{
  "Event": {
    "analysis": "1",
    "date": "2026-05-21",
    "extends_uuid": "",
    "info": "[Threat Intel] The Gentleman Ransomware | Defense Evasion TTPs Uncovered",
    "protected": false,
    "publish_timestamp": "1780284562",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780284562",
    "uuid": "bf870fb8-ded6-4287-a5f5-d67eb365e5e6",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#8f20d0",
        "local": false,
        "name": "misp-galaxy:producer=\"Huntress\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#705cef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#e7d48a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"",
        "relationship_type": ""
      },
      {
        "colour": "#7773ac",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"External Remote Services - T1133\"",
        "relationship_type": ""
      },
      {
        "colour": "#d74cce",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Bypass User Account Control - T1548.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#bf01b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#62f4c1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"",
        "relationship_type": ""
      },
      {
        "colour": "#755c09",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#59699c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#36d931",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#3970d7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#370063",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#c295b4",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:ransomware=\"the gentlemen\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003d",
        "local": false,
        "name": "rectifyq:sub-category=\"TA-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#120044",
        "local": false,
        "name": "rectifyq:sub-category=\"intrusion-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"Ransomware\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779447611",
        "to_ids": false,
        "type": "link",
        "uuid": "49ab8599-0473-4c4e-bbea-a3900451d26e",
        "value": "https://www.huntress.com/blog/the-gentlemen-ransomware-defense-evasion-ttps"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779447611",
        "to_ids": false,
        "type": "text",
        "uuid": "a7022af7-c5fc-4dfe-8b00-74a21db8d2ba",
        "value": "In April and May 2026, investigations revealed two incidents involving The Gentlemen ransomware-as-a-service operation, which has claimed over 400 victims across 70 countries since mid-2025. Both incidents demonstrated common tactics including Scheduled Tasks, PowerShell commands, and defense evasion techniques such as clearing Security, System, and Application Event Logs, disabling Microsoft Defender, and adding antivirus exclusions. A leaked internal database in early May exposed the operation's infrastructure, affiliate structure, and targeting of vulnerabilities like CVE-2024-55591. The attacks showed threat actors using RDP connections, disguised executables, SOCKS proxy connections for persistence, and domain-wide deployment via NETLOGON shares. Despite attempts to evade detection, sufficient forensic telemetry remained for analysis, revealing workstation names previously associated with Qilin ransomware and Lazarus infrastructure."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779447611",
        "to_ids": false,
        "type": "text",
        "uuid": "c4e0a2b9-cb6d-4717-bbde-7440f5df138e",
        "value": "Name: The Gentleman Ransomware | Defense Evasion TTPs Uncovered\nAuthor: AlienVault\nAdversary: The Gentlemen\nTags: [\"ransomware-as-a-service\", \"scheduled tasks\", \"trojan:win32/mptamperbulkexcl.h\", \"defense evasion\", \"cve-2024-55591\", \"socks proxy\", \"powershell\", \"qilin\", \"the gentlemen\", \"event log clearing\", \"rdp compromise\", \"microsoft defender tampering\"]\nTgtd countries: []\nMlwr families: [\"The Gentlemen\", \"Qilin\", \"Trojan:Win32/MpTamperBulkExcl.H\"]\nAttack_ids: [\"T1053.005\", \"T1033\", \"T1133\", \"T1548.002\", \"T1036.005\", \"T1082\", \"T1112\", \"T1070.001\", \"T1083\", \"T1057\", \"T1059.001\", \"T1562.001\", \"T1078\", \"T1027\", \"T1486\", \"T1071.001\", \"T1018\", \"T1105\", \"T1021.001\", \"T1090.001\"]\nIndustries: [\"Transportation\", \"Construction\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779447611",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "e6dd37e2-e13d-4b99-a093-d4f078f70ace",
        "value": "The Gentlemen"
      },
      {
        "category": "Network activity",
        "comment": "C2 IP address for malicious Scheduled Task (second incident)",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780280650",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "032ec472-c60c-46c0-a974-66c349929aa2",
        "value": "193.233.202.17",
        "Tag": [
          {
            "colour": "#94cdd8",
            "local": false,
            "name": "asn:asn=\"200019\"",
            "relationship_type": ""
          },
          {
            "colour": "#f50d01",
            "local": false,
            "name": "asn:as-owner=\"ALEXHOST\"",
            "relationship_type": ""
          },
          {
            "colour": "#9ca493",
            "local": false,
            "name": "asn:as-country=\"MD\"",
            "relationship_type": ""
          },
          {
            "colour": "#4f4d08",
            "local": false,
            "name": "misp-galaxy:country=\"moldova\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779447611",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "9b517cb6-1359-4921-b327-41be03b02439",
        "value": "CVE-2024-55591"
      },
      {
        "category": "Network activity",
        "comment": "C2 IP address for malicious Scheduled Task (second incident)",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780280672",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "c9e89473-652e-4a47-89b5-e883fda26cff",
        "value": "77.110.122.137",
        "Tag": [
          {
            "colour": "#c3e702",
            "local": false,
            "name": "asn:asn=\"210644\"",
            "relationship_type": ""
          },
          {
            "colour": "#c047ce",
            "local": false,
            "name": "asn:as-owner=\"AEZA-AS\"",
            "relationship_type": ""
          },
          {
            "colour": "#e1449b",
            "local": false,
            "name": "asn:as-country=\"GB\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united kingdom\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "Encryptor (second incident) No sample in VT\r\nLast check:31/05/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780197875",
        "to_ids": true,
        "type": "sha256",
        "uuid": "1b1808dd-6772-4342-bc5c-279493e42ea4",
        "value": "f918535f974591ef031bd0f30a8171e3da27a6754e6426a8ba095f83195661c8",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Targeting data",
        "comment": "Malicious workstation name (second incident)",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780180458",
        "to_ids": false,
        "type": "target-machine",
        "uuid": "d44b7074-1ada-476b-8f3a-ca7fceb51b89",
        "value": "WIN-8OA3CCQAE4D"
      },
      {
        "category": "Network activity",
        "comment": "On port 44729",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780180489",
        "to_ids": true,
        "type": "ip-dst|port",
        "uuid": "6ad59f36-2210-4e4e-a08b-3f6cbcada75e",
        "value": "193.233.202.17|44729"
      },
      {
        "category": "Network activity",
        "comment": "On port 37182",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780180489",
        "to_ids": true,
        "type": "ip-dst|port",
        "uuid": "10d4e94d-aacc-449e-887e-d89f9daaa883",
        "value": "77.110.122.137|37182"
      }
    ]
  }
}