Inside GentleKiller: The EDR-Killer Powering The Gentlemen
ID: 6a3e9fa7-2072-5b2c-b685-b751ceee4d58
STIX ID: report--6a3e9fa7-2072-5b2c-b685-b751ceee4d58
Feed Name: Security Affairs
ESET’s investigation into The Gentlemen reveals that the ransomware group provides affiliates with a centralized EDR-killer suite (GentleKiller) comprising multiple BYOVD-based variants that impersonate legitimate drivers to disable hundreds of security processes, alongside third-party killers and a Rust-based credential stealer (OxideHarvest); the group targets victims selected via FortiGate misconfigurations, rapidly weaponizes public BYOVD PoCs, and the leak of internal data corroborated operator-managed distribution and attribution details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
