Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gentlemen ransomware EDR-killer tooling

Malware Activity
First reported
Last updated
Happening score
H score 35
3 unique sources, 3 articles

Summary

Hide ▲

Gentlemen ransomware-as-a-service (RaaS) is actively maintaining a suite of EDR killers led by GentleKiller to disable endpoint defenses before encryption. ESET says the framework has at least eight variants, impersonates legitimate security products such as Kaspersky, Valorant, Javelin, and WatchDog, and uses BYOVD with vulnerable drivers to obtain kernel-level privileges and target more than 400 processes across roughly 48 security vendors and products. The broader tooling set also includes HexKiller, ThrottleBlood, HavocKiller, and OxideHarvest. ESET also reported that Gentlemen can operationalize newly disclosed BYOVD PoC exploits within days and appears to favor victims with FortiGate endpoint configurations.

Related Happenings

SprySOCKS Windows backdoor activity against government organizations

Malware Activity
H score23 First: 16.06.2026 12:00 Last: 16.06.2026 12:00 Sources 1

About this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...

Atlas RAT and related loaders deployed for remote access and credential theft

Malware Activity
H score33 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

About this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...

AI-built ransomware toolkit with AD discovery and EDR evasion

Malware Activity
H score36 First: 02.06.2026 23:01 Last: 02.06.2026 23:01 Sources 1

About this happening: A customer-detected AI-built ransomware toolkit is automating Active Directory discovery and EDR evasion, increasing the chance that payloads slip past security contro...

Vidar infostealer market rise and distribution expansion

Malware Activity
H score30 First: 28.04.2026 22:07 Last: 28.04.2026 22:07 Sources 1

About this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...

The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up

Threat Actor Meta
H score57 First: 21.04.2026 17:00 Last: 21.04.2026 17:00 Sources 1

How related: The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor.

About this happening: The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...

Timeline

  1. 19.06.2026 01:31 4 articles · 27d ago

    Gentlemen ransomware maintains EDR killers to evade endpoint detection

    Initial Disclosure

    ESET reports that Gentlemen ransomware-as-a-service is actively maintaining a suite of endpoint detection and response killers led by GentleKiller, a tool with at least eight variants that impersonate legitimate security products such as Kaspersky, Valorant, Javelin, and WatchDog. The tooling uses vulnerable drivers and BYOVD to obtain kernel-level privileges, disable defenses, and target more than 400 processes across roughly 48 security vendors and products, while the broader collection also includes HexKiller, ThrottleBlood, HavocKiller, and OxideHarvest; ESET also says Gentlemen appears to select victims based on FortiGate endpoint configuration.

    Show sources