Hackers Create Domain Admin Account and Disable Security Tools Inside Windows Network
The Gentlemen ransomware group can turn a single infected Windows PC into full control of an entire company network. They create admin accounts, disable security tools, and use the network's own security system to spread the attack.
- Report priority
- High
- Victim
- Windows
What is known
- Attackers start with a foothold on one Windows PC.
- They use that access to create a new admin account with full control over the company's network.
- Then they turn off security software on every PC.
- Finally, they abuse the network's own security system to spread the ransomware to every other PC.
What to do
If your company uses Windows PCs connected to a shared network with admin controls, check if your network has a domain admin account, most businesses do. If your security team reports disabled tools or new admin accounts, contact your company's IT or security team immediately.
They must check for new admin accounts, disabled security software, and unusual network activity. Follow their instructions to restore security tools and remove any unauthorized accounts. If you're a security admin, review logs for signs of unauthorized access and disable any suspicious accounts.
Reported details
Attackers first break into a single Windows PC in a company. They use that access to create a new admin account with full control over the company's network. Then they turn off security software on every PC. Finally, they abuse the network's own security system to spread the ransomware to every other PC.
A newly documented ransomware intrusion attributed to The Gentlemen shows how attackers can convert a foothold in a Windows environment into domain-wide control by elevating accounts, turning off endpoint defenses, and abusing trusted Active Directory infrastructure to distribute ransomware.