{"id":13771,"date":"2026-06-21T10:03:42","date_gmt":"2026-06-21T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/21\/gentlekiller-ransomware-abuses-vulnerable-drivers-to-disable-400-edr-security-processes\/"},"modified":"2026-06-21T10:03:42","modified_gmt":"2026-06-21T10:03:42","slug":"gentlekiller-ransomware-abuses-vulnerable-drivers-to-disable-400-edr-security-processes","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/21\/gentlekiller-ransomware-abuses-vulnerable-drivers-to-disable-400-edr-security-processes\/","title":{"rendered":"GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes"},"content":{"rendered":"<p>    GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A highly sophisticated EDR-killing framework, dubbed GentleKiller, was used by the <a href=\"https:\/\/cybersecuritynews.com\/gentlemen-raas-attacking-windows-linux\/\" target=\"_blank\" rel=\"noreferrer noopener\">Gentlemen ransomware-as-a-service (RaaS)<\/a> gang to systematically disable endpoint security tools before deploying its ransomware payload.<\/p>\n<p class=\"wp-block-paragraph\">The findings by ESET, published on June 17, 2026, detail how Gentlemen, one of the most active ransomware gangs in Q1 2026, provides affiliates with a centralized, operator-maintained suite of EDR killers, a model rare even among top-tier ransomware operations.<\/p>\n<p class=\"wp-block-paragraph\">GentleKiller is an in-house EDR-killing framework with at least eight distinct variants, each impersonating a different legitimate security product and abusing a unique vulnerable or malicious kernel-level driver.<\/p>\n<p class=\"wp-block-paragraph\">The technique used is <a href=\"https:\/\/cybersecuritynews.com\/lenovo-driver-terminate-edr-processes\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bring Your Own Vulnerable Driver (BYOVD)<\/a>, loading a legitimately signed but exploitable driver to terminate security processes at the kernel level, bypassing user-mode protections.<\/p>\n<p class=\"wp-block-paragraph\">In total, GentleKiller targets more than 400 processes mapped to 48 security products, including industry leaders such as Microsoft Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky, and McAfee\/Trellix.<\/p>\n<p class=\"wp-block-paragraph\">The framework operates on a loop, periodically scanning and terminating targeted processes every two seconds, as evidenced by the output shown below.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh7MpREDbf7bra3sU2J3A5UFdL5uW5ExUlvGwsGANvmJERqk9Iyd-2Gx-1eKzrM47UVIcLkdbqdMniVLx-iwYqwXyHNZmoNkHWdf0879sMHHxKnhyphenhyphentHOfAOb4nLJEuwMgj60or4aY8f2fuk7u35DN_mZRXUVg7dZiLcvwpuN2CdkxfYS8jq9zrsfdFgFu2P\/w640-h582\/GentleKiller%2520Ransomware%2520Abuses%2520Vulnerable%2520Drivers.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Window spawned by GentleKiller [ESET Research]<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The eight GentleKiller variants abuse drivers from Kaspersky (<code>eb.sys<\/code>), FACEIT Anti-Cheat (<code>nseckrnl.sys<\/code>), Valorant (<code>GameDriverX64.sys<\/code>), Javelin\/Safetica (<code>stpm_old.sys<\/code>\/<code>stpm_new.sys<\/code>), Zemana WatchDog (<code>dmx.sys<\/code>), Qihoo 360 (<code>360netmon_wfp.sys<\/code>), IObit (<code>IMFForceDelete<\/code>), and the PoisonX rootkit.<\/p>\n<p class=\"wp-block-paragraph\">A defining capability of Gentlemen is its ability to operationalize newly published BYOVD proof-of-concept (PoC) exploits within days of public release.<\/p>\n<p class=\"wp-block-paragraph\">Tools such as UnknownKiller and PoisonKiller were incorporated into GentleKiller\u2019s arsenal within days of their public GitHub disclosure, demonstrating a well-resourced and agile development pipeline, <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/killing-me-gently-inside-gentlemens-edr-killer-framework\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">according to ESET research<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">This rapid adoption distinguishes Gentlemen from most other RaaS operators, who typically wait weeks or months before adapting publicly released exploits into production-ready tooling.