Ransomware attacks are increasingly about more than encrypting files. Modern ransomware operations combine credential theft, remote access abuse, data exfiltration, security disruption, and backup tampering before encryption begins, making early detection and response increasingly important.
Sophos Counter Threat Unit™ (CTU) researchers analysed 15 incidents linked to The Gentlemen, a ransomware-as-a-service (RaaS) operation run by the threat group Sophos tracks as GOLD SHERWOOD. Sophos found a repeatable attack pattern involving rapid privilege escalation, legitimate administrative tools, stolen credentials, data theft, attempts to disable security products, and ransomware deployment. In some cases, ransomware was deployed less than 24 hours after the first identified post-compromise activity.
For businesses, the findings highlight an important reality: ransomware prevention cannot depend only on detecting the final encryption stage. Organisations need visibility and controls across remote access, identities, endpoints, administrative activity, data movement, and backup infrastructure throughout the entire attack lifecycle.
The Gentleman Ransomware Operation Is Scaling Quickly
GOLD SHERWOOD began operating The Gentlemen RaaS scheme in mid-2025 using a double-extortion model, where attackers steal data before encrypting systems and can use the stolen information as additional pressure on victims. According to Sophos, fewer than 20 victim names were published each month during the remainder of 2025, but the average increased to more than 75 per month at the beginning of 2026. By the end of July 2026, 683 victim names had appeared on the group's leak site, including 169 during July alone.
The victims identified by Sophos span multiple industries, indicating an opportunistic approach rather than attacks limited to one sector. This means organisations of different sizes and industries may be exposed when attackers identify vulnerable internet-facing systems, weak remote-access controls, or compromised credentials.
Compromised Credentials and Remote Access Can Open the Door
Sophos observed The Gentlemen affiliates using compromised credentials and remote-access services to enter and move through networks. In one investigated incident, attackers authenticated to a Fortinet SSL VPN using compromised credentials, with the absence of multi-factor authentication allowing access. The attacker then established additional VPN sessions and used Remote Desktop Protocol (RDP) with legitimate domain credentials to move between internal systems, including file servers and domain controllers.
Once inside, attackers used legitimate Windows utilities and administrative functions for reconnaissance, privilege escalation, and persistence. Sophos also observed tools being staged in the legitimate C:\PerfLogs directory, including network discovery tools, data-exfiltration utilities, and tools intended to interfere with endpoint security. This demonstrates why organisations need to monitor not only known malware, but also unusual behaviour involving legitimate tools and privileged accounts.
Attackers Target Data, Security Controls, and Backups Before Encryption
The Gentlemen affiliates do not immediately move to ransomware encryption. Sophos observed attackers stealing data using tools including Rclone, Restic, FileZilla, MEGAsync, and MinIO Client, sometimes changing tools during an intrusion depending on the environment. This supports the group's double-extortion strategy, where sensitive information can be stolen before systems are encrypted.
Attackers also attempted to disable antivirus and EDR protections, including through vulnerable-driver techniques, while targeting backup and recovery services to make restoration more difficult. Sophos observed more than 200 variations of commands used to disable backup-related services across the investigated incidents. In some cases, attackers also cleared Windows logs to reduce visibility into their activity. Sophos found a median period of approximately two days between the first observed post-compromise activity and ransomware deployment, with the fastest observed case taking less than 24 hours.
How JK Tech Helps
As an official Sophos partner, JK Tech helps organisations build a more resilient defence against ransomware by strengthening the controls attackers commonly target, including endpoints, identities, remote access, networks, and critical systems. With Sophos Endpoint, Firewall, XDR and MDR alongside deployment, security configuration, monitoring, backup and recovery, and managed IT support, JK Tech can help businesses improve threat visibility, enforce stronger access controls such as MFA, identify suspicious administrative and data-transfer activity, protect recovery capabilities, and respond faster before an intrusion progresses from initial access to data theft and ransomware deployment. Sophos' portfolio includes endpoint protection, EDR, XDR, firewall, identity security, MDR, incident response, and backup and recovery capabilities.
Further Reading & Resources
https://www.sophos.com/en-us/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation - Sophos Newsroom
Source: Sophos Limited
Need help turning this into action?
Speak with JK Tech about practical next steps, technology planning, cyber resilience, deployment, and business-ready IT implementation.
Contact Us
Need help with your enquiry? Speak with JK Tech to get more information.
Tell us what you need, and our team will get back to you shortly.



