{
  "Event": {
    "analysis": "1",
    "date": "2026-06-09",
    "extends_uuid": "",
    "info": "[Threat Intel] Ransomware Analysis: Go Binary and Fast Encryption",
    "protected": false,
    "publish_timestamp": "1781559740",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1781559740",
    "uuid": "c92fa0fa-d0dc-4c67-b387-52edb9b647d7",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#705cef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#f8140a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"",
        "relationship_type": ""
      },
      {
        "colour": "#f28fb8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"",
        "relationship_type": ""
      },
      {
        "colour": "#b2a633",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Domain Groups - T1069.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Network Share Discovery - T1135\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#fa3e60",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Clear Command History - T1070.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#041edc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"SMB/Windows Admin Shares - T1021.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#5affe5",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Remote Management - T1021.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#755c09",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#36d931",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"",
        "relationship_type": ""
      },
      {
        "colour": "#3970d7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"",
        "relationship_type": ""
      },
      {
        "colour": "#297c25",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"",
        "relationship_type": ""
      },
      {
        "colour": "#b8ab01",
        "local": false,
        "name": "misp-galaxy:target-information=\"United States\"",
        "relationship_type": ""
      },
      {
        "colour": "#c94db5",
        "local": false,
        "name": "misp-galaxy:target-information=\"Brazil\"",
        "relationship_type": ""
      },
      {
        "colour": "#5ed128",
        "local": false,
        "name": "misp-galaxy:target-information=\"Germany\"",
        "relationship_type": ""
      },
      {
        "colour": "#ce59f1",
        "local": false,
        "name": "misp-galaxy:target-information=\"United Kingdom\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:ransomware=\"the gentlemen\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003d",
        "local": false,
        "name": "rectifyq:sub-category=\"TA-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#110041",
        "local": false,
        "name": "rectifyq:sub-category=\"malware-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"Ransomware\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#3500ca",
        "local": false,
        "name": "rectifyq:detection-rules=\"yara-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#220082",
        "local": false,
        "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781146809",
        "to_ids": false,
        "type": "link",
        "uuid": "7214896a-1a7e-4c7f-bb23-c2d546efad75",
        "value": "https://darkatlas.io/blog/how-a-go-binary-locks-down-enterprise-networks-in-minutes-the-story-behind-gentlemen-ransomware",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781146809",
        "to_ids": false,
        "type": "text",
        "uuid": "d4ce3f82-ed0c-49da-9c1d-5d0e967085d7",
        "value": "The Gentlemen is a Ransomware-as-a-Service operation, tracked as Storm-2697, that emerged in mid-2025 after splitting from Qilin ransomware following a payment dispute. Operating as a highly structured syndicate with at least 9 core operators, the group has compromised over 1,570 organizations across 70+ countries, with approximately 71-78% paying ransoms and never appearing on public leak sites. The operation uses custom Go and C-compiled cross-platform lockers featuring partial encryption modes (0.3%-9% per file), built-in lateral movement via WMI and PowerShell remoting, aggressive defense evasion including Windows Defender disabling and event log clearing, and self-propagation capabilities. A formal partnership with BreachForums in May 2026 expanded distribution through integrated affiliate onboarding. Despite sophisticated encryption using X25519 key exchange and XChaCha20, a critical CWE-244 implementation flaw allows key recovery from process memory dumps."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781146809",
        "to_ids": false,
        "type": "text",
        "uuid": "981f1cda-ad7a-4f31-86de-8eaaeb480749",
        "value": "Name: Ransomware Analysis: Go Binary and Fast Encryption\nAuthor: AlienVault\nAdversary: The Gentlemen\nTags: [\"double extortion\", \"gentlemen\", \"anydesk\", \"storm-2697\", \"ransomware-as-a-service\", \"cve-2024-55591\", \"lateral movement\", \"go binary\", \"systembc\", \"cobalt strike\", \"breachforums partnership\", \"larva-368\", \"xchacha20 encryption\"]\nTgtd countries: [\"United States of America\", \"Brazil\", \"Germany\", \"United Kingdom of Great Britain and Northern Ireland\"]\nMlwr families: [\"Gentlemen\", \"SystemBC\", \"Cobalt Strike - S0154\", \"AnyDesk\"]\nAttack_ids: [\"T1053.005\", \"T1047\", \"T1003\", \"T1489\", \"T1069.002\", \"T1135\", \"T1082\", \"T1070.003\", \"T1140\", \"T1021.002\", \"T1021.006\", \"T1070.001\", \"T1083\", \"T1059.001\", \"T1547.001\", \"T1562.001\", \"T1027\", \"T1486\", \"T1018\", \"T1490\"]\nIndustries: [\"Manufacturing\", \"Technology\", \"Healthcare\", \"Finance\", \"Government\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781146809",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "e27cf681-6126-4fe8-b6fb-4bc9ca3896fa",
