Summary
Multiple independent trackers recorded August 2026 as the highest single month for ransomware leak-site claims on record. Comparitech logged 997 attacks worldwide, averaging 32 per day, surpassing the prior monthly record of 988 set in February 2025 [1]. Breachsense recorded 964 victims across 83 distinct active groups, also a yearly high [18]. The two top groups by volume, Qilin (157 claims) and The Gentlemen (107 to 127, depending on source), together accounted for more than a quarter of all August postings [1][18]. Clop returned to the top five after months of minimal activity, driven by exploitation of CVE-2026-12569 in PTC Windchill [1][21].
These figures represent leak-site claims, not confirmed breaches. Ransomnews, which independently verifies incidents through breach disclosures, regulatory filings, and press reporting, confirmed 51 ransomware attacks in August 2026, down from 62 in July and 136 in August 2025 [19]. The year-to-date confirmed total stands at 762 across 65 countries [20]. The gap between claimed and confirmed numbers is normal: many claims are real intrusions where the victim has not yet disclosed, while some are exaggerated or misattributed [18].
Background: The Qilin and Gentlemen Rivalry
Qilin (also tracked as Agenda ransomware and Spikey Scorpius by Unit 42) has operated as a RaaS platform since mid-2022 [6][22]. The operation rewrote its codebase in Rust for cross-platform targeting of Windows, Linux, and VMware ESXi [6]. Black Kite recorded 1,358 Qilin victims between April 2025 and March 2026, a 443% increase over the prior 12 months [5]. MOXFIVE tracking puts the total at approximately 1,500 since launch, with more than 500 in 2026 alone [22]. Affiliates earn 80 to 85 percent of each ransom payment, and recruitment runs through RAMP, a Russian-language cybercrime forum [22].
The Gentlemen (tracked as Storm-2697 by Microsoft) emerged in mid-2025 from ArmCorp, a former Qilin affiliate [3][4]. Blackpoint Cyber reports that the split went public on July 22, 2025, when the operator using the alias "hastalamuerte" claimed Qilin owed roughly $48,000 in unpaid commissions [8]. The first known Gentlemen sample appeared on VirusTotal on July 17, five days before the public claim, indicating development was already underway [8]. The group's RaaS model offers affiliates a 90% payout, well above the industry norm of 70 to 80 percent [3][4]. Through the end of July 2026, Comparitech attributed 600 claimed victims to The Gentlemen, making it the second-most active operation behind Qilin's 771 [4].
In June 2026, The Gentlemen briefly surpassed Qilin with 115 claimed victims versus 78, the first month a rival came out ahead [5]. Qilin reclaimed the top spot in August.
Group Rankings and Turnover
Qilin posted 157 victims in August, a 22% increase from July [1]. Breachsense recorded The Gentlemen at 127 victims for the month [18], while Comparitech placed the count at 107, down 21% from July [1]. Five of the top ten most active groups in August were not in July's top ten, pointing to significant affiliate churn and group fluidity [18].
Clop added 45 victims to its leak site in August compared to one in July [1]. Scrutex's weekly report for August 10 to 16 attributed 46 postings to Clop in a single day (August 12), most of which were previously masked names from an August 5 batch now revealed [21]. The activity was linked to exploitation of CVE-2026-12569 in PTC Windchill [21].
Sector Breakdown
Businesses absorbed 861 of the 997 Comparitech-tracked claims, a 24% increase from July's 692 [1]. Manufacturers saw a 23% increase with 12 confirmed incidents. Law firms recorded a 52% spike. Technology companies were up 42%, and financial institutions up 40% [1].
Healthcare providers recorded 69 claims in August per Comparitech (up 30% from 53 in July), with eight confirmed during the month [1]. Breachsense placed healthcare at 91 victims, calling it the most-targeted industry for August and its second-highest month of the year [18]. Three confirmed August healthcare incidents affected U.S. organizations, including Nutex Health Inc. [1]. Separately, two ransomware groups claimed Interim HealthCare, a home health and hospice provider in roughly 40 U.S. states, within weeks of each other, with a franchise location reporting a breach to HHS on July 31, 2026 [17].
Utility companies saw claims double from five in July to ten in August [1]. The absolute numbers are small, but Rebecca Moody, head of data research at Comparitech, noted that "utility companies saw the biggest spike" proportionally [1].
Government entities totaled 270 claims across January through August 2026, roughly matching 267 for the same period in 2025, with 124 confirmed so far [1]. Qilin claimed attacks on the Commission de la construction du Quebec, Colombia's Ministerio de Justicia y del Derecho, Guatemala's Corte de Constitucionalidad, a Greek municipal port fund, and a Hungarian government agency [1]. Qilin also claimed the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) on August 27, 2026, an incident the Department of Justice designated a "major incident," triggering mandatory congressional notification [16].
Clop's Oracle EBS Campaign and Current CVE Exploitation
Clop's August activity is the latest phase of a broader pattern. The group's Oracle E-Business Suite campaign, attributed with moderate confidence to the FIN11 threat cluster, exploited CVE-2025-61882 (CVSS 9.8) as a zero-day beginning as early as August 9, 2025, weeks before patches were available [12][13][23]. GTIG and Mandiant tracked the subsequent extortion campaign beginning September 29, 2025, when threat actors sent high-volume emails to company executives from hundreds of compromised accounts [13]. Twenty-nine organizations were eventually named on the Clop leak site, including Harvard University, The Washington Post, Logitech, Schneider Electric, and Envoy Air [11][14].
The attack chain combined SSRF, CRLF injection, authentication bypass, and XSL template injection to achieve remote code execution on Oracle EBS servers [13]. Post-exploitation tooling included the in-memory Java-based loader GOLDVEIN.JAVA, with logical similarities to malware from the Cleo MFT campaign (the GOLDVEIN downloader and GOLDTOMB backdoor) [12].
In current operations, Clop's August 2026 activity is tied to CVE-2026-12569 in PTC Windchill [1][21]. Separately, Cisco Talos reported in September 2026 that three threat clusters are exploiting CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center (FMC), with one cluster deploying Qilin ransomware [15]. Qilin-linked actors have also been associated with exploitation of SonicWall SMA 1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 [16]. CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog with a remediation deadline of September 12, 2026 [15].
Initial Access
The Gentlemen gains entry through exploitation of internet-exposed services or compromised administrative credentials, including exposed FortiGate firewall and VPN management interfaces. Unit 42 documents the group's use of brute force attacks, leaked and stolen credentials, and collaboration with initial access brokers [3]. In May 2026, the group announced a partnership with HasanBroker's BreachForums, stating: "We are actively looking for skilled affiliates, teams, individual pentesters, and access brokers, to join our program and scale operations worldwide" [4].
Persistence and Defense Evasion
The group deploys a custom Go-based backdoor and an EDR-killer framework dubbed GentleKiller [3]. Defense evasion techniques include Bring Your Own Vulnerable Driver (BYOVD) using drivers such as ThrottleStop.sys and ThrottleBlood.sys, as well as abuse of PowerRun.exe to bypass UAC and execute processes at SYSTEM-level privileges [7]. Trend Micro documented legitimate driver abuse, Group Policy manipulation, and custom anti-AV utilities in a campaign spanning at least 17 countries [10].
Reconnaissance and Lateral Movement
After gaining a foothold, operators map the environment using Advanced IP Scanner and Active Directory queries. Red Piranha reports an average dwell time of two to six weeks from initial access to encryption [7]. The group conducts extensive internal reconnaissance before deploying ransomware, using tools to target specific processes for termination including dbeng50.exe, agntsvc.exe, vmcompute.exe, vmwp.exe, and vmms.exe [10].
Exfiltration and Impact
The Gentlemen operates a double-extortion model: data theft over a multi-week period, followed by encryption, followed by threatened publication on a Tor-based leak site with countdown timers and sample data [7][8]. Negotiations occur via TOX messenger [7]. The ransomware binary is written in Golang, targeting Windows, Linux, ESXi, NAS, and BSD [7].
Qilin: Healthcare Impact and Enforcement Gap
Qilin's most consequential healthcare incident remains the June 2024 attack on Synnovis, a pathology provider for NHS hospitals in London. The attack halted blood testing across King's College Hospital, Guy's and St Thomas', and Lewisham and Greenwich hospitals, cancelling more than 10,000 outpatient appointments and postponing over 1,700 elective operations [6]. As of January 2026, 161,560 pathology reports remained unentered into NHS patient records, alongside 122 recorded patient-safety incidents [5]. In June 2025, King's College Hospital NHS Foundation Trust confirmed that blood test delays from the attack contributed to a patient death [6]. Synnovis put direct costs at more than 32 million GBP and issued breach notifications in February 2026 after an 18-month forensic review [6].
