Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
2 malware familiesExploits CVEs in the wild

Storm-2697

Also known asstorm_2697

Storm-2697 is a financially motivated threat actor tracked by Microsoft Threat Intelligence as the operator behind the ransomware-as-a-service platform The Gentlemen. The group emerged around mid-2025 as a tightly closed ransomware network and later transitioned into a public RaaS ecosystem, offering access to affiliates by September 2025. Microsoft reported that the operators established an official partnership with BreachForums to recruit affiliates, including penetration testers and initial access brokers. Storm-2697/The Gentlemen uses a double-extortion model, encrypting victim systems while exfiltrating data and threatening public release of stolen corporate information. Microsoft observed victims across healthcare, transportation, education, and financial sectors, with activity spanning North America, South America, Europe, Africa, and Asia. The Gentlemen ransomware is written in Go and obfuscated with Garble. It uses a hybrid cryptographic scheme based on Curve25519 and XChaCha20, appends the .umc16h extension to encrypted files, and drops ransom notes named README-GENTLEMEN.txt. The malware disables Microsoft Defender protections, adds exclusions for its binary and the C:\ volume, deletes Volume Shadow Copies, clears event logs, deletes forensic artifacts including PowerShell history, and terminates or disables processes and services associated with virtualization, databases, backup software, EDR tools, SAP, Exchange, Office applications, browsers, remote access tools, and accounting software. It also establishes persistence via scheduled tasks named UpdateSystem and UpdateUser and Run registry values GupdateS and GupdateU. The ransomware supports multiple execution modes, including local, network-share, and SYSTEM-level encryption. When launched with spreading enabled, it gains worm-like propagation capabilities by staging itself over SMB, creating hidden shares, enumerating remote hosts and shares, weakening defenses on remote systems, and attempting numerous remote execution methods including PsExec, WMIC, scheduled tasks, services, PowerShell remoting, and PowerShell WMI. It can also overwrite free disk space using wipefile.tmp and self-delete after execution. Known alias in the provided content: The Gentlemen.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Health Care Equipment & Services
  • Transportation
  • Academia & Research
MITRE ATT&CK

Tradecraft

30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics37 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1190
Exploit Public-Facing Application
TA0002
Execution
3 techniques
T1047×2
Windows Management Instrumentation
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1059.003
Windows Command Shell
TA0003
Persistence
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1112
Modify Registry
TA0004
Privilege Escalation
1 technique
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
TA0005
Stealth
2 techniques
T1070
Indicator Removal
T1070.001×2
Clear Windows Event Logs
T1070.004×2
File Deletion
T1218
System Binary Proxy Execution
T1218.002
Control Panel
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0007
Discovery
7 techniques
T1007
System Service Discovery
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1057
Process Discovery
T1069
Permission Groups Discovery
T1083×2
File and Directory Discovery
T1135×2
Network Share Discovery
TA0008
Lateral Movement
2 techniques
T1021
Remote Services
T1021.002
SMB/Windows Admin Shares
T1021.006
Windows Remote Management
T1570×2
Lateral Tool Transfer
TA0010
Exfiltration
2 techniques
T1041
Exfiltration Over C2 Channel
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
TA0040
Impact
5 techniques
T1486×4
Data Encrypted for Impact
T1489×2
Service Stop
T1490×2
Inhibit System Recovery
T1561
Disk Wipe
T1657×2
Financial Theft
WEAPONIZED

Associated vulnerabilities

4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.

CVE-2024-55591Authentication Bypass in FortiOS and FortiProxy Node.js WebSocket ModuleIn the wildEvidence2

The group actively tracks and evaluates modern vulnerabilities, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, and combines them with technique-driven paths like backup and management-controller abuse and NTLM relay workflows, giving them a flexible exploitation pipeline.

CVE-2025-32433Unauthenticated RCE in Erlang/OTP SSH ServerIn the wildEvidence2

The group actively tracks and evaluates modern vulnerabilities, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, and combines them with technique-driven paths like backup and management-controller abuse and NTLM relay workflows, giving them a flexible exploitation pipeline.

CVE-2025-33073Windows SMB Client Elevation of Privilege VulnerabilityIn the wildEvidence2

The group actively tracks and evaluates modern vulnerabilities, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, and combines them with technique-driven paths like backup and management-controller abuse and NTLM relay workflows, giving them a flexible exploitation pipeline.

CVE-2025-7771Arbitrary Physical Memory Read/Write in TechPowerUp ThrottleStop.sysIn the wildEvidence1

Defense Evasion. BYOVD через ThrottleStop.sys (CVE-2025-7771, CVSS 8.7)... Легитимный драйвер ThrottleStop.sys ... экспонирует два IOCTL-интерфейса для произвольного чтения и записи в физическую память через MmMapIoSpace... Публичный эксплойт: EDB-52512.

IOCS

Observables

5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping30

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs4

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables5

Domains, IPs, and hashes tied to this actor, refreshed continuously.