logo

Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs

ID: 25a617f4-ea49-5d4d-a338-3be7b8994332

STIX ID: report--25a617f4-ea49-5d4d-a338-3be7b8994332

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2026-06-30

Date Updated: 2026-07-16

...
...

This report analyzes a high-risk operational incident where the ransomware group “The Gentlemen” used a zero-day vulnerable kernel driver (ktapi.sys) in a BYOVD attack to gain kernel code execution, bypass SMEP/SMAP and PatchGuard protections, and terminate protected EDR processes; the analysis includes technical walkthroughs, IOCs (driver and payload hashes, device names, filenames, and signatures), and practical mitigations such as enabling VBS/core isolation, WDAC, and vulnerable-driver blocklists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.