Ransomware Analysis: Go Binary and Fast Encryption

June 10, 2026, 2:01 p.m.

Description

The Gentlemen is a Ransomware-as-a-Service operation, tracked as Storm-2697, that emerged in mid-2025 after splitting from Qilin ransomware following a payment dispute. Operating as a highly structured syndicate with at least 9 core operators, the group has compromised over 1,570 organizations across 70+ countries, with approximately 71-78% paying ransoms and never appearing on public leak sites. The operation uses custom Go and C-compiled cross-platform lockers featuring partial encryption modes (0.3%-9% per file), built-in lateral movement via WMI and PowerShell remoting, aggressive defense evasion including Windows Defender disabling and event log clearing, and self-propagation capabilities. A formal partnership with BreachForums in May 2026 expanded distribution through integrated affiliate onboarding. Despite sophisticated encryption using X25519 key exchange and XChaCha20, a critical CWE-244 implementation flaw allows key recovery from process memory dumps.

Date

  • Created: June 10, 2026, 11:58 a.m.
  • Published: June 10, 2026, 11:58 a.m.
  • Modified: June 10, 2026, 2:01 p.m.

Indicators

  • 3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235
  • http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/

Attack Patterns

Additional Informations

  • Finance
  • Manufacturing
  • Technology
  • Healthcare
  • Government
  • tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion
  • Brazil
  • United Kingdom of Great Britain and Northern Ireland
  • Germany
  • United States of America

Linked vulnerabilities