No arrest, indictment, sanction, seizure, or joint government advisory has been issued against Qilin as of August 2026 [5]. CISA and the FBI have published #StopRansomware advisories for Akira, Black Basta, BianLian, RansomHub, and Gunra (the Gunra advisory was published August 10, 2026) but not for Qilin [5]. No free decryptor exists for any Qilin variant [5].
IOC Table
| Type | Value | Context | Source |
|---|---|---|---|
| malware | GentleKiller |
EDR-killer framework used by The Gentlemen | [3] |
| filename | ThrottleStop.sys |
BYOVD driver used by The Gentlemen | [3] |
| filename | PowerRun.exe |
UAC bypass tool used by The Gentlemen | [7] |
| filename | ThrottleBlood.sys |
BYOVD driver used by The Gentlemen | [7] |
| filename | All.exe |
Defense-impairment tool used by The Gentlemen | [7] |
| filename | Allpatch2.exe |
Security-disabling tool used by The Gentlemen | [7] |
| filename | README-GENTLEMEN.txt |
Ransom note dropped by The Gentlemen | [7] |
| filename | 1.bat |
Reconnaissance script used by The Gentlemen | [7] |
| domain | tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion |
The Gentlemen Tor negotiation portal | [7] |
| filename | dbeng50.exe |
Process targeted for termination by The Gentlemen | [10] |
| filename | agntsvc.exe |
Process targeted for termination by The Gentlemen | [10] |
| filename | vmcompute.exe |
Process targeted for termination by The Gentlemen | [10] |
| malware | GOLDVEIN.JAVA |
In-memory Java loader in Clop Oracle EBS campaign | [12] |
| malware | GOLDTOMB |
Backdoor deployed in suspected Clop Cleo MFT campaign | [12] |
support@pubstorm.com |
FIN11/Clop extortion contact email | [12] | |
support@pubstorm.net |
FIN11/Clop extortion contact email | [12] | |
| malware | impacket |
Open-source tooling used by Qilin-linked attackers on Cisco FMC | [15] |
| malware | Invoke-TheHash |
Tool used by Qilin-linked attackers on Cisco FMC | [15] |
MITRE ATT&CK Techniques
| Technique ID | Name | Applicability |
|---|---|---|
| T1190 | Exploit Public-Facing Application | Qilin (Cisco FMC, SonicWall SMA); Clop (Oracle EBS, PTC Windchill); The Gentlemen (edge devices, FortiGate) [3][15][21] |
| T1078 | Valid Accounts | Qilin initial access via leaked credentials; The Gentlemen compromised credentials [5][8] |
| T1133 | External Remote Services | The Gentlemen exploitation of VPN/firewall management interfaces [8] |
| T1566 | Phishing | The Gentlemen initial access vector [8] |
| T1136 | Create Account | The Gentlemen persistence technique [8] |
| T1543 | Create or Modify System Process | The Gentlemen persistence technique [8] |
| T1574 | Hijack Execution Flow | The Gentlemen persistence and privilege escalation [9] |
| T1562.001 | Impair Defenses: Disable or Modify Tools | GentleKiller EDR-killer, custom anti-AV utilities [3][10] |
| T1068 | Exploitation for Privilege Escalation | BYOVD technique with ThrottleStop.sys, ThrottleBlood.sys [3][7] |
| T1486 | Data Encrypted for Impact | Qilin, The Gentlemen, Clop encryption operations [5][7] |
| T1490 | Inhibit System Recovery | Qilin and The Gentlemen kill chain [9] |
| T1489 | Service Stop | Process termination of database and VM services by The Gentlemen [10] |
| T1021 | Remote Services | Lateral movement via RDP and SMB by both groups [9][15] |
| T1570 | Lateral Tool Transfer | The Gentlemen internal tool staging [9] |
| T1048.001 | Exfiltration Over Alternative Protocol: Encrypted Non-C2 | The Gentlemen encrypted exfiltration channels [9][10] |
Network Indicators
Monitor DNS queries and proxy logs for .onion domains associated with The Gentlemen's negotiation portal (tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion) [7]. Look for outbound connections to TOX messenger infrastructure, which the group uses for ransom negotiation [7].
For Cisco FMC exploitation (CVE-2026-20079), audit for anomalous port forwarding activity on LDAP (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985) [15].
Endpoint Indicators
Hunt for the presence of README-GENTLEMEN.txt ransom notes, GentleKiller processes, and the BYOVD drivers ThrottleStop.sys and ThrottleBlood.sys [3][7]. Monitor for PowerRun.exe execution, which the group uses to bypass UAC [7].
The Gentlemen's ransomware binary requires a password parameter at execution, a trait that can be used as a behavioral signature: watch for command-line executions of unknown Golang binaries with password-style arguments.
Sigma Rule: Gentlemen Ransomware BYOVD Driver Load
title: Suspicious BYOVD Driver Load Associated With Gentlemen Ransomware
id: 9a2e1b7c-4d3f-4e8a-b5c6-7d8e9f0a1b2c
status: experimental
description: Detects loading of known BYOVD drivers used by The Gentlemen ransomware operation
author: RedSheepSec
date: 2026/09/15
logsource:
category: driver_load
product: windows
detection:
selection:
ImageLoaded|endswith:
- '\ThrottleStop.sys'
- '\ThrottleBlood.sys'
condition: selection
falsepositives:
- Legitimate ThrottleStop utility used for CPU undervolting; verify context and parent process
level: high
tags:
- attack.defense_evasion
- attack.t1068
Log Queries
For organizations running Oracle E-Business Suite, search web server logs for requests to /OA_HTML/SyncServlet, the component exploited in the Clop/FIN11 campaign [13]. Correlate with any outbound connections to the Clop extortion email addresses support@pubstorm.com and support@pubstorm.net in email gateway logs [12].
Analysis
Three structural factors explain the sustained increase in leak-site volume.
First, the collapse or disruption of LockBit, ALPHV/BlackCat, and RansomHub throughout 2024 and 2025 displaced affiliates into surviving programs. Qilin had the infrastructure, recruitment pipeline, and revenue model to absorb them [22]. The Gentlemen's 90% affiliate payout and active BreachForums recruitment created a competing destination [3][4].
Second, the Qilin-Gentlemen rivalry itself generates volume. The Gentlemen was born from a Qilin affiliate dispute [4][8], and competition between the two operations for affiliate loyalty likely pushes both toward higher claim counts. In September 2025, DragonForce announced a coalition with Qilin and LockBit on a Russian-language forum, documented by ReliaQuest, to share techniques, infrastructure, and affiliates [6]. The RaaS market is consolidating around a few large platforms while simultaneously fragmenting at the affiliate level.
Third, mass-exploitation campaigns by Clop (Oracle EBS, PTC Windchill) and Qilin-linked actors (Cisco FMC, SonicWall SMA) produce sudden volume spikes. Clop's pattern of targeting widely deployed enterprise software has been consistent since at least the MOVEit campaign in 2023, and the Oracle EBS campaign fits the same model [13][21].
The confirmed-to-claimed ratio continues to warrant attention. Ransomnews has confirmed 762 attacks for 2026 through mid-September [20], against thousands of leak-site claims. Among 57 confirmed 2026 incidents with a public outcome, five victims paid and 52 refused, a disclosed payment rate of 8.8% [20]. The low payment rate may be pushing groups toward higher volume to maintain revenue.
Red Sheep Assessment
Confidence: Moderate
The absence of any U.S. government enforcement action against Qilin, despite the group's confirmed role in the Synnovis/NHS attack (which contributed to a patient death [6]) and the ATF breach (designated a "major incident" by DOJ [16]), is a notable gap. CISA and the FBI have issued #StopRansomware advisories for Akira, Black Basta, BianLian, RansomHub, and Gunra [5], but not for Qilin. This is not explained in any of the reviewed sources.
One possible interpretation: Qilin's affiliate model and distributed infrastructure make traditional law enforcement disruption more difficult than operations with more centralized command structures. Another: active intelligence or law enforcement operations may be underway that preclude public advisory issuance. A third possibility is that the interagency process simply hasn't prioritized Qilin relative to other groups despite its volume.
Regardless of the reason, the practical consequence is that defenders cannot rely on government-provided IOCs and TTPs for the single most prolific ransomware operation of 2026. Organizations must source Qilin detection guidance from commercial threat intelligence and community reporting.
The Gentlemen's trajectory also bears watching. The group went from zero to 675 claimed victims in roughly one year [4], built on experienced operators who already understood RaaS operations from their Qilin tenure. The 90% affiliate payout is likely unsustainable long-term unless the core team has alternative revenue (selling access, operating other criminal services), but it is an effective market-capture strategy in the near term.
The sources collectively suggest that the ransomware ecosystem has entered a phase where affiliate loyalty is the primary competitive variable, and groups are willing to sacrifice profit margins to acquire it. That dynamic rewards volume over operational security, which may eventually create more opportunities for law enforcement but also increases the rate of victimization in the interim.
Defender's Checklist
- ▢[ ] Patch Cisco FMC (CVE-2026-20079) and SonicWall SMA 1000 (CVE-2026-15409, CVE-2026-15410) immediately; verify CISA KEV remediation deadlines have been met [15][16]
- ▢[ ] Hunt for Gentlemen BYOVD artifacts: search Sysmon Event ID 6 (driver load) logs for
ThrottleStop.sysandThrottleBlood.sys, and file-creation events forREADME-GENTLEMEN.txt,All.exe,Allpatch2.exe[3][7] - ▢[ ] Audit Oracle E-Business Suite web server logs for requests to
/OA_HTML/SyncServletand validate that CVE-2025-61882 and CVE-2025-61884 patches are applied on all EBS instances [13][14] - ▢[ ] Review firewall and VPN management interface exposure, particularly FortiGate appliances, and restrict administrative access to trusted internal networks or jump hosts [3]
- ▢[ ] Search email gateway logs for messages from
support@pubstorm.comandsupport@pubstorm.net, which are Clop/FIN11 extortion contact addresses active since at least May 2025 [12]
References
[1] https://industrialcyber.co/ransomware/global-ransomware-attacks-hit-record-997-in-august-2026-as-utility-healthcare-and-business-attacks-surge/
[2] https://www.infosecurity-magazine.com/news/university-ransomware-attacks-rise/
[3] https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/
[4] https://www.comparitech.com/news/the-gentlemen-ransomware-stats-on-attacks-ransoms-data-breaches/
[5] https://www.adaptivesecurity.com/blog/qilin-ransomware
[6] https://cybelangel.com/blog/qilin-ransomware-tactics-attack/
[7] https://redpiranha.net/news/the-gentlemen-ransomware-analysis
[8] https://blackpointcyber.com/threat-profile/gentlemen-ransomware/
[9] https://blackpointcyber.com/wp-content/uploads/2025/11/The-Gentlemen.pdf
[10] https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html
[11] https://www.paubox.com/blog/cl0p-ransomware-gang-names-29-oracle-ebs-breach-victims
[12] https://www.infosecurity-magazine.com/news/google-clop-data-oracle-exploit/
[13] https://thehackernews.com/2025/10/cl0p-linked-hackers-breach-dozens-of.html
[14] https://www.securityweek.com/nearly-30-alleged-victims-of-oracle-ebs-hack-named-on-cl0p-ransomware-site/
[15] https://securityaffairs.com/198884/cyber-crime/attackers-exploit-critical-cisco-fmc-flaw-to-deploy-qilin-ransomware.html
[16] https://tech-insider.org/atf-qilin-ransomware-breach-major-incident-2026/
[17] https://tech-insider.org/interim-healthcare-ransomware-genesis-attack-2026/
[18] https://www.breachsense.com/ransomware-reports/august-2026/
[19] https://ransomnews.com/ransomware/
[20] https://ransomnews.com/ransomware-attacks/2026/
[21] https://scrutex.ai/blogs/weekly-ransomware-intelligence-report-august-16-2026
[22] https://www.moxfive.com/blog/qilin-ransomware-2026-ttps-victims-and-defense-guide
[23] https://securityaffairs.com/183306/hacking/google-mandiant-expose-malware-and-zero-day-behind-oracle-ebs-extortion.html
[24] https://threatprotect.qualys.com/2025/10/06/oracle-e-business-suite-remote-code-execution-vulnerability-exploited-in-the-wild-cve-2025-61882/
[25] https://www.riministreet.com/blog/inside-the-ciop-ransomware-campaign-how-oracle-ebs-clients-can-stay-ahead-of-evolving-threats/
Event Timeline
Timeline
Entity Relationships
Entity Graph (24 entities, 71 relationships)
Diamond Model
Diamond Model
Hunt Guide: Qilin, The Gentlemen, and Clop Ransomware Ecosystem - August 2026 Surge
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If Qilin, The Gentlemen, or Clop ransomware affiliates are active in our environment, we expect to observe BYOVD driver loads (ThrottleStop.sys, ThrottleBlood.sys), EDR-killer processes (GentleKiller), ransom note creation (README-GENTLEMEN.txt), exploitation attempts against Cisco FMC (CVE-2026-20079), SonicWall SMA (CVE-2026-15409/15410), or Oracle EBS (/OA_HTML/SyncServlet), UAC bypass via PowerRun.exe, credential abuse via impacket/Invoke-TheHash, and lateral movement via RDP/SMB in endpoint, network, and authentication logs.
Intelligence Summary: August 2026 set a record for ransomware leak-site claims at 997, driven primarily by Qilin (157 claims), The Gentlemen (107-127 claims), and Clop's return (45 claims tied to CVE-2026-12569 in PTC Windchill). The Gentlemen, which emerged in mid-2025 from a Qilin affiliate dispute, employs BYOVD techniques, a custom EDR-killer framework called GentleKiller, and a double-extortion model with a 90% affiliate payout. Qilin-linked actors are exploiting CVE-2026-20079 in Cisco FMC and SonicWall SMA vulnerabilities, while Clop/FIN11 continues mass-exploitation campaigns against enterprise software, with confirmed activity against Oracle EBS (CVE-2025-61882) and now PTC Windchill.
Confidence: Moderate | Priority: Critical
Scope
- Networks: All enterprise network segments including DMZ, server VLANs (particularly Oracle EBS, Cisco FMC, SonicWall SMA, FortiGate infrastructure), endpoint subnets, and cloud environments. Priority focus on healthcare systems, critical infrastructure, and internet-facing application servers.
- Timeframe: Retrospective hunt window: 90 days (June 1 through August 31, 2026) to cover The Gentlemen's 2-6 week average dwell time and Clop's August surge. Continuous monitoring going forward.
- Priority Systems: Oracle E-Business Suite servers, Cisco Secure Firewall Management Center (FMC) appliances, SonicWall SMA 1000 devices, FortiGate firewalls and VPN concentrators, PTC Windchill servers, domain controllers, VMware ESXi hosts, healthcare clinical systems, backup infrastructure
MITRE ATT&CK Techniques
T1190: Exploit Public-Facing Application (Initial Access) [P1]
Qilin affiliates are exploiting CVE-2026-20079 in Cisco FMC and CVE-2026-15409/15410 in SonicWall SMA 1000. Clop/FIN11 exploited CVE-2025-61882 in Oracle EBS and CVE-2026-12569 in PTC Windchill. The Gentlemen targets exposed FortiGate firewall and VPN management interfaces.
Splunk SPL:
index=corelight sourcetype=corelight_http (uri="/OA_HTML/SyncServlet" OR uri="*windchill*" OR uri="*api/fmc*") | stats count by src_ip dest_ip uri status_code | sort -count | table src_ip dest_ip uri status_code count
Elastic KQL:
url.path:("/OA_HTML/SyncServlet" OR "*windchill*" OR "*api/fmc*") AND event.dataset:"corelight.http"
Sigma Rule:
title: Exploitation Attempt Against Oracle EBS SyncServlet or Cisco FMC
id: b3d4e5f6-7a8b-4c9d-ae0f-1a2b3c4d5e6f
status: experimental
description: Detects HTTP requests to Oracle EBS SyncServlet endpoint exploited in Clop/FIN11 campaign or Cisco FMC API paths
author: RedSheepSec
date: 2026/09/15
logsource:
category: proxy
product: web
detection:
selection_oracle:
cs-uri-stem|contains: '/OA_HTML/SyncServlet'
selection_fmc:
cs-uri-stem|contains: '/api/fmc'
condition: selection_oracle or selection_fmc
falsepositives:
- Legitimate Oracle EBS or Cisco FMC administrative access
level: high
tags:
- attack.initial_access
- attack.t1190
Correlate any hits on /OA_HTML/SyncServlet with outbound connections to known Clop infrastructure. For Cisco FMC, check for anomalous authentication bypass patterns. Validate that CVE-2026-20079 patches have been applied across all FMC instances.
