#Gentlekiller
Inside GentleKiller: The EDR-Killer Powering The Gentlemen
Inside GentleKiller: The EDR-Killer Powering The Gentlemen
The Gentlemen equips affiliates with a centralized EDR-killer suite, rapidly weaponizing BYOVD exploits to disable security tools before ransomware attacks.
securityaffairs.com
June 20, 2026 at 4:11 PM
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes thehackernews.com/2026/06/the-...
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
ESET says Gentlemen RaaS gives affiliates a GentleKiller EDR-killer suite targeting 400 processes across 48 security tools.
thehackernews.com
June 21, 2026 at 8:33 AM
#GentleKiller EDR‑killing tool lets the #Gentlemen group bypass defenses pre-ransomware attacks, hinting at heightened cross-border cyber threats amid global #War and #Security tensions. # https://securityaffairs.com/193941/uncategorized/inside-gentlekiller-the-edr-killer-powering-the-gentlemen.html
Inside GentleKiller: The EDR-Killer Powering The Gentlemen
securityaffairs.com
June 21, 2026 at 3:38 PM
The Hacker News - Article
"The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes"...

thehackernews.com/2026/06/the-...

==========================
#librecanada #linux #opensource
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
ESET says Gentlemen RaaS gives affiliates a GentleKiller EDR-killer suite targeting 400 processes across 48 security tools.
thehackernews.com
June 25, 2026 at 2:52 PM
GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes
GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes
A highly sophisticated EDR-killing framework, dubbed GentleKiller, was used by the Gentlemen ransomware-as-a-service (RaaS) gang to systematically disable endpoint security tools before deploying its ransomware payload. The findings by ESET, published on June 17, 2026, detail how Gentlemen, one of the most active ransomware gangs in Q1 2026, provides affiliates with a centralized, operator-maintained suite of EDR killers, a model rare even among top-tier ransomware operations. GentleKiller is an in-house EDR-killing framework with at least eight distinct variants, each impersonating a different legitimate security product and abusing a unique vulnerable or malicious kernel-level driver. The technique used is Bring Your Own Vulnerable Driver (BYOVD) , loading a legitimately signed but exploitable driver to terminate security processes at the kernel level, bypassing user-mode protections. In total, GentleKiller targets more than 400 processes mapped to 48 security products, including industry leaders such as Microsoft Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky, and McAfee/Trellix. The framework operates on a loop, periodically scanning and terminating targeted processes every two seconds, as evidenced by the output shown below. Window spawned by GentleKiller [ESET Research] The eight GentleKiller variants abuse drivers from Kaspersky ( eb.sys ), FACEIT Anti-Cheat ( nseckrnl.sys ), Valorant ( GameDriverX64.sys ), Javelin/Safetica ( stpm_old.sys / stpm_new.sys ), Zemana WatchDog ( dmx.sys ), Qihoo 360 ( 360netmon_wfp.sys ), IObit ( IMFForceDelete ), and the PoisonX rootkit. A defining capability of Gentlemen is its ability to operationalize newly published BYOVD proof-of-concept (PoC) exploits within days of public release. Tools such as UnknownKiller and PoisonKiller were incorporated into GentleKiller’s arsenal within days of their public GitHub disclosure, demonstrating a well-resourced and agile development pipeline, according to ESET research . This rapid adoption distinguishes Gentlemen from most other RaaS operators, who typically wait weeks or months before adapting publicly released exploits into production-ready tooling. Third-Party EDR Killers Integrated Into the Suite Beyond GentleKiller, Gentlemen also integrates three externally sourced EDR killers into its affiliate-facing suite: HexKiller — Previously attributed exclusively to the Warlock gang; abuses a Baidu Antivirus BdApi driver ( googleApiUtil64.sys ) ThrottleBlood — Previously observed in MedusaLocker and DragonForce intrusions; abuses a TechPowerUp LLC driver ( ThrottleBlood.sys ) HavocKiller — First publicly disclosed by Huntress on March 19, 2026, but observed in real-world intrusions as early as January 23, 2026; abuses a Huawei Audio driver ( havoc.sys ) All three tools are standardized through a shared defense-evasion layer that applies Enigma or Themida binary protectors, impersonates security vendors with fabricated version information, copied digital signatures, and matching icons. Gentlemen applies its evasion strategy at the compiled binary level, allowing it to protect even EDR killers for which it does not own the source code. This creates significant attribution challenges, as tools from different ransomware groups appear near-identical once processed through Gentlemen’s standardization pipeline. The gang also uses OxideHarvest, a Rust-written credential stealer maintained by a Gentlemen affiliate, which harvests credentials from Chromium-based and Gecko-based browsers across compromised hosts. Gentlemen emerged in late 2025 as a RaaS operation founded by hastalamuerte , a former Qilin affiliate , and rapidly became one of the five most active ransomware gangs in Q1 2026. Unlike most major ransomware groups that focus heavily on US-based targets, Gentlemen deliberately targets victims in Southeast Asia, South America, and Western Europe, selecting targets primarily based on FortiGate misconfigurations rather than geographic criteria. The gang was further exposed by an internal data leak in May 2026, which confirmed that its operators actively develop, maintain, and distribute GentleKiller and the broader EDR-killer suite to vetted affiliates. Gentlemen offers affiliates an unusually generous 90% revenue share, lowering the barrier to entry and accelerating its affiliate recruitment. Security teams should prioritize driver allowlisting and enforce Microsoft’s Vulnerable Driver Blocklist to prevent BYOVD-style attacks. Defenders should also monitor for the GentlemenCollection staging directory and anomalous kernel driver loading events. Correlating process-termination patterns, especially targeting security software with driver installation events, remains the most reliable behavioral detection signal against GentleKiller and its variants. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates. The post GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes appeared first on Cyber Security News .
cybersecuritynews.com
June 21, 2026 at 7:11 AM
GentleKiller is Gentlemen’s most prevalent EDR killer. We found eight distinct variants of the tool, each impersonating a different legitimate product. Across all builds, GentleKiller targets more than 400 processes, which we mapped with the help of AI to 48 products. 4/6
June 18, 2026 at 9:40 AM
⚠️ Gentlemen RaaS standardizes EDR killing

