Custom Go Backdoor Lets The Gentlemen Operators Execute Commands and Pivot With SOCKS Proxy

A newly discovered custom Go-based backdoor used by the ransomware group known as The Gentlemen is giving attackers powerful capabilities to execute remote commands, establish SOCKS proxy tunnels, and move deeper inside compromised enterprise networks before launching ransomware.

The malware, deployed shortly before encryption begins, highlights the group’s growing focus on stealth, reconnaissance, and long-term access.

Security researchers who have been tracking The Gentlemen since early 2026 found that the ransomware-as-a-service (RaaS) operation has significantly expanded its toolkit and attack methods.

The group has rapidly become one of the most active ransomware operators, targeting organizations across manufacturing, healthcare, finance, IT services, logistics, and critical infrastructure worldwide.

Unlike traditional ransomware campaigns that focus only on encrypting files, The Gentlemen spend considerable time gathering intelligence inside victim environments.

Their attacks commonly begin by exploiting internet-facing services such as VPN appliances and firewalls or by using stolen and weak credentials.

Researchers also believe the group frequently works with initial access brokers (IABs), allowing them to purchase existing access to corporate networks rather than compromise victims directly.

The Gentlemen background image (Source: securelist)
The Gentlemen background image (Source: securelist)

Gentlemen Backdoor SOCKS Pivot

One of the most notable discoveries is a custom Go implant that functions as a fully featured backdoor.

Investigators observed the malware being deployed approximately one day before the ransomware payload, indicating it plays a key role during the preparation stage of attacks.

After execution, the implant collects detailed information about the compromised machine, including the hostname, Windows domain, UUID, and local IP addresses.

Event clearing function (Source: securelist)
Event clearing function (Source: securelist)

It retrieves the system UUID using Windows Management Instrumentation (WMI) queries before packaging the information into JSON format and transmitting it to a remote command-and-control (C2) server over a persistent TCP connection established through the Yamux library.

Once communication is established, the backdoor waits for instructions from its operators. Depending on the command received, it can execute Windows commands through cmd.exe or create a SOCKS proxy tunnel.

The SOCKS proxy capability is especially valuable because it allows attackers to route network traffic through the infected machine, enabling them to reach internal systems that would otherwise remain inaccessible.

This lets operators expand reconnaissance, scan isolated network segments, and pivot throughout enterprise environments while remaining difficult to detect.

Researchers observed the attackers immediately issuing reconnaissance commands after the first connection, including identifying the current user, enumerating Domain Admin groups, listing available groups, and exploring file system contents.

These commands help attackers understand privilege levels and identify valuable systems before deploying ransomware.

Securelist said, The Gentlemen use an extensive collection of legitimate administration and offensive security tools during intrusions.

Utilities such as SharpADWS, NetScan, Advanced IP Scanner, and the Windows netsh utility are used to enumerate Active Directory environments, discover hosts, scan services, and capture network traffic.

Packet captures are later analyzed to uncover sensitive information such as credentials and unencrypted communications.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories