INTEL_REPORT
Microsoft Security Blog · published 5/28/2026, 3:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target. The post The Gentlemen ransomware: Dissecting a self-propagating Go…
https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor
sha256:d591d1f2bc8b082b3e18658db8b2f12e31aad073066702ce9f2384bf0b863d52
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| sha256 |
| 078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b |
| Open → |
| sha256 | fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68 | Open → |
| domain | wmic.exe | Open → |