Threats · 84 days ago
Gentlemen is packaging kernel-level EDR killing as a reusable RaaS feature, so the standard assumption that endpoint tools will still be there when encryption starts no longer holds. Once the attacker loads a signed but vulnerable driver, it can shut down security processes from inside the kernel, before normal protections can react.
ESET now ties GentleKiller to at least eight variants and more than 400 targeted processes across roughly 48 security products, including Microsoft Defender, CrowdStrike, Sophos, and ESET. That makes the pre-encryption blindfold more portable across affiliates and across incidents, not a one-off trick from a skilled crew.
6 sources covering this story
GentleKiller Framework Disables Victims' Security Software
ESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliates
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
ESET says Gentlemen RaaS gives affiliates a GentleKiller EDR-killer suite targeting 400 processes across 48 security tools.
Threat actor adds advanced 'EDR killer' tools to ransomware-as-a-service platform
Traditional EDR defense is under threat after a criminal group added a sophisticated capability to shut it down, warns ESET.
Gentlemen ransomware uses multiple EDR killers to disable defenses
The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks.
Killing me gently: Inside Gentlemen’s EDR killer framework
ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen
GentleKiller targets more than 400 security processes across 48 products - Help Net Security
Gentlemen EDR killers are built and maintained by the ransomware gang's operators and handed to affiliates to disable endpoint security.
Part of the PlainSec briefing for 2026-06-23