Automatically translated.View original post

The Gentlemen, a group of new ransomware, heavy rampage.

"The Gentlemen," a new ransomware group, has been on a heavy rampage since mid-2025, stealing important data before logging, hitting more than 17 countries around the world.

Gentlemen or gentlemen, when you see this word, you may think of a modest, good-looking man with a genus, but if you turn it into a malware name, especially Ransomware, there is no way for the victim to be polite.

According to a report by the website, Cyberpress has mentioned the detection of a new ransomware spread campaign called Gentlemen, which was developed by the ransomware group of the same name. The malware has been spreading since last August and has spread to 17 countries around the world, covering countries in the Asia-Pacific, North America, South America and the Middle East. The attack has focused on important and high-value business groups such as manufacturing groups, construction groups, medical business groups, and insurance business groups, focusing on medium and large businesses. The model of operations shows that the ransomware group is Highly proficient and professional.

Technically, the Gentlemen ransomware is built with the Go language. It collects a variety of techniques for invading the victim's system on a single malware. After the malware is embedded on the victim's system, before encrypting the files on the victim's machine to secure them. The malware will shut down the Windows Defender, shut down the Backup Service, such as Veeam, stop Databases such as MSSQL and MongoDB, and delete the Sytem Log to cause post-damage analysis to occur. Even harder to do.

The malware will run under specified environment images. It will run within the Password (-password) parameter. If the password is not used correctly, the malware will stop immediately. This prevents accidental operation and prevents being monitored by the malware research team. In addition, the malware also runs Argument on Command-Line to help determine the scope of operation, the desired file target, and the speed of encryption of the file. It increases the performance and flexibility of such malware, such as -system, -shares, -fast, and -ultrafast, etc.

As part of the file encryption technique, this ransomware uses a hybrid X25519 (ECDH) and XChaCha20 encryption technique in which each encrypted file has a unique key (Unique Key) and a nonce key, which is encrypted with a non-static format, or Dynamic, to increase the difficulty of trying to decrypt the unlock of the file without relying on the private key or Private Key stored with hackers using such ransomware. Files of 1 MB or smaller are fully encrypted, while larger files are encrypted only in parts of the file simply by guaranteeing that the file will be used. No. To help file encryption more quickly than full-file encryption.

After the ransomware has completed the encryption of the file lock on the machine, the malware will release a ransom note under the file name README-GENTLEMEN.txt. It will tell which folders are the victims, along with the words that all files have been sent to hackers, and will release them to the public immediately if the ransom is not paid at the specified time. It is proposed that two files will be unlocked to confirm that hackers can unlock the file. At the same time, the malware will change the background (Wallpaper) to intimidate the victim.

A research team from AhnLab, an expert in the development of cyber tools that detect ransomware, has identified ransomware under the name Ransomware / Win GentlemenCrypt and updated the AhnLab V3 detection tool during the month of December to detect it as well as provide malware identification in the MD5 Hash format. The malware file identifier looks like this.

adf675ffc1acb357f2d9f1a94e016f52 and de1a114a2c5552387a1bbb61501bf129

# Welcome 2026 # Take care of yourself # Open budget # Includes IT matters # Trending

1/4 Edited to

... Read moreใครที่กดค้นหา “The Gentlemen นางเอก” แล้วเจอผลลัพธ์ปน ๆ กัน ไม่ได้แปลว่าคุณจำผิดนะ เพราะคำว่า The Gentlemen มักถูกใช้ในหลายคอนเทนต์ และบางทีไปโผล่คู่กับข่าวไอที/แรนซัมแวร์ด้วย ทำให้คนที่ตั้งใจหาข้อมูลสายหนัง-ซีรีส์งงได้ง่ายมาก จากประสบการณ์เรา เวลาจะหาว่า “นางเอกคือใคร” ให้เริ่มจากการแยกเวอร์ชันก่อน: The Gentlemen ที่คนส่วนใหญ่ถามหานางเอก มักหมายถึงเวอร์ชันซีรีส์/จักรวาลเดียวกับเรื่องแนวอาชญากรรม-คอมเมดี้แบบอังกฤษ ซึ่งโทนจะเป็นแก๊งมาเฟีย การต่อรองผลประโยชน์ และความสัมพันธ์ตัวละครที่ไม่ได้มี “นางเอก” แบบโรแมนติกชัด ๆ เหมือนซีรีส์รัก แต่จะมีตัวละครหญิงเด่นหลายคนที่ขับเคลื่อนพล็อต ทริคที่เราใช้แล้วเวิร์ก: 1) ดูรายชื่อนักแสดงในหน้าแพลตฟอร์มที่คุณดู (Netflix/Prime/ฯลฯ) แล้วโฟกัสคำว่า “Main cast” เพราะตัวละครหญิงที่เป็นแกนเรื่องมักอยู่ตรงนั้น 2) สังเกตบทบาท ไม่ใช่แค่หน้าปก: บางเรื่องผู้หญิงไม่ได้ขึ้นเป็น “นางเอก” แต่เป็นคนคุมเกม เช่น ผู้จัดการธุรกิจ, คนกลางเจรจา, สายข่าว หรือคนในตระกูลที่มีอิทธิพล ซึ่งมักสำคัญกว่าเลิฟไลน์ 3) ถ้าคุณหมายถึง “นางเอกในเชิงคู่กับพระเอก” ให้ลองค้นแบบเจาะจงเพิ่ม เช่น “The Gentlemen female lead character name” หรือใส่ชื่อพระเอกต่อท้าย จะตัดความคลุมเครือได้เยอะ อีกอย่างที่อยากเตือน (เพราะเราเคยพลาด): ถ้าคุณเจอคำว่า “YOUR NETWORK IS LOCKED BY THE GENTLEMEN” หรือไฟล์เรียกค่าไถ่แนว README-GENTLEMEN.txt นั่นไม่เกี่ยวกับซีรีส์เลย แต่เป็นคนละเรื่องแบบสิ้นเชิง เป็นคีย์เวิร์ดที่พาไปสายความปลอดภัยไซเบอร์ ทำให้ผลค้นหายิ่งมั่ว สรุปสั้น ๆ: The Gentlemen ไม่ได้มี “นางเอก” แบบสูตรสำเร็จคนเดียวเสมอไป แต่มีตัวละครหญิงเด่นหลายตำแหน่ง ให้ยึดเวอร์ชันที่คุณดู + เช็ก Main cast + ดูบทบาทในพล็อต แล้วคุณจะระบุได้ว่าใครคือ “นางเอก” ในความหมายที่คุณต้องการจริง ๆ