The Gentlemen Ransomware With Custom EDR/AV Killers Scaling Faster to Attack Industries Worldwide
ID: 19ec14ff-af8b-561c-a002-67873c0ca5a6
STIX ID: report--19ec14ff-af8b-561c-a002-67873c0ca5a6
Feed Name: cybersecurityNews.com
The Gentlemen is a rapidly escalating, human-operated Ransomware-as-a-Service (RaaS) that surfaced in 2025 and by 2026 has claimed hundreds of victims globally; it uses a modular evasion suite (GentleKiller plus HexKiller/ThrottleBlood/HavocKiller) which abuses vulnerable signed kernel drivers (BYOVD) to terminate EDR/AV, a Go-based worm-like encryptor using Curve25519/XChaCha20, and a large affiliate program—an internal backend leak (‘Rocket’) exposed operator identities, 1,500+ victims, ransom negotiations and the full toolchain, and the report supplies IoCs, CVEs exploited (notably Fortinet and other public-facing flaws), MITRE ATT&CK mappings, and prioritized defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
