logo

Gentlemen ransomware uses multiple EDR killers to disable defenses

ID: c78afddf-31e5-5ef2-bb56-9be5c5944fcb

STIX ID: report--c78afddf-31e5-5ef2-bb56-9be5c5944fcb

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Bill Toulas

...
...

Gentlemen ransomware-as-a-service (RaaS) actively uses a suite of EDR-killing tools—most prominently a multi-variant tool named GentleKiller that impersonates legitimate security products—to disable endpoint defenses via 'bring your own vulnerable driver' (BYOVD) techniques, often leveraging stolen digital signatures and commercial packers; the actor also employs additional external killers (HexKiller, ThrottleBlood, HavocKiller) and a Rust-based credential stealer (OxideHarvest), targets many security vendor processes, and has been linked to prior compromises and a SystemBC proxy botnet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.