logo

Inside GentleKiller: The EDR-Killer Powering The Gentlemen

ID: 0f91bb8b-6091-5f70-bc1b-b0923c8d2006

STIX ID: report--0f91bb8b-6091-5f70-bc1b-b0923c8d2006

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-06-20

Date Updated: 2026-06-21

Author: Pierluigi Paganini

...
...

The report details The Gentlemen ransomware-as-a-service operation and its centralized EDR-killer suite, GentleKiller, which uses Bring Your Own Vulnerable Driver (BYOVD) techniques across multiple variants to rapidly disable endpoint security before ransomware deployment; it also covers affiliated third-party EDR killers, a Rust-based credential stealer (OxideHarvest), victim selection practices from leaked internal data, and operator attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.