logo

The Gentlemen Ransomware With Custom EDR/AV Killers Scaling Faster to Attack Industries Worldwide

ID: 19ec14ff-af8b-561c-a002-67873c0ca5a6

STIX ID: report--19ec14ff-af8b-561c-a002-67873c0ca5a6

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-07-07

Date Updated: 2026-07-07

Author: Guru Baran

...
...

The Gentlemen is a rapidly escalating, human-operated Ransomware-as-a-Service (RaaS) that surfaced in 2025 and by 2026 has claimed hundreds of victims globally; it uses a modular evasion suite (GentleKiller plus HexKiller/ThrottleBlood/HavocKiller) which abuses vulnerable signed kernel drivers (BYOVD) to terminate EDR/AV, a Go-based worm-like encryptor using Curve25519/XChaCha20, and a large affiliate program—an internal backend leak (‘Rocket’) exposed operator identities, 1,500+ victims, ransom negotiations and the full toolchain, and the report supplies IoCs, CVEs exploited (notably Fortinet and other public-facing flaws), MITRE ATT&CK mappings, and prioritized defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.