#GentleKiller targets over 400 processes across 48 security products while affiliates use BYOVD tools like HexKiller and HavocKiller.

🔗 read more: gbhackers.com/gentlemen-ra...

#ransomNews #cybersecurity
June 23, 2026 at 9:37 AM
The report also details #ESETresearch findings from the Gentlemen leak. We found the gang uses a shared defense-evasion layer across its EDR killer suite – spanning in-house GentleKiller, third-party, and leaked tools – and can operationalize new BYOVD PoCs within days. 3/5
July 28, 2026 at 7:47 AM
We hypothesized that GentleKiller was an internal tool in February 2026, and the recent leak of Gentlemen data confirmed our suspicions. The leaked data also allowed us to link one of Gentlemen’s affiliates to a credential stealer we named OxideHarvest. 5/6
June 18, 2026 at 9:40 AM
GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes cybersecuritynews.com/gentlekiller...
GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes
A highly sophisticated EDR-killing framework, dubbed GentleKiller, was used by the Gentlemen ransomware-as-a-service (RaaS) gang to systematically disable endpoint security tools before deploying its ...
cybersecuritynews.com
June 22, 2026 at 11:53 AM
Inside GentleKiller: A Technical Deep-Dive into the Gentlemen RaaS EDR-Killer Supply Chain

A technical breakdown of GentleKiller, the BYOVD-based EDR killer Gentlemen ransomware builds and distributes to…

https://thecybersecguru.com/news/gentlekiller-gentlemen-ransomware-edr-killer-byovd/
June 21, 2026 at 1:16 PM
July 5, 2026 at 1:58 PM
Gentlemen operators develop and maintain a suite of EDR killers, combining an in-house tool, GentleKiller, with externally sourced tooling (HexKiller, ThrottleBlood, and HavocKiller). The gang applies a standardized set of defense evasion techniques across its portfolio. 3/6
June 18, 2026 at 9:40 AM
📰 Manfaatkan Taktik BYOVD, Geng Ransomware "Gentlemen" Siapkan Pasukan Penghancur EDR

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/19/ransomware-gentlemen-gunakan-edr-killer-gentlekiller/

