + README-GENTLEMEN.txt + gentlemen.bmp (encryption)
All.exe # BYOVD EDR killer ThrottleBlood.sys # vulnerable driver EDRStartupHinder.exe # EDR evasion gfreeze.exe # evasion glinker.exe # evasion NetExec / nxc # AD discovery / share enum RelayKing.exe # NTLM relay TaskHound.exe # scheduled-task abuse PrivHound.exe # priv-esc path mapping CertiHound.exe # AD CS / cert abuse velociraptor.exe # abused as C2 DumpBrowserSecrets.exe; Phemedrone; LummaC2; XenAllPasswordPro
CVE-2024-55591 # FortiOS/FortiProxy auth bypass (PRIMARY) CVE-2025-32433 # Erlang/OTP SSH CVE-2025-33073 # NTLM relay / SMB # Also weaponized per leak: VMware Aria Operations, Cisco, Microsoft # Egress: block MEGA (mega.nz) + unsanctioned cloud storage # Disable SMBv1 fleet-wide; alert on re-enable
Hardening Recommendations
Patch CVE-2024-55591 now
- Confirm FortiOS/FortiProxy firmware vs. Fortinet PSIRT; verify CVE-2025-32433 and CVE-2025-33073 remediated; review Cisco and VMware Aria Operations exposure.
- Force MFA on all VPN auth (FIDO2 preferred); SMS is inadequate against cookie theft and brute force.
- Rotate all FortiGate VPN + local appliance credentials; block reuse-password patterns (e.g.
gentlemen25,gentle26). - Restrict appliance mgmt/admin UI to a management VLAN — never expose
/remote/loginor the mgmt interface (the CVE-2024-55591 surface). - Rate-limit / geo-fence SSL VPN logins; alert on VPN brute-force; forward appliance logs to SIEM (≥90-day retention).
- Enable Microsoft Vulnerable Driver Blocklist (HVCI) + Falcon vulnerable-driver protection to break BYOVD (
ThrottleBlood.syset al.). - Disable SMBv1 fleet-wide and alert on re-enable — the encryptor self-propagates over SMB.
- Enable Falcon Tamper Protection; confirm the sensor can't be stopped via
sc/taskkillwithout the maintenance token. - Restrict ADMIN$/C$ access from non-management hosts; monitor remote service creation (Q9). Block MEGA + unsanctioned cloud egress to disrupt rclone.
- Turn on Falcon Identity Protection — the built-in-binary recon chain lights up identity policies immediately.
- Enable PowerShell ScriptBlock (4104) + Module logging via GPO → LogScale; Sysmon on Tier-0/DCs.
- Audit policy: Distribution/Security Group Management + Sensitive Privilege Use on DCs; alert on event-log clears (1102/104); watch GPO changes (Gentlemen manipulate GPOs).
- App allow-listing (AppLocker/WDAC) blocking AnyDesk/ScreenConnect/RustDesk/Atera unless sanctioned; restrict Velociraptor to IR hosts.
- LSA Protection (RunAsPPL) + Credential Guard to neuter LSASS dumping/browser-cred theft; don't allow RestrictAnonymous to be loosened.
- LAPS, Tier 0/1/2 admin model, disable LLMNR/NBT-NS/WPAD.
- Immutable / offline backups (3-2-1) not deletable by a Domain Admin credential; monitor new local-admin creation (4720/4732); limit VPN-pool interactive logons via Auth Policy Silos.
Detection Coverage Map
| Technique | Name | CQL | IOA | Coverage |
|---|---|---|---|---|
| T1190 / T1110 | Exploit FortiOS / VPN brute force | — | — | GAP patch + appliance logs |
| T1078 | Valid Accounts (VPN) | Q5 | — | Partial needs VPN CIDRs |
| T1087.002 / T1069.002 / T1482 / T1018 | AD discovery | Q1, Q5, Q16 | IOA-3 | Good |
| T1482 + S0521 | SharpHound / BloodHound | Q2, Q3 | — | Good |
| T1003.001 / T1555.003 / T1649 | Cred access / cert abuse | Q12, Q16 | — | Good (+ native) |
| T1219 / T1071 | RMM / Velociraptor C2 | Q4, Q16 | IOA-4 | Good |
| T1574.002 | DLL sideloading (msimg32) | Q13 | — | Good |
| T1562.001 / .004 / .010 | Disable/modify tools | Q7 | IOA-2 | Good |
| T1068 / T1543.003 | BYOVD vulnerable driver | Q10 | IOA-5 | Good |
| T1070.001 | Clear event logs | Q11 | IOA-6 | Good |
| T1021.002 / T1570 | Self-propagation over SMB | Q9 | — | Partial tune deploy allow-list |
| T1490 | Inhibit recovery / --wipe | Q6 | IOA-1 | Good |
| T1567.002 / T1048 | Exfil rclone→MEGA | Q14 | — | Good (+ egress block) |
| T1486 | Data encrypted (.i8p14s) | Q8 | — | Good extension known |
Coverage: 13 of 14 technique groups have at least partial coverage (up from 8/13). The remaining gap — the FortiOS exploit / VPN brute-force phase (T1190/T1110) — is inherently pre-endpoint; defend with patching, MFA, and appliance log review.
