Gentlemen Ransomware Uses Multiple EDR Killers to Disable Defenses
ID: ae6ef4bf-b813-5786-b9eb-a79527f16fe1
STIX ID: report--ae6ef4bf-b813-5786-b9eb-a79527f16fe1
Feed Name: CosmicBytez Labs
Threat Score
**Gentlemen** RaaS actively develops and fields multiple EDR-killer tools (e.g., BYOVD, API-based process termination, service disruption, token impersonation) to blind endpoint defenses prior to ransomware deployment, has claimed roughly 478 victims by mid-2026, and leverages SystemBC for relay infrastructure; the report advises multi-layer detection, tamper protection, vulnerable driver monitoring, and privileged access hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
