logo

GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes

ID: ee608a9e-1f62-50ff-95c9-70ebd3a02373

STIX ID: report--ee608a9e-1f62-50ff-95c9-70ebd3a02373

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-21

Date Updated: 2026-06-21

Author: Guru Baran

...
...

ESET research details the Gentlemen RaaS operation and its modular EDR-killing suite, GentleKiller, which leverages BYOVD (legitimately signed but vulnerable kernel drivers) to repeatedly terminate over 400 security-related processes across 48 products before deploying ransomware; the report enumerates eight GentleKiller variants, three integrated third-party EDR killers, a Rust-based credential stealer (OxideHarvest), evidence of rapid incorporation of public PoCs, an internal operator data leak, targeted victimology, and recommended mitigations such as driver allowlisting and monitoring for anomalous driver loads and process-termination patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.