Security1 distinct publisher2 min readPublished
Sophos CTU reviewed 15 intrusions by GOLD SHERWOOD affiliates and found the same route each time: a working credential on a Fortinet SSL VPN with no MFA, then RDP into domain controllers within hours.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Fifteen incidents is enough to call it a playbook [3]. Each step in it is unremarkable. Affiliates authenticate to a remote access service with credentials that work, then reuse the same domain credentials over RDP to reach file servers and domain controllers [4][5]. Tooling lands in C:\PerfLogs, the Windows performance-log directory, which CTU notes is rarely scrutinized by administrators or security controls [6]. Nothing after the front door requires an exploit.
That is what makes the 24-hour figure a control question [1]. If encryption can follow the first observed post-compromise activity by a day, the controls that decide the outcome are the ones sitting in front of the credential. In the February case, the actor opened multiple VPN sessions from different foreign IP addresses inside the first hour, which CTU reads as access validation and redundancy [7]. Sophos names the absence of MFA as the condition that allowed the initial login at all [8].
The sources pull apart on the access vector. Group-IB reported in March that affiliates hunted internet-exposed FortiGate management interfaces vulnerable to CVE-2024-55591 [9], and leaked Rocket chat logs from May showed the group testing stolen credentials against a range of VPN services [10]. CTU found artifacts in several intrusions consistent with exploited Fortinet endpoints, but said the available telemetry could not confirm it [11]. Patching the firewall is worth doing, but it would not have stopped the February intrusion CTU documented, which needed no firewall bug.
The volume arithmetic explains the recruiting. Monthly postings stayed under 20 through the end of 2025, then averaged over 75 at the start of 2026 [14], and the site held 683 names by the end of July 2026, 169 of them added in July [16][17]. Subtract a generous 80 for the four months of 2025 and at least 603 names land in the first seven months of 2026, roughly 86 a month [18]. July alone is about a quarter of everything the site has ever published [19]. CTU attributes the rise to a growing affiliate pool [15], which tracks with the 90/10 ransom split advertised on the RAMP forum in September 2025 [20]. A 90 percent share rewards persistence over skill.
Sector spread is wide, and CTU takes that as evidence the affiliates pick victims on available access rather than industry [21]. Sophos also logged the first attempted deployment against one of its own customers as the 2026 surge began [22]. The qualifying condition for being next is a remote access service where a password is sufficient [8].
Ranked by verification strength, evidence, and original report placement.
Sophos Counter Threat Unit researchers identified a consistent post-exploitation playbook used in The Gentlemen ransomware-as-a-service scheme, operated by a group CTU tracks as GOLD SHERWOOD; rapid privilege escalation, adaptive tool usage and aggressive defense evasion enable ransomware deployment soon after initial access, sometimes within 24 hours of the first identified post-compromise activity.
Sophos recommends that organizations prioritize hardening remote access services, enforcing multi-factor authentication, monitoring administrative activity, and detecting anomalous use of data exfiltration tools and staging directories.
CTU analysis covered 15 separate incidents involving The Gentlemen ransomware network intrusions.
In a February incident, a threat actor obtained initial access by using compromised user credentials to authenticate to a Fortinet SSL VPN service; the connection originated from an external IP address geolocated to the Netherlands and resulted in assignment of an internal VPN address.
In the February incident the attacker moved laterally over RDP, authenticating in rapid succession to multiple internal systems including a file server and domain controllers using valid domain credentials, and maintained access through repeated VPN logins.
In multiple incidents the attackers staged tools in the C:\PerfLogs directory, a legitimate Windows system directory for performance monitoring logs that is not commonly scrutinized by security controls or administrators; staged files included data exfiltration tools.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
security
Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures1 distinct publisher
security
Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain1 distinct publisher
security
ClickFix operators install the signed Deno runtime to run their remote JavaScript1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Concrete first-hand detail, one set of eyes
The specifics are unusually hard for threat intelligence: an entry address geolocated to the Netherlands, RDP hops named down to the file server and domain controllers, binaries parked in a performance-log directory, a tasklist-and-findstr command for locating LSASS. All of it comes from Sophos's own response telemetry across fifteen intrusions. What none of it comes from is a second observer. Group-IB's FortiGate finding and the leaked chat logs are relayed rather than shown, and Sophos itself declines to confirm the Fortinet exploitation route it half-sees in the artifacts — a candour that raises trust in the write-up while lowering certainty about the entry vector.
Scaled, accelerating, self-reported
Whatever else is uncertain, this is an operation at volume: 683 names by the end of July 2026, 169 in that month alone, and the top spot among leak sites for the month. The growth curve is the striking part — a step from under twenty postings a month in late 2025 to something near ninety, meaning almost the entire history of this leak site happened in 2026. Two caveats keep this short of the top band. The victim tally originates on the criminals' own publicity page, where inflation costs nothing, and the first attempt Sophos saw against its own customers is a single data point offered without outcome.
Careful prose, urgent framing
Sophos hedges more than the story around it does. 'Sometimes within 24 hours' is a ceiling on some incidents; retold, it becomes the standing speed of the group. The clean narrative arc from a Netherlands login to domain controllers belongs to one February intrusion, not to all fifteen, and the affiliate-growth reading is inference from posting counts dressed as a finding. Pulling the other way: the post volunteers that it cannot confirm Fortinet exploitation, and the victim numbers are specific enough to be checked by anyone who watches leak sites. Mild overstatement, mostly in emphasis rather than in fact.
The investigator sells the remedy
Every mitigation in the closing advice — MFA, remote-access hardening, admin activity monitoring, detection of EDR killers and staging directories — is a line item Sophos sells. And the note that its analysts caught the first attempted deployment against a Sophos customer works as a visibility credential as much as a timeline marker. This is not a reason to doubt the artifacts; investigators with commercial skin in the game still see real intrusions. It is a reason to want the same fifteen incidents described by someone who does not have a product in the category.
Trust the artifacts, not the calendar
Two things hold this down. First, single authorship: there is no second telemetry set, and the outside work cited is summarised rather than shown. Second, the dating is loose — February, March and May appear without years in a piece published in September 2026, so the reader places the flagship intrusion by inference. The technical particulars are the sort a responder does not invent, and the victim counts are falsifiable by anyone tracking leak sites, which is why this sits above the midpoint rather than below it.