T1068: Exploitation for Privilege Escalation (Privilege Escalation) [P1]
The Gentlemen uses Bring Your Own Vulnerable Driver (BYOVD) technique, loading ThrottleStop.sys and ThrottleBlood.sys to gain kernel-level access for EDR tampering. These drivers are loaded to facilitate the GentleKiller EDR-killer framework.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=6 (ImageLoaded="*\\ThrottleStop.sys" OR ImageLoaded="*\\ThrottleBlood.sys") | stats count by Computer ImageLoaded Hashes SignatureStatus | table Computer ImageLoaded Hashes SignatureStatus count
Elastic KQL:
event.code:"6" AND (file.path:*ThrottleStop.sys OR file.path:*ThrottleBlood.sys)
Sigma Rule:
title: Suspicious BYOVD Driver Load Associated With Gentlemen Ransomware
id: 9a2e1b7c-4d3f-4e8a-b5c6-7d8e9f0a1b2c
status: experimental
description: Detects loading of known BYOVD drivers used by The Gentlemen ransomware operation
author: RedSheepSec
date: 2026/09/15
logsource:
category: driver_load
product: windows
detection:
selection:
ImageLoaded|endswith:
- '\ThrottleStop.sys'
- '\ThrottleBlood.sys'
condition: selection
falsepositives:
- Legitimate ThrottleStop utility used for CPU undervolting; verify context and parent process
level: high
tags:
- attack.defense_evasion
- attack.t1068
ThrottleStop is a legitimate CPU tuning utility; however, loading the driver outside of expected use by system administrators warrants investigation. Correlate with parent process and user context. ThrottleBlood.sys is not associated with any known legitimate software and should be treated as high-confidence malicious.
T1562.001: Impair Defenses: Disable or Modify Tools (Defense Evasion) [P1]
The Gentlemen deploys the GentleKiller EDR-killer framework and custom anti-AV utilities (All.exe, Allpatch2.exe) to disable endpoint security products before encryption. Group Policy manipulation is also used to push security-disabling configurations across domains.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1 (OriginalFileName IN ("All.exe", "Allpatch2.exe") OR Image="*\\All.exe" OR Image="*\\Allpatch2.exe" OR CommandLine="*GentleKiller*") | stats count by Computer User Image CommandLine ParentImage | table Computer User Image CommandLine ParentImage count
Elastic KQL:
(process.name:("All.exe" OR "Allpatch2.exe") OR process.command_line:*GentleKiller*) AND event.code:"1"
Sigma Rule:
title: Gentlemen Ransomware Defense Impairment Tools Execution
id: f1a2b3c4-d5e6-4f7a-8b9c-0d1e2f3a4b5c
status: experimental
description: Detects execution of known defense impairment tools used by The Gentlemen ransomware group including All.exe and Allpatch2.exe
author: RedSheepSec
date: 2026/09/15
logsource:
category: process_creation
product: windows
detection:
selection_tools:
Image|endswith:
- '\All.exe'
- '\Allpatch2.exe'
selection_cmdline:
CommandLine|contains:
- 'GentleKiller'
condition: selection_tools or selection_cmdline
falsepositives:
- Very unlikely; these filenames in the context of security tool disablement are highly suspicious
level: critical
tags:
- attack.defense_evasion
- attack.t1562.001
All.exe and Allpatch2.exe are generic filenames but in context of security tool disruption, they are highly indicative. Correlate with antivirus/EDR service stops occurring in the same timeframe.
T1078: Valid Accounts (Initial Access) [P2]
Both Qilin and The Gentlemen gain initial access through compromised administrative credentials, leaked credentials, and brute force attacks. The Gentlemen collaborates with initial access brokers to obtain valid credentials for victim environments.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" EventCode=4625 | bin _time span=5m | stats count as failed_attempts dc(TargetUserName) as unique_users by src_ip _time | where failed_attempts > 20 OR unique_users > 5 | table _time src_ip failed_attempts unique_users
Elastic KQL:
event.code:"4625" AND event.provider:"Microsoft-Windows-Security-Auditing" | stats count by source.ip, @timestamp
Sigma Rule:
title: Brute Force Login Attempts Indicative of Ransomware Initial Access
id: d7e8f9a0-1b2c-4d3e-5f6a-7b8c9d0e1f2a
status: experimental
description: Detects high-volume authentication failures from a single source, consistent with brute force tactics used by Qilin and The Gentlemen ransomware affiliates
author: RedSheepSec
date: 2026/09/15
logsource:
product: windows
service: security
detection:
selection:
EventID: 4625
filter_local:
IpAddress: '-'
condition: selection and not filter_local | count() by IpAddress > 20
falsepositives:
- Service accounts with misconfigured credentials
- Password spraying from security assessments
level: medium
tags:
- attack.credential_access
- attack.t1078
Tune threshold based on environment baseline. Focus on authentication attempts against VPN concentrators, FortiGate management interfaces, and administrative accounts. Cross-reference source IPs against threat intelligence feeds.
T1133: External Remote Services (Initial Access) [P2]
The Gentlemen exploits internet-exposed FortiGate firewall and VPN management interfaces for initial access. Organizations with exposed administrative interfaces are primary targets.
Splunk SPL:
index=firewall-pan sourcetype="pan:traffic:aggregated" dest_port IN (443, 8443, 10443) app="ssl" action="allow" | stats count dc(src_ip) as unique_sources by dest_ip dest_port | where unique_sources > 10 | table dest_ip dest_port unique_sources count | sort -unique_sources
Elastic KQL:
destination.port:(443 OR 8443 OR 10443) AND event.dataset:"panw.traffic" AND event.action:"allow"
Focus on identifying management interfaces accessible from untrusted networks. Cross-reference with asset inventory to identify FortiGate, SonicWall SMA, and Cisco FMC appliances with exposed management planes.
T1486: Data Encrypted for Impact (Impact) [P1]
All three groups (Qilin, The Gentlemen, Clop) deploy ransomware encryption as the terminal phase. The Gentlemen's binary is Golang-based and requires a password parameter at execution. Qilin uses Rust-based ransomware targeting Windows, Linux, and ESXi.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=11 TargetFilename="*README-GENTLEMEN.txt" | stats count by Computer User TargetFilename Image | table Computer User TargetFilename Image count
Elastic KQL:
event.code:"11" AND file.name:"README-GENTLEMEN.txt"
Sigma Rule:
title: Gentlemen Ransomware Ransom Note Creation
id: a1b2c3d4-e5f6-4a7b-8c9d-0e1f2a3b4c5d
status: experimental
description: Detects creation of README-GENTLEMEN.txt ransom note indicating active Gentlemen ransomware encryption
author: RedSheepSec
date: 2026/09/15
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|endswith: '\README-GENTLEMEN.txt'
condition: selection
falsepositives:
- None expected; this is a specific ransomware ransom note filename
level: critical
tags:
- attack.impact
- attack.t1486
Detection of this file indicates active encryption is likely already in progress. Immediate containment actions should be initiated. Also hunt for Golang binary executions with password-style arguments as a pre-encryption indicator.
T1489: Service Stop (Impact) [P1]
The Gentlemen terminates specific processes before encryption, including database engines (dbeng50.exe, agntsvc.exe) and virtualization services (vmcompute.exe, vmwp.exe, vmms.exe) to unlock files and maximize encryption impact.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1 (CommandLine="*taskkill*" OR CommandLine="*net stop*" OR CommandLine="*sc stop*") (CommandLine="*dbeng50*" OR CommandLine="*agntsvc*" OR CommandLine="*vmcompute*" OR CommandLine="*vmwp*" OR CommandLine="*vmms*") | stats count by Computer User Image CommandLine | table Computer User Image CommandLine count
Elastic KQL:
(process.command_line:*taskkill* OR process.command_line:*"net stop"* OR process.command_line:*"sc stop"*) AND (process.command_line:*dbeng50* OR process.command_line:*agntsvc* OR process.command_line:*vmcompute* OR process.command_line:*vmwp* OR process.command_line:*vmms*)
Sigma Rule:
title: Gentlemen Ransomware Pre-Encryption Process Termination
id: c5d6e7f8-9a0b-4c1d-2e3f-4a5b6c7d8e9f
status: experimental
description: Detects termination of database and virtualization processes targeted by The Gentlemen ransomware before encryption
author: RedSheepSec
date: 2026/09/15
logsource:
category: process_creation
product: windows
detection:
selection_kill:
CommandLine|contains:
- 'taskkill'
- 'net stop'
- 'sc stop'
selection_targets:
CommandLine|contains:
- 'dbeng50'
- 'agntsvc'
- 'vmcompute'
- 'vmwp'
- 'vmms'
condition: selection_kill and selection_targets
falsepositives:
- Legitimate administrative maintenance; correlate with change management records
level: high
tags:
- attack.impact
- attack.t1489
Multiple process termination commands in rapid succession targeting these specific processes is a strong pre-encryption indicator. If combined with BYOVD driver loads or GentleKiller activity, treat as confirmed ransomware event.
T1021: Remote Services (Lateral Movement) [P2]
Both Qilin and The Gentlemen use RDP and SMB for lateral movement. Qilin-linked attackers on Cisco FMC set up port forwarding for LDAP (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985) to facilitate lateral movement.
