The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
2026-05-29T02:52:17Z•fd99ff063f16aa3d6c21b998173d69a090b805ea151b74ca8a094c142fbbfcac
@antvAI-assisted-malicious-sitesCI/CD credential theftConfluenceF5 BIG-IPFox TempestGPU miningGentlemenGoKerberos relayLinux intrusionMini Shai HuludSEO poisoningScreenConnectStorm-2697Vanilla Tempestcredential theftcryptojackingidentity security platforms RAMPART Claritylateral movementmalware-signing-as-a-servicenpmransomwareself-propagationsupply chain compromise
What happened
Microsoft Threat Intelligence posts (May 19–28, 2026) detail multiple active and high-impact campaigns and supply-chain threats: the Gentlemen ransomware (Go-based, affiliated with Storm-2697) uses per-file ephemeral key encryption plus an aggressive self‑propagation module that performs simultaneous lateral-movement techniques to quickly compromise networks; a cryptojacking campaign leverages SEO poisoning, malicious sites surfaced via AI chatbots, ScreenConnect, and .NET utilities to deploy GPU miners on high-performance hosts; a multi-stage Linux intrusion abused exposed F5 BIG-IP to pivot/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- fd99ff063f16aa3d6c21b998173d69a090b805ea151b74ca8a094c142fbbfcac
- Enrichment time
- 2026-05-29T02:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.