<\/p>\n<h2 id=\"h-third-party-edr-killers-integrated-into-the-suite\" class=\"wp-block-heading\"><strong>Third-Party EDR Killers Integrated Into the Suite<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Beyond GentleKiller, Gentlemen also integrates three externally sourced EDR killers into its affiliate-facing suite:<\/p>\n<ul class=\"wp-block-list\">\n<li>HexKiller \u2014 Previously attributed exclusively to the Warlock gang; abuses a Baidu Antivirus BdApi driver (<code>googleApiUtil64.sys<\/code>)<\/li>\n<li>ThrottleBlood \u2014 Previously observed in MedusaLocker and DragonForce intrusions; abuses a TechPowerUp LLC driver (<code>ThrottleBlood.sys<\/code>)<\/li>\n<li>HavocKiller \u2014 First publicly disclosed by Huntress on March 19, 2026, but observed in real-world intrusions as early as January 23, 2026; abuses a Huawei Audio driver (<code>havoc.sys<\/code>)<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">All three tools are standardized through a shared defense-evasion layer that applies Enigma or Themida binary protectors, impersonates security vendors with fabricated version information, copied digital signatures, and matching icons.<\/p>\n<p class=\"wp-block-paragraph\">Gentlemen applies its evasion strategy at the compiled binary level, allowing it to protect even EDR killers for which it does not own the source code. This creates significant attribution challenges, as tools from different ransomware groups appear near-identical once processed through Gentlemen\u2019s standardization pipeline.<\/p>\n<p class=\"wp-block-paragraph\">The gang also uses OxideHarvest, a Rust-written credential stealer maintained by a Gentlemen affiliate, which harvests credentials from Chromium-based and Gecko-based browsers across compromised hosts.<\/p>\n<p class=\"wp-block-paragraph\">Gentlemen emerged in late 2025 as a RaaS operation founded by <code>hastalamuerte<\/code>, a <a href=\"https:\/\/cybersecuritynews.com\/qilin-ransomware-gain-traction\/\" target=\"_blank\" rel=\"noreferrer noopener\">former Qilin affiliate<\/a>, and rapidly became one of the five most active ransomware gangs in Q1 2026.<\/p>\n<p class=\"wp-block-paragraph\">Unlike most major ransomware groups that focus heavily on US-based targets, Gentlemen deliberately targets victims in Southeast Asia, South America, and Western Europe, selecting targets primarily based on FortiGate misconfigurations rather than geographic criteria.<\/p>\n<p class=\"wp-block-paragraph\">The gang was further exposed by an internal data leak in May 2026, which confirmed that its operators actively develop, maintain, and distribute GentleKiller and the broader <a href=\"https:\/\/cybersecuritynews.com\/ransomware-actors-expand-edr-killer-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">EDR-killer suite<\/a> to vetted affiliates.<\/p>\n<p class=\"wp-block-paragraph\">Gentlemen offers affiliates an unusually generous 90% revenue share, lowering the barrier to entry and accelerating its affiliate recruitment.<\/p>\n<p class=\"wp-block-paragraph\">Security teams should prioritize driver allowlisting and enforce Microsoft\u2019s Vulnerable Driver Blocklist to prevent BYOVD-style attacks. Defenders should also monitor for the GentlemenCollection staging directory and anomalous kernel driver loading events.<\/p>\n<p class=\"wp-block-paragraph\">Correlating process-termination patterns, especially targeting security software with driver installation events, remains the most reliable behavioral detection signal against GentleKiller and its variants.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gentlekiller-ransomware-edr-processes\/\">GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gentlekiller-ransomware-edr-processes\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes A highly sophisticated EDR-killing framework, dubbed GentleKiller, was used by the Gentlemen ransomware-as-a-service (RaaS) gang to systematically disable endpoint security tools before deploying its ransomware payload. The findings by ESET, published on June 17, 2026, detail how Gentlemen, one of the most active ransomware [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-13771","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13771"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13771"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13771\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13771"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13771"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}