The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
ID: de609aa5-d711-5d18-aa62-bb8587e50fd4
STIX ID: report--de609aa5-d711-5d18-aa62-bb8587e50fd4
Feed Name: The Hacker News
ESET and other researchers detail the activity of The Gentlemen ransomware RaaS, which centralizes and distributes an EDR-killer suite called GentleKiller (plus third-party BYOVD tools) to affiliates to disable endpoint defenses prior to encryption. The report documents exploitation of multiple vulnerable drivers and vendor-signed UEFI binaries (enabling Secure Boot bypass), a Rust-based credential stealer (OxideHarvest), the group's rapid operationalization of PoC BYOVD exploits, and an estimated 504 victims across multiple regions — highlighting a high-risk, actively exploited criminal capability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
