# Gentlemen Ransomware Deploys Advanced EDR Killers to Disable Enterprise Defenses


The Gentlemen ransomware-as-a-service (RaaS) operation is actively weaponizing a sophisticated suite of endpoint detection and response (EDR) killers to neutralize enterprise security defenses before deploying ransomware payloads. Security researchers at ESET have documented the group's primary tool, GentleKiller, which exists in at least eight variants and represents a significant escalation in evasion capabilities within the ransomware ecosystem.


## The Threat


Gentlemen RaaS affiliates are leveraging GentleKiller to systematically disable EDR solutions from more than 48 major security vendors, targeting over 400 processes across Microsoft, CrowdStrike, SentinelOne, Palo Alto Networks, Sophos, Trend Micro, ESET, Bitdefender, McAfee/Trellix, and Kaspersky. The tool operates as a standardized framework within the group's attack infrastructure, enabling attackers to:


  • Disable security monitoring before data exfiltration and encryption
  • Evade detection during lateral movement and privilege escalation
  • Maintain persistence by neutralizing behavioral analysis engines
  • Adapt rapidly by swapping vulnerable drivers without code rewrites

  • Each GentleKiller variant employs the bring-your-own-vulnerable-driver (BYOVD) technique—a privilege escalation method that leverages legitimate but unpatched drivers to gain kernel-level access. This approach allows the malware to circumvent user-mode EDR protections by operating at the highest privilege level on compromised systems.


    ESET's analysis reveals that while each variant uses different vulnerable drivers, they maintain identical code obfuscation techniques, common internal strings, and similar process-killing logic. This architectural consistency suggests intentional design for flexibility—allowing the threat actors to substitute newly disclosed driver vulnerabilities without redesigning core functionality.


    ## Background and Context


    The evolution of EDR killers represents a critical turning point in ransomware sophistication. Historically, ransomware operators relied on known techniques like AMSI bypass or API hooking. The emergence of BYOVD-based tools demonstrates a shift toward kernel-level attacks that fundamentally outpace traditional endpoint protections.


    Gentlemen has been actively targeting enterprises across multiple sectors. The group previously compromised Oltenia, a Romanian energy provider, and maintains operational infrastructure linked to the SystemBC proxy malware botnet—a network comprising over 1,570 identified corporate victims. This botnet infrastructure allows Gentlemen to maintain persistent access and coordinate complex multi-stage attacks.


    A particularly concerning development is the apparent correlation between Gentlemen's targeting patterns and leaked FortiGate VPN credentials. Earlier this year, security researchers discovered "FortiBleed," a collection of nearly 74,000 compromised FortiGate appliance credentials. Gentlemen's tendency to select targets based on FortiGate endpoint configurations suggests the group may be cross-referencing this leaked credential database with publicly available scanning data—a tactic that significantly reduces attack complexity and increases success rates.


    Beyond GentleKiller, Gentlemen's toolkit includes additional EDR killers:


    | Tool | Origin | Context |

    |------|--------|---------|

    | HexKiller | Previously used by Warlock gang | External acquisition, potential attribution complexity |

    | ThrottleBlood | Associated with MesudaLocker/DragonForce attacks | Demonstrates code reuse across ransomware families |

    | HavocKiller | Documented in other ransomware operations | Suggests shared tools across RaaS ecosystem |

    | OxideHarvest | Rust-based credential stealer | Likely externally developed based on language choice |


    ## Technical Details


    ### The GentleKiller Framework


    GentleKiller operates as a modular platform rather than a monolithic tool. This architecture provides three key advantages:


    1. Driver substitution capability: When kernel exploits are patched, operators can swap vulnerable drivers without modifying core logic

    2. Scalability: The framework can target new security products through configuration changes alone

    3. Obfuscation flexibility: Variant creation allows for continued evasion despite analysis and detection signatures


    Each variant implements a layered obfuscation strategy:


  • Commercial packing: Binaries are protected using Enigma and Themida—commercial-grade code protection tools typically associated with legitimate software development
  • Stolen signatures: The threat actors employ invalid digital signatures stolen from legitimate software, likely to bypass authentication checks or trigger false trust indicators during initial execution
  • Polymorphic loading: Different variants use distinct vulnerable drivers, creating unique binary fingerprints

  • ### The BYOVD Exploitation Chain


    The BYOVD technique operates in three stages:


    Stage 1: Vulnerable Driver Identification

    GentleKiller identifies and loads a known-vulnerable driver present on the target system. Variants use different drivers—some leveraging graphics drivers, others leveraging older storage or network drivers.


