logo

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

ID: 8e628eab-b069-5c19-801c-feada5902832

STIX ID: report--8e628eab-b069-5c19-801c-feada5902832

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

...
...

The report describes The Gentlemen RaaS and its GentleKiller EDR-evasion framework — a multi-stage toolkit distributed to affiliates that targets over 400 security-related processes, abuses signed drivers (BYOVD), removes persistence and shadow copies, and enables widespread ransomware deployment (linked to ~478 victims); it recommends layered defenses such as network-based detection, immutable remote logging, tamper protection, privileged access controls, and deception.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.