NEWS The Old Wolf of WannaCry's Old Trick Kills The Gentlemen - the most active extortionist of 2026

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,425
The hackers beat them with the same code. Experts have found a way to save data without paying a ransom.
1777760853055.png
The Gentlemen ransomware victims for the first time got a chance to return their files without paying for a ransom. Canadian company Bedrock Safeguard reported a public way of decrypting the data encrypted by this family, which is also known as hastalamaurete and by the first quarter of 2026 scored more than 320 confirmed victims.

According to Bedrock Safeguard, The Gentlemen now remains one of the most active RaaS groups. Previously, large companies, including Cyberesan, Group-IB, Check Point, ASEC and Trend Micro, considered the encryption scheme almost invulnerable from a cryptographic point of view. The authors of the new report emphasize that the algorithm itself was not hacked. The weakness was its implementation.

The Gentlemen uses XChacha20 streaming and the X25519 ECDH keys exchange. For each file, a separate time pair of keys is created, so direct selection does not make sense. However, malware is written in Go, and the language runtime environment does not clear the cryptographic data from the gault stack and memory after the completion of operations. As a result, temporary private keys can be stored in the process memory all the time the cipherer is working.

Bedrock Safeguard claims that one process memory dump is enough to remove the keys to decrypt files. In the test, the team restored 35 of the 35 files with 100% accuracy, and searching for all keys took 0.6 seconds. Such a dump could be saved in EDR or XDR systems, the incident response group, in Windows Error Reporting, emergency dumps, a full RAM image or hibernation file.

The company also published signs of compromise. Among them are a note README-GENTLEEN.txt, the body’s tail with a GENTLEMEN marker, randomly digitized file extensions, deletion of shadow copies via vssadmin and wmic, adding exceptions to Windows Defender, deleting Prefetch files, stopping database services, backing up and protection, as well as changing wallpaper on gentlemen.bm.

The report links work with the earlier restoration of the WannaCry keys, which Adrien Guine described in 2017. According to Bedrock Safeguard, the new publication was the first open example of the extraction of temporary X25519-keys from memory against the ransomware family. The Canadian Cyber Security Center and RCMP NC3 were notified of the find. The company also introduced the open service Bedrock RansomGuard, which should automatically notice encryption and save process memory while the keys can still be removed. A similar approach – a public decryptor as a result of the analysis of weak crypto-realization – was previously used against the FunkSec ransomware.
 

DARKWEB16 layers

Well-known member
Member
Joined
Aug 5, 2026
Messages
161
Reaction score
0
The hackers beat them with the same code. Experts have found a way to save data without paying a ransom.
View attachment 141
The Gentlemen ransomware victims for the first time got a chance to return their files without paying for a ransom. Canadian company Bedrock Safeguard reported a public way of decrypting the data encrypted by this family, which is also known as hastalamaurete and by the first quarter of 2026 scored more than 320 confirmed victims.

According to Bedrock Safeguard, The Gentlemen now remains one of the most active RaaS groups. Previously, large companies, including Cyberesan, Group-IB, Check Point, ASEC and Trend Micro, considered the encryption scheme almost invulnerable from a cryptographic point of view. The authors of the new report emphasize that the algorithm itself was not hacked. The weakness was its implementation.

The Gentlemen uses XChacha20 streaming and the X25519 ECDH keys exchange. For each file, a separate time pair of keys is created, so direct selection does not make sense. However, malware is written in Go, and the language runtime environment does not clear the cryptographic data from the gault stack and memory after the completion of operations. As a result, temporary private keys can be stored in the process memory all the time the cipherer is working.

Bedrock Safeguard claims that one process memory dump is enough to remove the keys to decrypt files. In the test, the team restored 35 of the 35 files with 100% accuracy, and searching for all keys took 0.6 seconds. Such a dump could be saved in EDR or XDR systems, the incident response group, in Windows Error Reporting, emergency dumps, a full RAM image or hibernation file.

The company also published signs of compromise. Among them are a note README-GENTLEEN.txt, the body’s tail with a GENTLEMEN marker, randomly digitized file extensions, deletion of shadow copies via vssadmin and wmic, adding exceptions to Windows Defender, deleting Prefetch files, stopping database services, backing up and protection, as well as changing wallpaper on gentlemen.bm.

The report links work with the earlier restoration of the WannaCry keys, which Adrien Guine described in 2017. According to Bedrock Safeguard, the new publication was the first open example of the extraction of temporary X25519-keys from memory against the ransomware family. The Canadian Cyber Security Center and RCMP NC3 were notified of the find. The company also introduced the open service Bedrock RansomGuard, which should automatically notice encryption and save process memory while the keys can still be removed. A similar approach – a public decryptor as a result of the analysis of weak crypto-realization – was previously used against the FunkSec ransomware.
Telegram Join our Telegram channel! Welcome to our Telegram channel, blacks Join our Telegram channel, blacks room! Welcome to our Telegram channel, Blacks Room continues to grow! Welcome to our Telegram channel, Blacks Room continues to grow! 186 Welcome to our Telegram channel, Blacks Room! We continue to grow and have 186 members. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members and entries are welcome. Welcome to our Telegram channel, Blacks Room! We're growing, we have 186 members, and entry is free. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members and entry is free. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but you need to send messages. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we have strict moderators for messaging. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we've implemented strict measures for sending messages. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we've implemented strict measures for sending messages. 35 35,000 35,000 Telegrams Pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send messages. This Telegram feature is only for legitimate sellers. You can pay 35,000 Telegram stars and then send messages. This Telegram is only for legitimate sellers. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure shopping. You can pay 35,000 Telegram stars and then send a message. This Telegram app is only for legitimate sellers and secure shopping. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure transactions. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure transactions. Now Now he's a scammer. No more scams We are putting an end to these scams now. We are putting an end to scams now, Blacks Room is safe. We are putting an end to scams; shop safely at Blacks Room. We are putting an end to scams; Blacks Room allows you to shop safely. We are putting an end to scams; Blacks Room allows you to shop safely.

 

DARKWRB3858484

Well-known member
Member
Joined
Aug 5, 2026
Messages
358
Reaction score
42
The hackers beat them with the same code. Experts have found a way to save data without paying a ransom.
View attachment 141
The Gentlemen ransomware victims for the first time got a chance to return their files without paying for a ransom. Canadian company Bedrock Safeguard reported a public way of decrypting the data encrypted by this family, which is also known as hastalamaurete and by the first quarter of 2026 scored more than 320 confirmed victims.

According to Bedrock Safeguard, The Gentlemen now remains one of the most active RaaS groups. Previously, large companies, including Cyberesan, Group-IB, Check Point, ASEC and Trend Micro, considered the encryption scheme almost invulnerable from a cryptographic point of view. The authors of the new report emphasize that the algorithm itself was not hacked. The weakness was its implementation.

The Gentlemen uses XChacha20 streaming and the X25519 ECDH keys exchange. For each file, a separate time pair of keys is created, so direct selection does not make sense. However, malware is written in Go, and the language runtime environment does not clear the cryptographic data from the gault stack and memory after the completion of operations. As a result, temporary private keys can be stored in the process memory all the time the cipherer is working.

Bedrock Safeguard claims that one process memory dump is enough to remove the keys to decrypt files. In the test, the team restored 35 of the 35 files with 100% accuracy, and searching for all keys took 0.6 seconds. Such a dump could be saved in EDR or XDR systems, the incident response group, in Windows Error Reporting, emergency dumps, a full RAM image or hibernation file.

The company also published signs of compromise. Among them are a note README-GENTLEEN.txt, the body’s tail with a GENTLEMEN marker, randomly digitized file extensions, deletion of shadow copies via vssadmin and wmic, adding exceptions to Windows Defender, deleting Prefetch files, stopping database services, backing up and protection, as well as changing wallpaper on gentlemen.bm.

The report links work with the earlier restoration of the WannaCry keys, which Adrien Guine described in 2017. According to Bedrock Safeguard, the new publication was the first open example of the extraction of temporary X25519-keys from memory against the ransomware family. The Canadian Cyber Security Center and RCMP NC3 were notified of the find. The company also introduced the open service Bedrock RansomGuard, which should automatically notice encryption and save process memory while the keys can still be removed. A similar approach – a public decryptor as a result of the analysis of weak crypto-realization – was previously used against the FunkSec ransomware.
 
6,044Threads
80,020Messages
5,936Members
jack forLatest member
Top Bottom