Minacce · 99 giorni fa
La rottura non è nel singolo driver, ma nel fatto che il kill dell'EDR diventa una capacità gestita e riusabile dagli affiliati. Se il driver vulnerabile viene caricato, la difesa endpoint può essere spenta dal kernel prima che la cifratura inizi, e il software di protezione smette di essere il presidio su cui contare.
ESET dice che GentleKiller è arrivato ad almeno otto varianti e a più di 400 processi bersaglio su circa 48 prodotti di sicurezza, tra cui Microsoft Defender, CrowdStrike, Sophos ed ESET. Il framework impersona prodotti legittimi e abusa di driver firmati ma vulnerabili, così il blocco avviene dall'interno del sistema operativo, sotto la visibilità delle difese in user mode.
Il punto di rischio è che questa tecnica non resta più un trucco da attori d'élite: diventa una funzione standard della supply chain criminale di un RaaS. Per gli ambienti che dipendono da EDR o AV con forte componente in user mode, il presupposto di rilevare o contenere prima dell'encryption è molto più fragile.
6 fonti che coprono questa storia
GentleKiller Framework Disables Victims' Security Software
ESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliates
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
ESET says Gentlemen RaaS gives affiliates a GentleKiller EDR-killer suite targeting 400 processes across 48 security tools.
Threat actor adds advanced 'EDR killer' tools to ransomware-as-a-service platform
Traditional EDR defense is under threat after a criminal group added a sophisticated capability to shut it down, warns ESET.
Gentlemen ransomware uses multiple EDR killers to disable defenses
The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks.
Killing me gently: Inside Gentlemen’s EDR killer framework
ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen
GentleKiller targets more than 400 security processes across 48 products - Help Net Security
Gentlemen EDR killers are built and maintained by the ransomware gang's operators and handed to affiliates to disable endpoint security.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-23