Threats & Adversaries · Ransomware
Ransomware Affiliates Rent Kernel-Grade EDR Killing Gentlemen is packaging kernel-level EDR killing as a reusable RaaS feature, so the standard assumption that endpoint tools will still be there when encryption starts no longer holds. Once the attacker loads a signed but vulnerable driver, it can shut down security processes from inside the kernel, before normal protections can react.
ESET now ties GentleKiller to at least eight variants and more than 400 targeted processes across roughly 48 security products, including Microsoft Defender, CrowdStrike, Sophos, and ESET. That makes the pre-encryption blindfold more portable across affiliates and across incidents, not a one-off trick from a skilled crew.
6 sources · Jun 22
Timeline Sources Jun 22 Infosecurity Magazine
GentleKiller Framework Disables Victims' Security Software
ESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliates
original Jun 20 The Hacker News
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
ESET says Gentlemen RaaS gives affiliates a GentleKiller EDR-killer suite targeting 400 processes across 48 security tools.
original Jun 19 CSO Online
Threat actor adds advanced 'EDR killer' tools to ransomware-as-a-service platform
Traditional EDR defense is under threat after a criminal group added a sophisticated capability to shut it down, warns ESET.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-06-20
Every edition of this story: Ransomware Affiliates Rent Kernel-Grade EDR Killing
More from today
Threats & Adversaries · Ransomware
Ransomware Affiliates Rent Kernel-Grade EDR Killing Gentlemen is packaging kernel-level EDR killing as a reusable RaaS feature, so the standard assumption that endpoint tools will still be there when encryption starts no longer holds. Once the attacker loads a signed but vulnerable driver, it can shut down security processes from inside the kernel, before normal protections can react.
ESET now ties GentleKiller to at least eight variants and more than 400 targeted processes across roughly 48 security products, including Microsoft Defender, CrowdStrike, Sophos, and ESET. That makes the pre-encryption blindfold more portable across affiliates and across incidents, not a one-off trick from a skilled crew.
6 sources · Jun 22
Timeline Sources Jun 22 Infosecurity Magazine
GentleKiller Framework Disables Victims' Security Software
ESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliates
original Jun 20 The Hacker News
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
ESET says Gentlemen RaaS gives affiliates a GentleKiller EDR-killer suite targeting 400 processes across 48 security tools.
original Jun 19 CSO Online
Threat actor adds advanced 'EDR killer' tools to ransomware-as-a-service platform
Traditional EDR defense is under threat after a criminal group added a sophisticated capability to shut it down, warns ESET.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-06-20
Every edition of this story: Ransomware Affiliates Rent Kernel-Grade EDR Killing
More from today