Ungentlemanly Behavior: Insights Into a Ransomware Operation
Sophos, Tuesday, September 1st, 2026
Sophos analyzes 15 intrusions by GOLD SHERWOOD affiliates running The Gentlemen ransomware-as-a-service scheme.
Sophos researchers analyzed 15 intrusions carried out by GOLD SHERWOOD affiliates operating The Gentlemen ransomware-as-a-service scheme.
Initial access came through firewall vulnerabilities and compromised VPN credentials, after which the actors escalated privileges quickly using native Windows utilities and legitimate administrative tools.
They staged malicious binaries in the C:\PerfLogs directory, exfiltrated data with tools such as Rclone, and deployed custom EDR-killing software to disable security products before encrypting files.
Sophos recommends prioritizing multi-factor authentication, patching internet-facing systems, monitoring administrative changes and detecting suspicious exfiltration and backup-tampering activity.