Splunk SPL:
index=corelight sourcetype=corelight_conn id.resp_p IN (389, 636, 88, 445, 135, 5985) | stats count dc(id.resp_h) as unique_destinations by id.orig_h | where unique_destinations > 5 | table id.orig_h unique_destinations count | sort -unique_destinations
Elastic KQL:
destination.port:(389 OR 636 OR 88 OR 445 OR 135 OR 5985) AND event.dataset:"corelight.conn" | stats cardinality(destination.ip) as unique_dests by source.ip
Focus on hosts making connections to multiple internal targets on these ports in a short timeframe, especially from DMZ segments or hosts that do not normally communicate on these protocols.
T1136: Create Account (Persistence) [P2]
The Gentlemen creates local or domain accounts for persistence after initial compromise. Monitor for unexpected account creation events, especially those created by non-standard processes or from unusual source systems.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" EventCode=4720 | stats count by SubjectUserName TargetUserName SubjectDomainName Computer | table Computer SubjectUserName TargetUserName SubjectDomainName count
Elastic KQL:
event.code:"4720" AND event.provider:"Microsoft-Windows-Security-Auditing"
Correlate new account creation with non-administrative parent processes or creation outside of business hours. The Gentlemen operators have been observed creating accounts during the 2-6 week dwell time between initial access and encryption.
T1574: Hijack Execution Flow (Persistence) [P1]
The Gentlemen uses execution flow hijacking for persistence and privilege escalation, including abuse of PowerRun.exe to bypass UAC and execute processes at SYSTEM-level privileges.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1 (Image="*\\PowerRun.exe" OR OriginalFileName="PowerRun.exe") | stats count by Computer User Image CommandLine ParentImage | table Computer User Image CommandLine ParentImage count
Elastic KQL:
(process.name:"PowerRun.exe" OR process.pe.original_file_name:"PowerRun.exe") AND event.code:"1"
Sigma Rule:
title: PowerRun.exe UAC Bypass Tool Execution
id: e2f3a4b5-c6d7-4e8f-9a0b-1c2d3e4f5a6b
status: experimental
description: Detects execution of PowerRun.exe, a UAC bypass tool used by The Gentlemen ransomware to gain SYSTEM privileges
author: RedSheepSec
date: 2026/09/15
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: '\PowerRun.exe'
- OriginalFileName: 'PowerRun.exe'
condition: selection
falsepositives:
- PowerRun is a legitimate tool but unusual in enterprise environments; verify business justification
level: high
tags:
- attack.privilege_escalation
- attack.t1574
- attack.defense_evasion
PowerRun.exe is a legitimate utility but not commonly found in enterprise environments. Any execution should be investigated, particularly if followed by child processes running as SYSTEM.
T1490: Inhibit System Recovery (Impact) [P1]
Both Qilin and The Gentlemen delete volume shadow copies and disable recovery options before encryption to prevent restoration from backups.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1 (CommandLine="*vssadmin*delete*shadows*" OR CommandLine="*wmic*shadowcopy*delete*" OR CommandLine="*bcdedit*recoveryenabled*no*" OR CommandLine="*wbadmin*delete*catalog*") | stats count by Computer User Image CommandLine | table Computer User Image CommandLine count
Elastic KQL:
(process.command_line:*vssadmin*delete*shadow* OR process.command_line:*wmic*shadowcopy*delete* OR process.command_line:*bcdedit*recoveryenabled*no* OR process.command_line:*wbadmin*delete*catalog*)
Shadow copy deletion is a near-universal pre-encryption indicator. Any occurrence outside of approved maintenance windows should trigger immediate investigation and containment.
T1048.001: Exfiltration Over Alternative Protocol: Encrypted Non-C2 (Exfiltration) [P2]
The Gentlemen exfiltrates data over encrypted channels during a multi-week period before encryption. The double-extortion model requires large-volume data theft prior to ransomware deployment.
Splunk SPL:
index=corelight sourcetype=corelight_conn orig_bytes > 104857600 | stats sum(orig_bytes) as total_bytes count by id.orig_h id.resp_h id.resp_p | eval total_MB=round(total_bytes/1048576,2) | where total_MB > 500 | sort -total_MB | table id.orig_h id.resp_h id.resp_p total_MB count
Elastic KQL:
source.bytes > 104857600 AND event.dataset:"corelight.conn" | stats sum(source.bytes) as total_bytes by source.ip, destination.ip, destination.port
Tune byte thresholds based on normal outbound data volumes. Focus on connections to cloud storage, file sharing services, and unknown external IPs. The Gentlemen's 2-6 week dwell time means exfiltration may occur over an extended period in smaller increments.
T1543: Create or Modify System Process (Persistence) [P2]
The Gentlemen modifies system processes and registry keys for persistence, including modifications to LSA and Terminal Services registry paths.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=13 (TargetObject="*\\Control\\Lsa\\MSV1_0*" OR TargetObject="*\\Control\\Lsa*" OR TargetObject="*\\Control\\Terminal*") | stats count by Computer User Image TargetObject Details | table Computer User Image TargetObject Details count
Elastic KQL:
event.code:"13" AND (registry.path:*Control\\Lsa\\MSV1_0* OR registry.path:*Control\\Lsa* OR registry.path:*Control\\Terminal*)
LSA registry modifications can disable NTLMv2 enforcement or enable credential caching. Terminal Services registry changes may enable RDP access. Correlate with account creation and lateral movement activity.
T1570: Lateral Tool Transfer (Lateral Movement) [P2]
The Gentlemen stages tools internally across compromised hosts before executing the encryption phase. Tools are transferred via SMB shares and administrative shares.
Splunk SPL:
index=corelight sourcetype=corelight_smb_files (name="*.exe" OR name="*.bat" OR name="*.sys") action="SMB::FILE_OPEN" | stats count by id.orig_h id.resp_h name path | sort -count | table id.orig_h id.resp_h name path count
Elastic KQL:
event.dataset:"corelight.smb_files" AND (file.name:*.exe OR file.name:*.bat OR file.name:*.sys)
Focus on executable and batch file transfers to multiple hosts in a short timeframe. Cross-reference file names against known Gentlemen tooling (All.exe, Allpatch2.exe, 1.bat, ThrottleStop.sys, ThrottleBlood.sys).
