Gentlemen ransomware EDR-killer tooling
Malware Activity
Summary
Hide ▲
Show ▼
Gentlemen ransomware-as-a-service (RaaS) is actively maintaining a suite of EDR killers led by GentleKiller to disable endpoint defenses before encryption. ESET says the framework has at least eight variants, impersonates legitimate security products such as Kaspersky, Valorant, Javelin, and WatchDog, and uses BYOVD with vulnerable drivers to obtain kernel-level privileges and target more than 400 processes across roughly 48 security vendors and products. The broader tooling set also includes HexKiller, ThrottleBlood, HavocKiller, and OxideHarvest. ESET also reported that Gentlemen can operationalize newly disclosed BYOVD PoC exploits within days and appears to favor victims with FortiGate endpoint configurations.
Related Happenings
SprySOCKS Windows backdoor activity against government organizations
Malware Activity
H score23
First: 16.06.2026 12:00
Last: 16.06.2026 12:00
Sources 1
About this happening:
SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
SprySOCKS Windows backdoor activity against government organizations
Malware ActivityAbout this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware Activity
H score33
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
About this happening:
TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware ActivityAbout this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
AI-built ransomware toolkit with AD discovery and EDR evasion
Malware Activity
H score36
First: 02.06.2026 23:01
Last: 02.06.2026 23:01
Sources 1
About this happening:
A customer-detected AI-built ransomware toolkit is automating Active Directory discovery and EDR evasion, increasing the chance that payloads slip past security contro...
AI-built ransomware toolkit with AD discovery and EDR evasion
Malware ActivityAbout this happening: A customer-detected AI-built ransomware toolkit is automating Active Directory discovery and EDR evasion, increasing the chance that payloads slip past security contro...
Vidar infostealer market rise and distribution expansion
Malware Activity
H score30
First: 28.04.2026 22:07
Last: 28.04.2026 22:07
Sources 1
About this happening:
Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
Vidar infostealer market rise and distribution expansion
Malware ActivityAbout this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up
Threat Actor Meta
H score57
First: 21.04.2026 17:00
Last: 21.04.2026 17:00
Sources 1
How related:
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor.
About this happening:
The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...
The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up
Threat Actor MetaHow related: The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor.
About this happening: The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...
Timeline
-
19.06.2026 01:31 4 articles · 27d ago
Gentlemen ransomware maintains EDR killers to evade endpoint detection
Initial DisclosureESET reports that Gentlemen ransomware-as-a-service is actively maintaining a suite of endpoint detection and response killers led by GentleKiller, a tool with at least eight variants that impersonate legitimate security products such as Kaspersky, Valorant, Javelin, and WatchDog. The tooling uses vulnerable drivers and BYOVD to obtain kernel-level privileges, disable defenses, and target more than 400 processes across roughly 48 security vendors and products, while the broader collection also includes HexKiller, ThrottleBlood, HavocKiller, and OxideHarvest; ESET also says Gentlemen appears to select victims based on FortiGate endpoint configuration.
Show sources
- Gentlemen ransomware uses multiple EDR killers to disable defenses — www.bleepingcomputer.com — 19.06.2026 01:31
- Gentlemen ransomware uses multiple EDR killers to disable defenses — www.bleepingcomputer.com — 19.06.2026 01:31
- The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes — thehackernews.com — 19.06.2026 21:33
- GentleKiller Framework Disables Victims' Security Software — www.infosecurity-magazine.com — 22.06.2026 18:00