#byo
vd#byovdi#edrKiller #eseti#fortibleedi#fortigatel#gentlekillerl#gentlemeni#hexkillera href="/hashtag/kea" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#kea
June 19, 2026 at 8:07 AM
Gentlemen RaaS is arming affiliates with GentleKiller, an EDR-killing suite targeting 400 security processes, plus tools like HexKiller and OxideHarvest in fast-moving BYOVD attacks. #Gentlemen #GentleKiller #BYOVD
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The Gentlemen ransomware group is distributing a standardized suite of EDR-killing tools to affiliates, centered on GentleKiller and supported by leaked or third-party utilities such as HexKiller, ThrottleBlood, and HavocKiller. ESET also found that the group rapidly weaponizes new BYOVD PoCs and that a Rust-based credential stealer, OxideHarvest, has been used...
www.hendryadrian.com
June 19, 2026 at 8:15 PM
-Telegram's cybercrime crackdown barely makes a dent
-More AI tools in the cyber underground as crimz worry for their own jobs
-BreachForums evolution
-New AryStinger botnet
-USB worm+clipper combo spotted in the wild
-New GentleKiller EDR killer
-New OXLOADERGentleKiller
-New Prinz Eugen ransomware
June 19, 2026 at 9:02 AM
Police and international partners disrupted an Evil Corp malware network, Operation Endgame removed SocGholish servers and cleaned 14,971 WordPress sites, and The Gentlemen ransomware used GentleKiller to target 400 security processes. #Russia
Cybersecurity News | Daily Recap [20 Jun 2026]
Daily Recap, Police and international partners disrupted a malware network tied to Russia’s Evil Corp, while Operation Endgame took down SocGholish servers and cleaned 14,971 compromised WordPress sites. Security teams also warned that The Gentlemen ransomware uses the GentleKiller EDR-killer framework to target 400 security processes before encryption. #EvilCorp #OperationEndgame #SocGholish #WordPress #TheGentlemen #GentleKiller #Texas #FortiBleed #Fortinet #Klue #Icarus #GravitySMTP #usbliter8 #SecureROM #AppleA12 #AppleA13 #AutoJack #Beats #Continuum
www.hendryadrian.com
June 21, 2026 at 11:45 PM
Thanks for sharing. GentleKiller is a serious threat—it’s crucial to keep EDR/AV updated and enforce strong endpoint policies to prevent such disabling tactics. Stay vigilant! #CyberSecurity
June 22, 2026 at 3:46 PM
Gentlemen ransomware is using multiple EDR killers, including GentleKiller, to disable defenses early in attacks. ESET also links the group to FortiGate targeting and SystemBC proxy abuse. #FortiGate #Romania #Ransomware
Gentlemen ransomware uses multiple EDR killers to disable defenses
The Gentlemen ransomware-as-a-service operation is actively maintaining a set of EDR killers, led by the GentleKiller tool, to help affiliates evade security defenses during attacks. ESET says the group also uses external tools like HexKiller, ThrottleBlood, and HavocKiller, and has tied the activity to FortiGate-based targeting, the Romanian energy provider Oltenia, and a SystemBC proxy botnet. #Gentlemen #GentleKiller #HexKiller #ThrottleBlood #HavocKiller #FortiGate #Oltenia #SystemBC
www.hendryadrian.com
June 19, 2026 at 1:45 AM
The Gentlemen's Go locker spreads itself 21 ways and kills 400+ security tools before it encrypts. https://intel.threadlinqs.com/threat/TL-2026-1220 #ThreatIntel #GentleKiller #Gentlemen #Storm2697
July 11, 2026 at 11:15 AM
New 'The Gentlemen' ransomware is aggressively disabling security tools. ⚔️ It uses a multi-pronged 'GentleKiller' framework to terminate EDR/AV products before encryption. Ensure your tamper protection is on! #Ransomware #CyberSecurity #EDR

🌐 cyber[.]netsecops[.]io
New
A new ransomware group,
cyber.netsecops.io
June 20, 2026 at 9:36 PM
🔥 「Gentlemen」ランサムウェアがヤバい——

CrowdStrikeやMicrosoftを含む48社以上のEDRを無力化する「GentleKiller」。BYOVDで400プロセスを即殺するRaaSが高度化している。

詳しくはこちら👇
https://www.ebisuda.net/tech/2026/06/19/gentlemenraas8edrgentlekillerbyovd48400-gentlemen-ransomware-uses-multiple-edr-k/

#TechNews #Windows
June 19, 2026 at 5:53 AM