News Room
16
Share
GOLD SHERWOOD Deploys Rapid Sub-24-Hour Ransomware Playbook Against Enterprise Targets
criticalThreat Intelligence

GOLD SHERWOOD Deploys Rapid Sub-24-Hour Ransomware Playbook Against Enterprise Targets

Threat actor GOLD SHERWOOD has escalated destructive double-extortion attacks, neutralizing security tooling and shadow backups before network encryption in under 24 hours.

04 September 2026Last updated 04 September 20263 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
North America
Confidence:
High Confidence
Source:
Mandiant
Read Time:
3 min

Executive Summary

Threat intelligence reporting has identified an aggressive, highly optimized attack lifecycle deployed by the cybercriminal syndicate known as The Gentlemen, tracked by researchers as GOLD SHERWOOD. The ransomware-as-a-service (RaaS) operation utilizes a streamlined double-extortion framework characterized by rapid data exfiltration, proactive defense neutralization, and the complete destruction of system backups prior to widespread network encryption. In observed intrusions, the dwell time from initial access to enterprise-wide payload deployment has contracted to under 24 hours, representing a significant challenge to defensive teams reliant on traditional mean-time-to-detect (MTTD) thresholds.

Threat Analysis

The operation conducted by GOLD SHERWOOD adheres to modern double-extortion dynamics, coupling wholesale data extortion with operational disruption. In parallel with emergent activity from factions such as Storm and Settra—which recently claimed multiple North American enterprise victims across finance, construction, and healthcare technology—GOLD SHERWOOD prioritizes tempo over prolonged reconnaissance. By accelerating lateral movement and automating privilege escalation, the group minimizes the window of opportunity for Security Operations Centers (SOCs) to contain intrusions prior to impact.

Technical Details

The intrusion lifecycle begins primarily with compromised credentials sourced from infostealer logs or internet-facing appliance exploits. Upon obtaining access, GOLD SHERWOOD establishes persistence via legitimate administrative utilities (living-off-the-land techniques).

Before initiating encryption routines, the operators execute structured scripts designed to impair defensive capabilities. These actions include:

  • Terminating Endpoint Detection and Response (EDR) and antivirus services via vulnerable signed drivers (Bring Your Own Vulnerable Driver techniques) or stolen high-privilege credentials.
  • Disabling automated backup agents and deleting Volume Shadow Copies (vssadmin delete shadows /all /quiet).
  • Staging and exfiltrating intellectual property and enterprise data to remote storage services via encrypted conduits.
  • Deploying multi-threaded encryptor binaries across the network perimeter simultaneously through scheduled tasks and Group Policy Objects (GPOs).

Attribution Assessment

The threat actor is tracked as GOLD SHERWOOD, operating the RaaS affiliate program known as The Gentlemen. Industry assessments evaluate with moderate confidence that the core operators operate out of Eastern Europe or the Commonwealth of Independent States (CIS), filling operational voids created following law enforcement disruptions of older tier-one syndicates such as ALPHV/BlackCat and LockBit.

Implications

The drastic shortening of the dwell time to less than 24 hours indicates a structural shift across mid-tier RaaS operators. Defensive response playbooks that assume multi-day lateral movement cycles are increasingly ineffective. The proactive disabling of backup systems highlights an adversary intention to ensure victims cannot recover operational capability without capitulating to extortion demands.

Recommendations

  • Implement Immutable Backups: Ensure all critical backup environments are air-gapped, immutable, and protected with out-of-band multi-factor authentication (MFA).
  • Harden Endpoint Protections: Enforce tamper-protection controls across EDR tooling to prevent malicious process termination and block unapproved driver installations.
  • Enforce Phishing-Resistant MFA: Restrict remote access pathways, VPNs, and administrative portals with hardware-backed or FIDO2 tokens to mitigate the impact of infostealer logs.
  • Automate Rapid Containment: Configure SIEM/SOAR platforms to automatically isolate hosts exhibiting mass process kills or suspicious Volume Shadow Copy manipulation.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo