logo

Inside GentleKiller: The EDR-Killer Powering The Gentlemen

ID: 6a3e9fa7-2072-5b2c-b685-b751ceee4d58

STIX ID: report--6a3e9fa7-2072-5b2c-b685-b751ceee4d58

Feed Name: Security Affairs

Threat Score
82/100

Date Published: 2026-06-20

Date Updated: 2026-06-22

Author: Pierluigi Paganini

...
...

ESET’s investigation into The Gentlemen reveals that the ransomware group provides affiliates with a centralized EDR-killer suite (GentleKiller) comprising multiple BYOVD-based variants that impersonate legitimate drivers to disable hundreds of security processes, alongside third-party killers and a Rust-based credential stealer (OxideHarvest); the group targets victims selected via FortiGate misconfigurations, rapidly weaponizes public BYOVD PoCs, and the leak of internal data corroborated operator-managed distribution and attribution details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.