THE Gentlemen ransomware is a Go-based locker exploited by the threat actor group GOLD SHERWOOD. Targeting various organizations globally, this ransomware employs stolen VPN credentials and exposed firewall interfaces for initial access. Key capabilities include rapid privilege escalation, data theft using Rclone, and effective evasion of defenses through a custom EDR-killer suite named GentleKiller. The attack often achieves encryption in under 24 hours, with a growing victim count peaking at 169 in July 2026.
To combat this threat, organizations are advised to implement MFA on VPNs, monitor for exfiltration tools, and protect backup systems.