The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours
Brief
The Gentlemen ransomware operation is moving from access to full network encryption at striking speed. In some intrusions, attackers disabled defenses and recovery services before deploying ransomware in less than 24 hours across enterprises.
The group runs as a ransomware-as-a-service operation, meaning affiliates can strike organizations they can reach. Its double-extortion approach adds pressure: files are stolen first, then encrypted, leaving victims facing a data leak as well as operational disruption.
Analysts at Sophos examined 15 incidents linked to the group, tracked as GOLD SHERWOOD, and found a repeatable playbook.
The findings show how a small window after a suspicious login can quickly become a business-wide outage.