Indicators of Compromise
| Type | Value | Context | |
|---|---|---|---|
| domain | tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion |
The Gentlemen Tor negotiation portal \ | VirusTotal 10/89 malicious |
support@pubstorm.com |
FIN11/Clop extortion contact email address used in Oracle EBS campaign | ||
support@pubstorm.net |
FIN11/Clop extortion contact email address used in Oracle EBS campaign | ||
| filename | ThrottleStop.sys |
BYOVD driver used by The Gentlemen ransomware for kernel-level EDR tampering | |
| filename | ThrottleBlood.sys |
BYOVD driver used by The Gentlemen ransomware for kernel-level EDR tampering | |
| filename | PowerRun.exe |
UAC bypass tool used by The Gentlemen to execute processes at SYSTEM-level privileges | |
| filename | All.exe |
Defense-impairment tool used by The Gentlemen ransomware | |
| filename | Allpatch2.exe |
Security-disabling tool used by The Gentlemen ransomware | |
| filename | README-GENTLEMEN.txt |
Ransom note dropped by The Gentlemen ransomware during encryption | |
| filename | 1.bat |
Reconnaissance script used by The Gentlemen ransomware operators | |
| filename | dbeng50.exe |
Database engine process targeted for termination by The Gentlemen before encryption | |
| filename | agntsvc.exe |
Database agent process targeted for termination by The Gentlemen before encryption | |
| filename | vmcompute.exe |
Hyper-V compute service process targeted for termination by The Gentlemen | |
| filename | vmwp.exe |
Hyper-V worker process targeted for termination by The Gentlemen | |
| filename | vmms.exe |
Hyper-V management service process targeted for termination by The Gentlemen | |
| filename | netscan.exe |
Network scanning tool used by Black Basta ransomware for internal reconnaissance | |
| filename | server.py |
Clop ransomware campaign malicious script used in exploitation operations | |
| url | /OA_HTML/SyncServlet |
Oracle EBS component exploited for remote code execution in Clop/FIN11 campaign (CVE-2025-61882) | |
| ip | 200.107.207.26 |
Reverse shell C2 in Oracle EBS exploitation (Clop/FIN11) \ | AbuseIPDB confidence 0% (0 reports, RU) |
| ip | 185.181.60.11 |
GET/POST activity IOC, Oracle EBS Clop/FIN11 campaign \ | AbuseIPDB confidence 0% (0 reports, NO) |
| hash_sha1 | c0979ec20b87084317d1bfa50405f7149c3b5c5f |
The Gentlemen ransomware KillAV sample (48/75 VT detections) \ | VirusTotal 48/75 malicious (trojan.killav/throttleb) |
| hash_sha1 | e00293ce0eb534874efd615ae590cf6aa3858ba4 |
The Gentlemen ransomware patched KillAV sample (32/75 VT detections) \ | VirusTotal 32/75 malicious (hacktool.powerrun/htool) |
| registry | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0 |
Registry key modified by The Gentlemen ransomware for credential harvesting/persistence | |
| registry | HKLM\System\CurrentControlSet\Control\Lsa |
Registry key modified by The Gentlemen ransomware | |
| registry | HKLM\SYSTEM\CurrentControlSet\Control\Terminal |
Registry key modified by The Gentlemen ransomware to enable RDP access | |
| ip | 66.249.66.18 |
Black Basta C2 IP from CISA AA24-131A advisory \ | AbuseIPDB confidence 0% (0 reports, US) |
| ip | 95.181.173.227 |
Black Basta C2 IP from CISA AA24-131A advisory \ | AbuseIPDB confidence 0% (0 reports, US) |
| ip | 207.126.152.242 |
Black Basta C2 IP from CISA AA24-131A advisory \ | AbuseIPDB confidence 0% (0 reports, US) |
| ip | 185.220.100.240 |
Black Basta Tor exit node from CISA advisory (AbuseIPDB 100% confidence, 682 reports) \ | AbuseIPDB confidence 100% (682 reports, DE) |
| ip | 107.189.30.69 |
Black Basta Tor exit node from CISA advisory (AbuseIPDB 100% confidence, 179 reports) \ | AbuseIPDB confidence 100% (179 reports, LU) |
| ip | 185.220.101.149 |
Black Basta Tor exit node from CISA advisory (AbuseIPDB 100% confidence, 172 reports) \ | AbuseIPDB confidence 100% (172 reports, DE) |
| domain | realbumblebee.net |
Black Basta Cobalt Strike C2 domain (VT 14/89 malicious) \ | VirusTotal 14/89 malicious |
| domain | trailshop.net |
Black Basta Cobalt Strike C2 domain (VT 13/89 malicious) \ | VirusTotal 13/89 malicious |
| domain | recentbee.net |
Black Basta Cobalt Strike C2 domain (VT 14/89 malicious) \ | VirusTotal 14/89 malicious |
| domain | adslsdfdsfmo.world |
Black Basta C2 domain IOC (VT 14/89 malicious) \ | VirusTotal 14/89 malicious |
| hash_sha256 | 58ddbea084ce18cfb3439219ebcf2fc5c1605d2f6271610b1c7af77b8d0484bd |
Black Basta malicious DLL (VT 55/75 malicious, ransomware.blackbasta) \ | VirusTotal 55/75 malicious (ransomware.blackbasta/imps) |
| hash_sha256 | ae7c868713e1d02b4db60128c651eb1e3f6a33c02544cc4cb57c3aa6c6581b6e |
Black Basta malicious EXE file (VT 63/75 malicious, ransomware.blackbasta) \ | VirusTotal 63/75 malicious (ransomware.blackbasta/basta) |
| hash_sha256 | 5d2204f3a20e163120f52a2e3595db19890050b2faa96c6cba6b094b0a52b0aa |
Black Basta malicious EXE file (VT 63/75 malicious, ransomware.blackbasta) \ | VirusTotal 63/75 malicious (ransomware.blackbasta/basta) |
| hash_sha256 | 723d1cf3d74fb3ce95a77ed9dff257a78c8af8e67a82963230dd073781074224 |
Black Basta malicious EXE file (VT 59/75 malicious) \ | VirusTotal 59/75 malicious (trojan.delshad/blackbasta) |
IOC Sweep Queries (Splunk):
index=corelight sourcetype=corelight_dns query="*tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad*" | stats count by src_ip query | table src_ip query count
index=* sourcetype=* ("support@pubstorm.com") | stats count by sourcetype src_ip dest_ip | table sourcetype src_ip dest_ip count
index=* sourcetype=* ("support@pubstorm.net") | stats count by sourcetype src_ip dest_ip | table sourcetype src_ip dest_ip count
index=sysmon sourcetype=XmlWinEventLog (EventCode=6 ImageLoaded="*\\ThrottleStop.sys" OR EventCode=11 TargetFilename="*\\ThrottleStop.sys") | stats count by Computer EventCode ImageLoaded TargetFilename | table Computer EventCode ImageLoaded TargetFilename count
index=sysmon sourcetype=XmlWinEventLog (EventCode=6 ImageLoaded="*\\ThrottleBlood.sys" OR EventCode=11 TargetFilename="*\\ThrottleBlood.sys") | stats count by Computer EventCode ImageLoaded TargetFilename | table Computer EventCode ImageLoaded TargetFilename count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 (Image="*\\PowerRun.exe" OR OriginalFileName="PowerRun.exe") | stats count by Computer User Image CommandLine | table Computer User Image CommandLine count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 (Image="*\\All.exe" OR OriginalFileName="All.exe") | stats count by Computer User Image CommandLine ParentImage | table Computer User Image CommandLine ParentImage count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 (Image="*\\Allpatch2.exe" OR OriginalFileName="Allpatch2.exe") | stats count by Computer User Image CommandLine ParentImage | table Computer User Image CommandLine ParentImage count
index=sysmon sourcetype=XmlWinEventLog EventCode=11 TargetFilename="*README-GENTLEMEN.txt" | stats count by Computer User TargetFilename Image | table Computer User TargetFilename Image count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\cmd.exe" CommandLine="*1.bat*" | stats count by Computer User CommandLine ParentImage | table Computer User CommandLine ParentImage count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 CommandLine="*taskkill*dbeng50*" | stats count by Computer User CommandLine | table Computer User CommandLine count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 CommandLine="*taskkill*agntsvc*" | stats count by Computer User CommandLine | table Computer User CommandLine count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 CommandLine="*taskkill*vmcompute*" | stats count by Computer User CommandLine | table Computer User CommandLine count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 CommandLine="*taskkill*vmwp*" | stats count by Computer User CommandLine | table Computer User CommandLine count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 CommandLine="*taskkill*vmms*" | stats count by Computer User CommandLine | table Computer User CommandLine count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 (Image="*\\netscan.exe" OR OriginalFileName="netscan.exe") | stats count by Computer User Image CommandLine | table Computer User Image CommandLine count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 CommandLine="*server.py*" | stats count by Computer User Image CommandLine | table Computer User Image CommandLine count
