The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

2026-05-29T02:52:17Zfd99ff063f16aa3d6c21b998173d69a090b805ea151b74ca8a094c142fbbfcac
@antvAI-assisted-malicious-sitesCI/CD credential theftConfluenceF5 BIG-IPFox TempestGPU miningGentlemenGoKerberos relayLinux intrusionMini Shai HuludSEO poisoningScreenConnectStorm-2697Vanilla Tempestcredential theftcryptojackingidentity security platforms RAMPART Claritylateral movementmalware-signing-as-a-servicenpmransomwareself-propagationsupply chain compromise

What happened

Microsoft Threat Intelligence posts (May 19–28, 2026) detail multiple active and high-impact campaigns and supply-chain threats: the Gentlemen ransomware (Go-based, affiliated with Storm-2697) uses per-file ephemeral key encryption plus an aggressive self‑propagation module that performs simultaneous lateral-movement techniques to quickly compromise networks; a cryptojacking campaign leverages SEO poisoning, malicious sites surfaced via AI chatbots, ScreenConnect, and .NET utilities to deploy GPU miners on high-performance hosts; a multi-stage Linux intrusion abused exposed F5 BIG-IP to pivot/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
fd99ff063f16aa3d6c21b998173d69a090b805ea151b74ca8a094c142fbbfcac
Enrichment time
2026-05-29T02:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.