The Gentlemen Hackers Encrypt Networks in 24 Hours
The Gentlemen hackers, a notorious ransomware group, have accelerated their attack strategy to encrypt enterprise networks within 24 hours. By disabling endpoint detection and response (EDR) systems along with backups, these criminals swiftly render businesses vulnerable. As a ransomware-as-a-service operation, the group allows affiliates to target accessible organizations. Analysts from Sophos, who studied 15 incidents linked to the group, known as GOLD SHERWOOD, detailed their methodical approach, which includes exploiting unpatched devices and accessing systems via stolen VPN credentials.
Once inside, attackers manipulate admin controls and utilize legitimate system tools to expand their reach. They strategically disable antivirus functions and reconfigure Windows Defender to avoid detection before encryption. The urgency with which they act highlights the critical need for organizations to secure remote-access points, enforce multi-factor authentication, and monitor unusual activities closely. Companies are urged to enhance their defenses against such sophisticated threats. For more, explore the full article at Cyber Security News.