index=corelight sourcetype=corelight_http uri="*OA_HTML/SyncServlet*" | stats count by src_ip dest_ip uri status_code method | table src_ip dest_ip uri method status_code count
index=corelight sourcetype=corelight_conn id.resp_h="200.107.207.26" | stats count by id.orig_h id.resp_h id.resp_p | table id.orig_h id.resp_h id.resp_p count
index=corelight sourcetype=corelight_conn id.resp_h="185.181.60.11" | stats count by id.orig_h id.resp_h id.resp_p | table id.orig_h id.resp_h id.resp_p count
index=sysmon sourcetype=XmlWinEventLog Hashes="*c0979ec20b87084317d1bfa50405f7149c3b5c5f*" | stats count by Computer Image Hashes | table Computer Image Hashes count
index=sysmon sourcetype=XmlWinEventLog Hashes="*e00293ce0eb534874efd615ae590cf6aa3858ba4*" | stats count by Computer Image Hashes | table Computer Image Hashes count
index=sysmon sourcetype=XmlWinEventLog EventCode=13 TargetObject="*\\Control\\Lsa\\MSV1_0*" | stats count by Computer User Image TargetObject Details | table Computer User Image TargetObject Details count
index=sysmon sourcetype=XmlWinEventLog EventCode=13 TargetObject="*\\CurrentControlSet\\Control\\Lsa*" | stats count by Computer User Image TargetObject Details | table Computer User Image TargetObject Details count
index=sysmon sourcetype=XmlWinEventLog EventCode=13 TargetObject="*\\CurrentControlSet\\Control\\Terminal*" | stats count by Computer User Image TargetObject Details | table Computer User Image TargetObject Details count
index=corelight sourcetype=corelight_conn (id.resp_h="66.249.66.18" OR id.orig_h="66.249.66.18") | stats count by id.orig_h id.resp_h id.resp_p | table id.orig_h id.resp_h id.resp_p count
index=corelight sourcetype=corelight_conn (id.resp_h="95.181.173.227" OR id.orig_h="95.181.173.227") | stats count by id.orig_h id.resp_h id.resp_p | table id.orig_h id.resp_h id.resp_p count
index=corelight sourcetype=corelight_conn (id.resp_h="207.126.152.242" OR id.orig_h="207.126.152.242") | stats count by id.orig_h id.resp_h id.resp_p | table id.orig_h id.resp_h id.resp_p count
index=corelight sourcetype=corelight_conn (id.resp_h="185.220.100.240" OR id.orig_h="185.220.100.240") | stats count by id.orig_h id.resp_h id.resp_p | table id.orig_h id.resp_h id.resp_p count
index=corelight sourcetype=corelight_conn (id.resp_h="107.189.30.69" OR id.orig_h="107.189.30.69") | stats count by id.orig_h id.resp_h id.resp_p | table id.orig_h id.resp_h id.resp_p count
index=corelight sourcetype=corelight_conn (id.resp_h="185.220.101.149" OR id.orig_h="185.220.101.149") | stats count by id.orig_h id.resp_h id.resp_p | table id.orig_h id.resp_h id.resp_p count
index=corelight sourcetype=corelight_dns query="*realbumblebee.net*" | stats count by src_ip query | table src_ip query count
index=corelight sourcetype=corelight_dns query="*trailshop.net*" | stats count by src_ip query | table src_ip query count
index=corelight sourcetype=corelight_dns query="*recentbee.net*" | stats count by src_ip query | table src_ip query count
index=corelight sourcetype=corelight_dns query="*adslsdfdsfmo.world*" | stats count by src_ip query | table src_ip query count
index=sysmon sourcetype=XmlWinEventLog Hashes="*58ddbea084ce18cfb3439219ebcf2fc5c1605d2f6271610b1c7af77b8d0484bd*" | stats count by Computer Image Hashes | table Computer Image Hashes count
index=sysmon sourcetype=XmlWinEventLog Hashes="*ae7c868713e1d02b4db60128c651eb1e3f6a33c02544cc4cb57c3aa6c6581b6e*" | stats count by Computer Image Hashes | table Computer Image Hashes count
index=sysmon sourcetype=XmlWinEventLog Hashes="*5d2204f3a20e163120f52a2e3595db19890050b2faa96c6cba6b094b0a52b0aa*" | stats count by Computer Image Hashes | table Computer Image Hashes count
index=sysmon sourcetype=XmlWinEventLog Hashes="*723d1cf3d74fb3ce95a77ed9dff257a78c8af8e67a82963230dd073781074224*" | stats count by Computer Image Hashes | table Computer Image Hashes count
YARA Rules
Gentlemen_Ransomware_Artifacts: Detects file artifacts associated with The Gentlemen ransomware operation, including ransom notes, defense impairment tools, and reconnaissance scripts
rule Gentlemen_Ransomware_Artifacts {
meta:
author = "RedSheepSec"
description = "Detects file artifacts associated with The Gentlemen ransomware"
date = "2026-09-15"
reference = "https://redpiranha.net/news/the-gentlemen-ransomware-analysis"
threat_actor = "The Gentlemen / Storm-2697"
strings:
$ransom_note = "README-GENTLEMEN.txt" ascii wide
$tor_portal = "tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad" ascii wide
$tox_ref = "TOX" ascii wide
$driver1 = "ThrottleStop.sys" ascii wide
$driver2 = "ThrottleBlood.sys" ascii wide
$tool1 = "GentleKiller" ascii wide
$tool2 = "Allpatch2.exe" ascii wide
condition:
any of ($ransom_note, $tor_portal) or ($tox_ref and any of ($driver1, $driver2)) or any of ($tool1, $tool2)
}
Gentlemen_BYOVD_Drivers: Detects BYOVD driver binaries used by The Gentlemen ransomware for EDR evasion
rule Gentlemen_BYOVD_Drivers {
meta:
author = "RedSheepSec"
description = "Detects BYOVD drivers associated with The Gentlemen ransomware"
date = "2026-09-15"
reference = "https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/"
strings:
$name1 = "ThrottleStop" ascii wide
$name2 = "ThrottleBlood" ascii wide
$ext = ".sys" ascii wide
$pe_header = { 4D 5A }
condition:
$pe_header at 0 and ($ext and any of ($name1, $name2))
}
Clop_Oracle_EBS_GOLDVEIN: Detects artifacts related to the GOLDVEIN.JAVA in-memory loader used in the Clop/FIN11 Oracle EBS exploitation campaign
rule Clop_Oracle_EBS_GOLDVEIN {
meta:
author = "RedSheepSec"
description = "Detects GOLDVEIN.JAVA loader artifacts from Clop Oracle EBS campaign"
date = "2026-09-15"
reference = "https://www.infosecurity-magazine.com/news/google-clop-data-oracle-exploit/"
strings:
$goldvein = "GOLDVEIN" ascii wide nocase
$goldtomb = "GOLDTOMB" ascii wide nocase
$sync = "/OA_HTML/SyncServlet" ascii wide
$xslt1 = "www.oracle.com/XSL/Transform/java/sun.misc.BASE64Decoder" ascii wide
$xslt2 = "www.oracle.com/XSL/Transform/java/javax.script.ScriptEngineManager" ascii wide
$email1 = "support@pubstorm.com" ascii wide
$email2 = "support@pubstorm.net" ascii wide
condition:
any of ($goldvein, $goldtomb) or $sync or any of ($xslt1, $xslt2) or any of ($email1, $email2)
}
Black_Basta_Ransomware_DLL: Detects known Black Basta ransomware DLL samples by SHA256 hash
rule Black_Basta_Ransomware_DLL {
meta:
author = "RedSheepSec"
description = "Detects Black Basta ransomware DLL samples from CISA AA24-131A"
date = "2026-09-15"
reference = "https://www.cisa.gov/sites/default/files/2024-05/aa24-131a-joint-csa-stopransomware-black-basta.pdf"
strings:
$hash1 = { 58 DD BE A0 84 CE 18 CF B3 43 92 19 EB CF 2F C5 C1 60 5D 2F 62 71 61 0B 1C 7A F7 7B 8D 04 84 BD }
$hash2 = { 51 EB 74 9D 6C BD 08 BA F9 D4 3C 2F 83 AB D9 D4 D8 6E B5 20 6F 62 BA 43 B7 68 25 1A 98 CE 9D 3E }
$pe_header = { 4D 5A }
condition:
$pe_header at 0 and any of ($hash1, $hash2)
}
Suricata Rules
SID 2026001: Detects DNS query for The Gentlemen ransomware Tor negotiation portal
alert dns $HOME_NET any -> any any (msg:"HUNT - The Gentlemen Ransomware Tor Portal DNS Query"; dns.query; content:"tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad"; nocase; classtype:trojan-activity; sid:2026001; rev:1; metadata:created_at 2026-09-15, author RedSheepSec;)
SID 2026002: Detects HTTP request to Oracle EBS SyncServlet endpoint exploited in Clop/FIN11 campaign
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"HUNT - Clop/FIN11 Oracle EBS SyncServlet Exploitation Attempt"; flow:to_server,established; http.uri; content:"/OA_HTML/SyncServlet"; classtype:web-application-attack; sid:2026002; rev:1; metadata:created_at 2026-09-15, author RedSheepSec, cve CVE-2025-61882;)
SID 2026003: Detects outbound connection to Clop/FIN11 Oracle EBS C2 IP 200.107.207.26
alert ip $HOME_NET any -> 200.107.207.26 any (msg:"HUNT - Clop/FIN11 Oracle EBS Reverse Shell C2"; classtype:trojan-activity; sid:2026003; rev:1; metadata:created_at 2026-09-15, author RedSheepSec;)
SID 2026004: Detects outbound connection to Clop/FIN11 Oracle EBS campaign IP 185.181.60.11
alert ip $HOME_NET any -> 185.181.60.11 any (msg:"HUNT - Clop/FIN11 Oracle EBS Campaign C2"; classtype:trojan-activity; sid:2026004; rev:1; metadata:created_at 2026-09-15, author RedSheepSec;)
SID 2026005: Detects DNS query for Black Basta realbumblebee.net Cobalt Strike C2 domain
alert dns $HOME_NET any -> any any (msg:"HUNT - Black Basta Cobalt Strike C2 realbumblebee.net DNS Query"; dns.query; content:"realbumblebee.net"; nocase; classtype:trojan-activity; sid:2026005; rev:1; metadata:created_at 2026-09-15, author RedSheepSec;)
