
GOLD SHERWOOD Deploys Rapid Sub-24-Hour Ransomware Playbook Against Enterprise Targets
Threat actor GOLD SHERWOOD has escalated destructive double-extortion attacks, neutralizing security tooling and shadow backups before network encryption in under 24 hours.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- North America
- Confidence:
- High Confidence
- Source:
- Mandiant
- Read Time:
- 3 min
Executive Summary
Threat intelligence reporting has identified an aggressive, highly optimized attack lifecycle deployed by the cybercriminal syndicate known as The Gentlemen, tracked by researchers as GOLD SHERWOOD. The ransomware-as-a-service (RaaS) operation utilizes a streamlined double-extortion framework characterized by rapid data exfiltration, proactive defense neutralization, and the complete destruction of system backups prior to widespread network encryption. In observed intrusions, the dwell time from initial access to enterprise-wide payload deployment has contracted to under 24 hours, representing a significant challenge to defensive teams reliant on traditional mean-time-to-detect (MTTD) thresholds.
Threat Analysis
The operation conducted by GOLD SHERWOOD adheres to modern double-extortion dynamics, coupling wholesale data extortion with operational disruption. In parallel with emergent activity from factions such as Storm and Settra—which recently claimed multiple North American enterprise victims across finance, construction, and healthcare technology—GOLD SHERWOOD prioritizes tempo over prolonged reconnaissance. By accelerating lateral movement and automating privilege escalation, the group minimizes the window of opportunity for Security Operations Centers (SOCs) to contain intrusions prior to impact.
Technical Details
The intrusion lifecycle begins primarily with compromised credentials sourced from infostealer logs or internet-facing appliance exploits. Upon obtaining access, GOLD SHERWOOD establishes persistence via legitimate administrative utilities (living-off-the-land techniques).
Before initiating encryption routines, the operators execute structured scripts designed to impair defensive capabilities. These actions include:
- Terminating Endpoint Detection and Response (EDR) and antivirus services via vulnerable signed drivers (Bring Your Own Vulnerable Driver techniques) or stolen high-privilege credentials.
- Disabling automated backup agents and deleting Volume Shadow Copies (
vssadmin delete shadows /all /quiet). - Staging and exfiltrating intellectual property and enterprise data to remote storage services via encrypted conduits.
- Deploying multi-threaded encryptor binaries across the network perimeter simultaneously through scheduled tasks and Group Policy Objects (GPOs).
Attribution Assessment
The threat actor is tracked as GOLD SHERWOOD, operating the RaaS affiliate program known as The Gentlemen. Industry assessments evaluate with moderate confidence that the core operators operate out of Eastern Europe or the Commonwealth of Independent States (CIS), filling operational voids created following law enforcement disruptions of older tier-one syndicates such as ALPHV/BlackCat and LockBit.
Implications
The drastic shortening of the dwell time to less than 24 hours indicates a structural shift across mid-tier RaaS operators. Defensive response playbooks that assume multi-day lateral movement cycles are increasingly ineffective. The proactive disabling of backup systems highlights an adversary intention to ensure victims cannot recover operational capability without capitulating to extortion demands.
Recommendations
- Implement Immutable Backups: Ensure all critical backup environments are air-gapped, immutable, and protected with out-of-band multi-factor authentication (MFA).
- Harden Endpoint Protections: Enforce tamper-protection controls across EDR tooling to prevent malicious process termination and block unapproved driver installations.
- Enforce Phishing-Resistant MFA: Restrict remote access pathways, VPNs, and administrative portals with hardware-backed or FIDO2 tokens to mitigate the impact of infostealer logs.
- Automate Rapid Containment: Configure SIEM/SOAR platforms to automatically isolate hosts exhibiting mass process kills or suspicious Volume Shadow Copy manipulation.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

The Gentlemen and INC Ransom Deploy Rapid Double Extortion Across Global Targets

FulcrumSec Targets Manchester Airports Group as Krybit and Qilin Escalate Global Extortion Campaigns

