The ransomware operation tracked as The Gentlemen has claimed 478 victims and, more consequentially, can now spread on its own. Microsoft, which tracks the group as Storm-2697, reports that a self spread argument turns the malware from a single host encryptor into a self propagating worm. Threat intelligence firm PRODAFT, which calls the operation Phantom Mantis, documented a cross platform payload written in Go that runs on Windows, Linux and ESXi and encrypts with X25519 key exchange paired with XChaCha20.

The development that should reset defensive assumptions is the return of wormable ransomware. For several years the dominant model was hands on keyboard intrusion, where operators moved laterally by hand and defenders could hope to interrupt the chain. A worm capability removes that human pause. The Gentlemen reaches in through internet facing VPN appliances and firewalls, with a documented focus on Cisco and Fortinet products, then can propagate without an operator driving each hop. Roughly 13 percent of victims are US based, with concentrations in Thailand, the United Kingdom, Brazil, Germany and India, and the group accounted for about 10 percent of ransomware activity in April.

The original insight is that self propagation collapses the time defenders have to respond and rewards exactly the controls many organizations defer. The same edge appliance exposure that drives this week’s critical patches is the worm’s entry point, and the group leans heavily on AI for development and post exploitation, part of a broader move toward industrialized threat campaigns scaling through automation. The practical guidance for security teams: stop planning for single host containment and assume lateral self spread. That means network segmentation that actually blocks east west movement, rapid patching of perimeter devices, and identity hardening so a single compromised credential cannot become a building wide encryption event.

Source: The Hacker News.