logo

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

ID: de609aa5-d711-5d18-aa62-bb8587e50fd4

STIX ID: report--de609aa5-d711-5d18-aa62-bb8587e50fd4

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: [email protected] (The Hacker News)

...
...

ESET and other researchers detail the activity of The Gentlemen ransomware RaaS, which centralizes and distributes an EDR-killer suite called GentleKiller (plus third-party BYOVD tools) to affiliates to disable endpoint defenses prior to encryption. The report documents exploitation of multiple vulnerable drivers and vendor-signed UEFI binaries (enabling Secure Boot bypass), a Rust-based credential stealer (OxideHarvest), the group's rapid operationalization of PoC BYOVD exploits, and an estimated 504 victims across multiple regions — highlighting a high-risk, actively exploited criminal capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.