    Stage 2: Privilege Escalation

    Through documented or zero-day vulnerabilities in these drivers, the malware achieves ring-0 (kernel) access. From this vantage point, system-level restrictions become irrelevant.


    Stage 3: Defense Neutralization

    With kernel privileges, GentleKiller systematically terminates security processes, disables kernel callbacks used by EDR sensors, and patches security engine memory to prevent re-initialization.


    ### Target Scope


    ESET's process analysis identified 400+ security processes across 48 vendors. Notable targets include:


  • Microsoft Defender (multiple processes)
  • CrowdStrike Falcon (csfalcon.exe, CSFalconService.exe)
  • SentinelOne (SentinelAgent.exe, SentinelAgentWorker.exe)
  • Kaspersky (avp.exe, klswd.exe)
  • Sophos (SophosRT.exe, SophosHealthService.exe)

  • This comprehensive targeting eliminates the assumption that organizations using premium EDR solutions gain meaningful protection against Gentlemen attacks.


    ## Implications


    The emergence of production-grade, modular EDR killers represents a fundamental shift in the adversarial calculus:


    ### For Enterprise Security Teams

  • EDR alone is insufficient: Kernel-level attacks require defense-in-depth approaches combining EDR, network segmentation, endpoint hardening, and behavioral monitoring
  • Vulnerable drivers are a liability: Organizations must inventory and patch or disable drivers, particularly legacy or graphics drivers rarely considered security-critical
  • Access controls matter more: Since EDR can be defeated, robust identity controls, MFA, and network micro-segmentation become primary defenses

  • ### For Vulnerability Researchers

  • Driver vulnerabilities require expedited patching: The BYOVD technique creates pressure for OEMs to patch driver flaws traditionally considered low-priority
  • Code reuse accelerates threats: The sharing of tools like HexKiller across ransomware families suggests emerging commoditization of attack infrastructure

  • ### For the Threat Landscape

  • Ransomware sophistication continues escalating: Gentlemen's investment in modular tooling suggests RaaS operations are evolving into sophisticated software development organizations
  • Correlation with credential dumps is strategic: The FortiBleed connection demonstrates how threat actors synthesize leaked credentials with targeting intelligence to reduce operational friction

  • ## Recommendations


    ### Immediate Actions


    Organizations targeted by ransomware groups should:


    1. Audit driver inventory across all endpoints and virtual machines, prioritizing graphics, storage, and network drivers for removal or patching

    2. Verify EDR sensor operational status using out-of-band monitoring channels (e.g., logging servers, SIEM platforms) rather than endpoint-based health checks

    3. Review FortiGate access logs for unexpected administrative logins, particularly from newly registered accounts or geographic anomalies


    ### Medium-Term Hardening


  • Implement kernel integrity monitoring using hardware-backed security features (e.g., Intel TXT, AMD SME) to detect runtime kernel modifications
  • Deploy application whitelisting to prevent execution of unsigned binaries, restricting driver loading to approved sources
  • Enable attack surface reduction rules in Windows Defender, including "Block Office applications from creating child processes" and "Block Win32 API calls from Office macros"

  • ### Long-Term Strategy


  • Adopt zero-trust architecture that validates every access request regardless of endpoint security posture
  • Establish threat intelligence sharing for driver vulnerability trends and EDR killer detection signatures
  • Develop incident response procedures specific to EDR compromise scenarios, including network isolation protocols and forensic imaging timelines

  • ## HackWire Analysis


    The release of FortiBleed—74,000 exposed VPN credentials—occurred within weeks of when Gentlemen began demonstrating FortiGate-aware targeting. This is unlikely to be coincidental. What's striking is not simply that credential leaks enable faster breach success, but that modern ransomware RaaS operations now maintain active threat intelligence pipelines. Gentlemen isn't just a malware gang; it's operating like a sophisticated intelligence organization, correlating leaked data with scanning results to identify high-value targets with minimal reconnaissance overhead.


    The deeper implication is that EDR as a security boundary is collapsing. For years, the security industry marketed EDR as the solution to targeted attacks and advanced threats. Yet Gentlemen has systematized EDR defeat into reproducible, updateable tooling. Organizations that bet their security strategy on a single protective layer are gambling that their chosen EDR will remain undefeated. The evidence suggests that gamble is increasingly poor odds.


    For defenders, the lesson is uncomfortable: you cannot achieve security through technology purchases alone. If Gentlemen can disable any EDR with modular tooling, then security must rest on defense-in-depth, network segmentation, and identity controls that operate independently of endpoint agent status. The organizations that survive Gentlemen attacks will be those that assume endpoint compromise as a baseline scenario and design around it.


    — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)