Gentlemen is packaging kernel-level EDR killing as a reusable RaaS feature, so the standard assumption that endpoint tools will still be there when encryption starts no longer holds. Once the attacker loads a signed but vulnerable driver, it can shut down security processes from inside the kernel, before normal protections can react.
ESET now ties GentleKiller to at least eight variants and more than 400 targeted processes across roughly 48 security products, including Microsoft Defender, CrowdStrike, Sophos, and ESET. That makes the pre-encryption blindfold more portable across affiliates and across incidents, not a one-off trick from a skilled crew.