SID 2026006: Detects DNS query for Black Basta trailshop.net C2 domain
alert dns $HOME_NET any -> any any (msg:"HUNT - Black Basta C2 trailshop.net DNS Query"; dns.query; content:"trailshop.net"; nocase; classtype:trojan-activity; sid:2026006; rev:1; metadata:created_at 2026-09-15, author RedSheepSec;)
SID 2026007: Detects connection to high-confidence Black Basta Tor exit node 185.220.100.240
alert ip $HOME_NET any -> 185.220.100.240 any (msg:"HUNT - Black Basta Tor Exit Node 185.220.100.240"; classtype:trojan-activity; sid:2026007; rev:1; metadata:created_at 2026-09-15, author RedSheepSec;)
SID 2026008: Detects DNS query for Black Basta adslsdfdsfmo.world C2 domain
alert dns $HOME_NET any -> any any (msg:"HUNT - Black Basta C2 adslsdfdsfmo.world DNS Query"; dns.query; content:"adslsdfdsfmo.world"; nocase; classtype:trojan-activity; sid:2026008; rev:1; metadata:created_at 2026-09-15, author RedSheepSec;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Sysmon (EventID 1, 6, 11, 13) | T1068, T1562.001, T1486, T1489, T1574, T1490, T1543 | Requires Sysmon deployed with configuration that includes driver load (EID 6), process creation (EID 1), file creation (EID 11), and registry value set (EID 13) events. Verify Sysmon is deployed across all Windows endpoints and servers. |
| Windows Security Event Log (4624, 4625, 4688, 4720) | T1078, T1136, T1021 | Requires Windows Security audit policy with logon auditing, account management auditing, and process creation auditing enabled. Command-line logging in 4688 events requires advanced audit policy. |
| Corelight/Zeek (HTTP, DNS, Connection, SMB) | T1190, T1021, T1048.001, T1570 | Requires Corelight sensors with HTTP, DNS, connection, and SMB file logging enabled. Verify coverage of segments containing Oracle EBS servers, Cisco FMC appliances, and SonicWall SMA devices. |
| Palo Alto Firewall (pan:traffic, pan:threat) | T1133, T1190 | Requires firewall logging at appropriate verbosity to capture connection metadata for management interface access attempts. |
| CrowdStrike EDR | T1562.001, T1068, T1486 | CrowdStrike detection events and sensor telemetry provide EDR-level visibility for BYOVD attacks and defense impairment. Verify prevention policies are active and not in detect-only mode. |
| PowerShell Script Block Logging (EventID 4104) | T1574 | Required for detecting Invoke-TheHash and other PowerShell-based lateral movement tools used by Qilin-linked actors. |
| DNS Server Logs | T1190 | Required for detecting DNS queries to known ransomware infrastructure domains and Tor-related lookups. |
Mitigations & Recommendations
Curated baseline: LockBit; library archetype
The curated LockBit playbook covers ransomware fundamentals well: edge-CVE exploitation, stolen credentials, shadow copy deletion, service-kill lists, exfil tooling hunts, and leak-site monitoring. However, this incident introduces net-new tradecraft from Qilin, The Gentlemen, and Clop: specifically BYOVD kernel-level EDR tampering, a named EDR-killer framework (GentleKiller), new 2026 edge CVEs (Cisco FMC, SonicWall SMA 1000, Oracle EBS, PTC Windchill, FortiGate), Rust/Golang cross-platform ransomware binaries (including password-parameter execution), and port-forwarding on compromised edge devices for AD protocol tunneling.
Established mitigations (curated):
- Execute all steps from Ransomware archetype containment (network isolation, backup protection, krbtgt reset, etc.).
- Block CISA-published LockBit C2 and exfil IPs/domains at perimeter.
- If Citrix ADC is deployed and Citrix Bleed is the vector: invalidate ALL ADC sessions and rotate session keys.
- Block MegaSync / rclone / StealBit process execution via EDR or AppLocker policy.
- Hunt peers of patient zero for LockBit precursor (commodity loader like Qakbot, IcedID, Bumblebee).
Established detection guidance (curated):
- Confirm LockBit by matching ransom note filename, wallpaper text, or encrypted file extension against CISA / vendor IOC list.
- Determine affiliate initial access vector: exploited edge CVE, phished credentials, brute-forced RDP, or IAB handoff.
- Scan for StealBit exfil tool and rclone misuse.
- Check for shadow copy deletion and recovery-disabling commands (shared with all ransomware but especially consistent for LockBit).
- Citrix Bleed session hijack hunt (if Citrix ADC/NetScaler is deployed).
- LockBit-specific service termination list: identify stopped services that LockBit kills pre-encryption.
Net-new from this incident:
- Extend the LockBit playbook into a multi-actor ransomware framework covering Qilin (Rust cross-platform, ESXi), The Gentlemen (Golang, password-parameter execution, BYOVD), and Clop (Windchill/EBS exploitation) since August 2026 volume is dominated by these operators.
- Add a standing BYOVD detection capability: enforce Microsoft's vulnerable driver blocklist and alert on any load of drivers from known-abused lists on non-workstation roles.
- Include ESXi-specific ransomware response (Qilin's Rust binary targets ESXi) — a scenario the current LockBit playbook does not address.
- Track ArmCorp / Storm-2697 attribution intelligence since The Gentlemen originated from a former Qilin affiliate, complicating affiliate fingerprinting.
- Enable Microsoft's vulnerable driver blocklist (HVCI / WDAC) and add ThrottleStop.sys and ThrottleBlood.sys hashes to EDR block policy. (Why: T1068 - BYOVD by The Gentlemen.)
- Emergency-patch or take offline Cisco FMC (CVE-2026-20079), SonicWall SMA 1000 (CVE-2026-15409/15410), Oracle EBS (CVE-2025-61882), PTC Windchill (CVE-2026-12569), and audit FortiGate management interfaces for internet exposure. (Why: T1190/T1133 - New edge CVEs actively exploited by Qilin/Clop/The Gentlemen.)
- Audit and remove unauthorized port-forwarding / NAT rules on Cisco FMC and other edge devices; rotate device admin credentials and API tokens. (Why: T1021 - Qilin port forwarding for AD protocol tunneling.)
- Block execution of All.exe, Allpatch2.exe, PowerRun.exe, and GentleKiller signatures via EDR/AppLocker. (Why: T1562.001 / T1574 - Named Gentlemen tooling.)
- Detect: Hunt for BYOVD driver loads matching ThrottleStop.sys, ThrottleBlood.sys, or other known vulnerable drivers used for kernel-mode EDR tampering. (Why: T1068 - The Gentlemen BYOVD loading ThrottleStop.sys/ThrottleBlood.sys for kernel access - not covered by curated LockBit playbook.)
- Detect: Search for GentleKiller framework artifacts and named anti-AV utilities (All.exe, Allpatch2.exe) on hosts prior to encryption. (Why: T1562.001 - The Gentlemen's specific EDR-killer toolset is distinct from LockBit's service-kill list.)
- Detect: Identify Golang/Rust ransomware binaries requiring a password parameter at execution (unusual command-line signature). (Why: T1486 - The Gentlemen's Golang binary requires password param; Qilin uses Rust. Curated playbook only addresses LockBit variants.)
- Detect: Sweep for edge appliance CVE exploitation on Cisco FMC (CVE-2026-20079), SonicWall SMA 1000 (CVE-2026-15409/15410), Oracle EBS (CVE-2025-61882), PTC Windchill (CVE-2026-12569), and FortiGate management interfaces. (Why: T1190/T1133 - New 2026 CVEs not in curated playbook (which lists only Citrix Bleed and GoAnywhere).)
Sources
- Global ransomware attacks hit record 997 in August 2026
- University ransomware attacks rise
- Unit 42: The Gentlemen Ransomware
- Comparitech: The Gentlemen Ransomware Stats
- Adaptive Security: Qilin Ransomware
- CybelAngel: Qilin Ransomware Tactics
- Red Piranha: The Gentlemen Ransomware Analysis
- Blackpoint Cyber: Gentlemen Ransomware Threat Profile
- Blackpoint Cyber: The Gentlemen PDF Report
- Trend Micro: Unmasking the Gentlemen Ransomware
- Paubox: Cl0p Names 29 Oracle EBS Breach Victims
- Infosecurity: Google Clop Data Oracle Exploit
- The Hacker News: Cl0p-Linked Hackers Breach Dozens
- SecurityWeek: Nearly 30 Alleged Victims of Oracle EBS Hack
- Security Affairs: Attackers Exploit Cisco FMC Flaw for Qilin
- Tech Insider: ATF Qilin Ransomware Breach Major Incident
- Tech Insider: Interim HealthCare Ransomware Genesis Attack
- Breachsense: August 2026 Ransomware Report
- Ransomnews: Ransomware Tracker
- Ransomnews: 2026 Ransomware Attacks
- Scrutex: Weekly Ransomware Intelligence Report August 16 2026
- MOXFIVE: Qilin Ransomware 2026 TTPs and Defense Guide
- Security Affairs: Google Mandiant Oracle EBS Zero-Day
- Qualys: Oracle EBS RCE Vulnerability CVE-2025-61882
- Rimini Street: Inside the Clop Ransomware Campaign Oracle EBS