Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Researchers Trick AI Browsers Into Leaking Credentials

June 24, 2026

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

June 24, 2026

macOS Backdoor Uses Prompt Injection to Evade AI Triage

June 24, 2026
Facebook X (Twitter) Instagram
Wednesday, June 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»GentleKiller Framework Disables Victims’ Security Software
News

GentleKiller Framework Disables Victims’ Security Software

Team-CWDBy Team-CWDJune 22, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


One of the most active ransomware gangs of 2026 has been handing its affiliates a ready-made toolkit for switching off victims’ security software before the encryption begins.

New analysis from ESET detailed the endpoint detection and response (EDR) killer suite of The Gentlemen, a ransomware-as-a-service operation (RaaS), built around an in-house framework the researchers named GentleKiller.

GentleKiller’s job is to disable endpoint protection. ESET found it targeting more than 400 processes across roughly 48 security products, from Microsoft Defender and CrowdStrike to Sophos and ESET’s own tools, killing them at the kernel level so the ransomware could run unchecked.

Borrowed Drivers, Kernel Power

The method is called bring your own vulnerable driver (BYOVD). Each build loads a legitimately signed but flawed kernel driver, then abuses it to kill security processes from inside the kernel, beyond the reach of user-mode protections.

ESET counted at least eight GentleKiller variants, each impersonating a different legitimate product, with names lifted from games and security brands such as Valorant, FACEIT and Kaspersky, and each abusing a different driver.

To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.

Read more: Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month

A Suite, Not a Single Tool

What makes Gentlemen unusual is that its operators, not its affiliates, build and maintain the EDR killers. ESET said most ransomware crews leave affiliates to find their own; only a handful, such as RansomHub, supply one. Gentlemen offers a whole portfolio:

  • GentleKiller, the in-house framework, in at least eight variants

  • HexKiller, previously tied to the Warlock gang

  • ThrottleBlood, seen in MedusaLocker and DragonForce intrusions

  • HavocKiller, which abuses a Huawei audio driver

The three borrowed tools were each re-skinned with Gentlemen’s shared evasion layer. GentleKiller itself moved faster still, with the operators turning newly disclosed driver exploits into working variants within days of release.

Inside the Gentlemen Operation

Gentlemen surfaced in late 2025, founded by a former Qilin affiliate, and lures affiliates with an unusually large 90% cut.

ESET confirmed the operator-run model partly through a May data leak, in which the gang’s leader openly discussed maintaining the EDR-killer packages. Unusually, it does not concentrate on US victims, picking targets across Southeast Asia, South America and Western Europe by their exposed FortiGate configurations.

ESET said understanding how GentleKiller works helps defenders prepare even for variants not yet built. In practice, defenses against such BYOVD attacks center on blocking known-vulnerable drivers and alerting whenever a protected security process is suddenly shut down.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleLiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
Next Article North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
Team-CWD
  • Website

Related Posts

News

Researchers Trick AI Browsers Into Leaking Credentials

June 24, 2026
News

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

June 24, 2026
News

macOS Backdoor Uses Prompt Injection to Evade AI Triage

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to mitigate the security and privacy risks of smart glasses

May 11, 2026

Common Apple Pay scams, and how to stay safe

January 22, 2026

Your information is on the dark web. What happens next?

January 13, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.