        "value": "The Gentlemen"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781146809",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "499295a7-59fa-4293-aa07-9b4d2298b133",
        "value": "CVE-2024-55591"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781435935",
        "to_ids": true,
        "type": "domain",
        "uuid": "1d3a5d9a-d57a-4fd4-867c-cc94c6ee33f7",
        "value": "tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781435956",
        "to_ids": true,
        "type": "url",
        "uuid": "8c72bae3-4d05-4eaf-a60a-6347f2b91ab0",
        "value": "http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:14/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781434320",
        "to_ids": true,
        "type": "md5",
        "uuid": "6faacdc3-2373-42eb-a980-a0b71c50abf8",
        "value": "ead0d7a8ae0a6ffb7f0a5873fec4ff5e",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:14/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781434321",
        "to_ids": true,
        "type": "sha1",
        "uuid": "fe4bdcce-bc10-4fed-979a-c225d5e61327",
        "value": "39bd9c888d3e8110c127ba60cc727d2538bf7da2",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781432863",
        "to_ids": true,
        "type": "email-src",
        "uuid": "c147c735-2203-42c2-bbd8-8ca6767e61bb",
        "value": "negotiation_hapvida@proton.me"
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1781432888",
        "uuid": "b5ad4005-b18a-4ae8-b78b-5b0d4738892b",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1781432888",
            "to_ids": false,
            "type": "text",
            "uuid": "59550c85-8315-4f8b-ae6f-983c78b04745",
            "value": "Windows_Ransomware_Gentlemen"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1781432888",
            "to_ids": false,
            "type": "comment",
            "uuid": "2d119ecc-ee4c-4b49-b768-f5fda36700a2",
            "value": "Gentlemen Go-Based ransomware Yara Rule"
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1781432888",
            "to_ids": true,
            "type": "yara",
            "uuid": "1e8d06f6-4a94-4445-af25-100ada95888a",
            "value": "rule Windows_Ransomware_Gentlemen\r\n{\r\n    meta:\r\n        description = \"Gentlemen Go-Based ransomware Yara Rule\"\r\n        author      = \"Buguard Threat Research\"\r\n        date        = \"2026-05-25\"\r\n\r\n    strings:\r\n        $s0         = \"gentlemen\" ascii nocase\r\n        $s1         = \"88984846080D639C9A4EC394E53BA616D550B2B3AD691942EA2CCD33AA5B9340FD1A8FF40E9A\" ascii\r\n        $s2         = \"/LEXF8q5iUJHValXwdVTYbEZ3k/c/s2y8uVrFa2AGSI=\" ascii\r\n        $s3         = \"tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion\" ascii\r\n        $s4         = \"negotiation_hapvida@proton.me\" ascii\r\n        $s5         = \"README-GENTLEMEN.txt\" ascii\r\n        $s6         = \"gentlemen.bmp\" ascii\r\n        $s7         = \"G7Vz9eyG\" ascii\r\n        $s8         = \"Cynet Ransom Protection(DON'T DELETE)\" ascii\r\n        $s9         = \"Set-MpPreference -DisableRealtimeMonitoring $true\" ascii\r\n\r\n    condition:\r\n        uint16(0) == 0x5A4D and\r\n        (\r\n            ($s0 and $s9) or\r\n            $s1 or\r\n            $s2 or\r\n            $s3 or\r\n            $s4 or\r\n            ($s5 and $s6) or\r\n            ($s7 and $s8 and $s0)\r\n        )\r\n}"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1781435977",
        "uuid": "fde298c6-f6da-46e5-98e4-5ad4299d350f",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1781435977",
            "to_ids": true,
            "type": "md5",
            "uuid": "8b0245d5-4217-4f28-8f95-37510d4cf585",
            "value": "4200b46a93c6ab059e2b34ce200c4a5b",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1781434319",
            "to_ids": true,
            "type": "sha1",
            "uuid": "47cf7dce-aa40-46f2-90bc-aff5c2c80693",
            "value": "42bcc743c71a9ea083c1c750a398110582796762",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1781434319",
            "to_ids": true,
            "type": "sha256",
            "uuid": "36cb7251-6196-4848-9a0f-2bd16cb7e6a8",
            "value": "3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1781434089",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "48c5dea9-dfac-44dc-8f9d-8efe2ab76ace",
            "value": "49152:Dl5LxQaoySboC9C5ZtPzKgv5bQgZ3tA5m25ElcY:DHS3EX"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1781434089",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "f6c17bd9-d571-4c22-bd41-0cbe0a303c66",
            "value": "2962944"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1781434089",
            "to_ids": true,
            "type": "vhash",
            "uuid": "c8f2a4de-ab46-4b46-98ed-f2e926794b45",
            "value": "026086655d75551d15541az2e!z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1781434089",
            "to_ids": true,
            "type": "filename",
            "uuid": "1cda0c57-4159-4f2e-bdf0-2484602987b6",
            "value": "hapvida.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 14/06/2026\nLast-scan\t:  10/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1781434089",
            "to_ids": false,
            "type": "text",
            "uuid": "9b094167-8dec-4d80-8314-d8a4225bde1d",
            "value": "Type Description: Win32 EXE\nMicrosoft: Ransom:Win64/BlackByte.SH!MTB\nVT Total Detection:55/71\nFirst Submission:2025-10-19T16:58:34.000000+00:00\nLast Submission:2026-05-15T13:53:18.000000+00:00"
          }
        ]
      }
    ]
  }
}