Hunt Summary Ticket
TITLE: Hunt — The Gentlemen Ransomware (Storm-2697 / Phantom Mantis)
SEVERITY: Critical (active RaaS, ~10% of April 2026 ransomware activity)
SCOPE: FortiGate/Cisco/VMware-exposed orgs; Windows/Linux/ESXi estates
HYPOTHESIS: FortiOS CVE-2024-55591 / VPN brute-force access -> AD recon -> cred theft ->
BYOVD EDR-kill -> log clear -> SMB self-propagation -> rclone exfil -> .i8p14s encrypt.
DWELL: 2-6 weeks initial access -> encryption (hunt 30-90d historical)
QUERIES RUN: Q1 AD disc | Q2/Q3 BloodHound | Q4 RMM | Q5 VPN->recon* | Q6 recovery/--wipe |
Q7 tamper | Q8 .i8p14s | Q9 SMB spread* | Q10 BYOVD | Q11 log clear |
Q12 cred access | Q13 msimg32 | Q14 rclone | Q15 IOC sweep | Q16 toolkit/Velociraptor
(* = requires env edit)
DO FIRST: Q5, Q9, Q10, Q6, Q8, Q11 — escalate any hit immediately
FINDINGS: <pending analyst execution>
GAPS: T1190/T1110 pre-endpoint (patch + appliance logs); network IOCs short-lived
ACTIONS: Patch CVE-2024-55591 + VPN MFA + cred rotation; HVCI vuln-driver blocklist;
disable SMBv1; deploy Q5/Q9/Q10 IOAs in Detect
OWNER: HuntPack
VERSION: v0.3 - 2026-06-11 (re-hunt)
Changelog
table() calls now carry an explicit row limit: the default is 200 and truncation is silent, so a capped result was indistinguishable from a complete one. Atomic-IOC sweeps (filters over 5+ hashes or C2 IPs) use limit=max so a wide infection is never silently under-scoped; behavioural hunts use limit=200, where exceeding the cap indicates the query needs tuning. Where present, event names that do not exist in the Falcon data model were corrected (e.g. ServiceInstalled is a Sysmon concept, not a Falcon event; ElfFileWritten is ELFFileWritten) — such queries could never return a row. No detection logic, fields, or IOCs changed.--spread/--wipe flags, Garble, 5 builds, named toolkit + Velociraptor C2 (new Q16), Cisco/VMware Aria targets, dwell corrected to 2–6 weeks, ~478 victims, AI-assisted ops, LARVA-368 attribution..i8p14s, self-propagation), corrected initial access to FortiOS CVE-2024-55591, added BYOVD/event-log/cred-access/SMB/exfil queries (8→15), real seed IOCs, Storm-2697 attribution.References
| Tier | Source | Used For |
|---|---|---|
| 1 | Microsoft — Self-propagating Go encryptor (Storm-2697) | Encryptor internals, --spread/--wipe, Garble |
| 1 | PRODAFT — Inside the Phantom Mantis Operation | LARVA-368 attribution, affiliate panel, 5 builds, AI-assisted |
| 1 | The Hacker News (11 Jun 2026) — 478 victims, worm-like spread | Consolidated TTP roundup, toolkit, geography |
| 1 | KrebsOnSecurity — Who Runs The Gentlemen | Operator attribution (A. Yapaev) |
| 2 | Huntress — Defense Evasion TTPs | BYOVD (All.exe/ThrottleBlood.sys), log clearing, Defender disable |
| 2 | Group-IB — How Hastalamuerte Operates | Attack methods, tooling |
| 2 | Check Point — Thus Spoke…The Gentlemen | CVE set, NTLM relay, exploitation pipeline |
| 2 | Halcyon · NCC Group · ZeroFox | Scale, GPO manipulation, multi-channel extortion, same-day patch |
| 3 | Hunt.io — Proton66 toolkit · SocRadar — Rocket leak | 176.120.22.127, geography, leak analysis |
| 3 | Bedrock-Safeguard — gentlemen-decryptor · CISA KEV · MITRE ATT&CK | April decryptor, CVE-2024-55591, technique reference |
HuntPack v0.3 · The Gentlemen / Storm-2697 · Generated 2026-06-11 · Defensive use only — no exploit code or offensive tradecraft. Validate field names and tune exclusions in your tenant before promoting any query to alerting. Network IOCs rotate quickly — re-hunt weekly while this campaign remains active.