The Gentlemen ransomware operation continues to strengthen its attack capabilities by supplying affiliates with specialized tools designed to disable security products. Researchers have identified multiple endpoint detection and response (EDR) killers that help attackers bypass defenses before launching ransomware attacks.
The ransomware-as-a-service group has rapidly grown since emerging in 2025. Security researchers now rank it among the most active ransomware operations of 2026. The group’s operators actively develop and maintain their own security-disabling tools rather than leaving that task to affiliates.
Researchers say this approach gives affiliates a better chance of avoiding detection during the early stages of an intrusion. Once attackers neutralize security software, they can move through networks more freely and prepare systems for encryption and data theft.
GentleKiller Targets Security Products
The most prominent tool in the group’s arsenal is a utility researchers named GentleKiller. Analysts have identified at least eight variants of the software, each designed to disable endpoint security solutions while disguising itself as legitimate applications.
Researchers found versions that impersonate well-known products and services to reduce suspicion. The operators continuously update the tool and distribute new builds to affiliates as security vendors improve detection capabilities.
According to ESET researchers, some GentleKiller variants can target hundreds of security-related processes across dozens of endpoint protection products. That level of coverage makes the tool particularly dangerous in enterprise environments.
Attackers Abuse Vulnerable Drivers
The ransomware group relies heavily on the bring-your-own-vulnerable-driver (BYOVD) technique. This tactic allows attackers to load legitimate but vulnerable drivers and then exploit them to gain elevated privileges on compromised systems.
After obtaining those privileges, the malware can terminate security processes, disable monitoring services, and interfere with defensive controls. Attackers often perform these actions before deploying ransomware payloads or stealing data.
Security researchers have observed a growing number of ransomware groups adopting similar tactics. However, The Gentlemen stands out because the group’s operators actively maintain and distribute EDR-killing tools as part of their ransomware platform.
Internal Leak Revealed Group Operations
A leak of internal Gentlemen data earlier this year provided researchers with a rare look into the operation’s infrastructure and affiliate program. The leaked information confirmed that the group develops EDR killers internally and provides them directly to affiliates.
Researchers also uncovered evidence that the operators help affiliates identify targets and evaluate victim environments. The group reportedly focuses heavily on organizations that use specific edge devices and enterprise infrastructure.
Threat intelligence reports suggest that the ransomware operation has already claimed hundreds of victims across multiple industries and countries. Its rapid growth has attracted significant attention from security researchers and incident responders.
Organizations Need Layered Defenses
Traditional endpoint security remains important, but organizations should not rely on a single layer of protection. Security teams should enable tamper protection features, monitor driver activity, and restrict the execution of unauthorized software whenever possible.
Defenders should also watch for unusual privilege escalation attempts, suspicious driver installations, and efforts to disable security tools. Rapid detection during the early stages of an attack can prevent ransomware operators from gaining full control of a network.
Conclusion
The Gentlemen ransomware group has invested heavily in tools that disable endpoint security products before attacks unfold. Its custom GentleKiller framework and other EDR-killing utilities help affiliates evade detection, move through networks, and deploy ransomware more effectively. As ransomware operators continue to refine these techniques, organizations must strengthen monitoring, harden endpoint protections, and prepare for attacks that target security tools themselves.


0 responses to “Gentlemen Ransomware Uses EDR Killers to Evade Detection”