Gentlemen Ransomware Uses Multiple EDR Killers to Disable Defenses

Security researchers report that the Gentlemen ransomware-as-a-service (RaaS) is actively developing a suite of EDR-killing tools to evade defenses, led by GentleKiller, a modular toolkit with at least eight variants that impersonate legitimate security products. These EDR killers use the bring-your-own-vulnerable-driver (BYOVD) technique to escalate privileges and disable security engines in the early stages of an intrusion, enabling encryption and data theft to proceed unimpeded. ESET notes that all GentleKiller variants share common strings, obfuscation techniques, and similar process-killing logic, and target more than 400 processes across roughly 48 security vendors. The operation also employs external tools—HexKiller, ThrottleBlood, HavocKiller—and OxideHarvest, a Rust-based credential stealer developed externally. Gentlemen has previously compromised the Romanian energy provider Oltenia and is linked to a SystemBC botnet with over 1,570 hosts; FortiGate endpoint configurations reportedly guide its targeting.

TechLogHub
June 19, 2026
4 min read
0 views

Share Article

Gentlemen Ransomware Uses Multiple EDR Killers to Disable Defenses

Gentlemen Ransomware: A Multifaceted EDR Evasion Toolkit and FortiGate Targeting

OverviewThe Gentlemen ransomware-as-a-service (RaaS) operation continues to evolve by building and maintaining an extensive set of endpoint detection and response (EDR) evasion tools. These tools are designed to help affiliates bypass security controls during intrusions, enabling data theft and encryption phases to proceed with minimal interference.

The EDR Killer FrameworkA core component of the Gentlemen toolkit is a collection of EDR-killing utilities that are deployed early in an attack to blunt defenses. The most prominent member of this family is a covert tool family researchers have dubbed GentleKiller. Across its variants, GentleKiller masquerades as a range of legitimate security products, a tactic that reduces suspicion during the initial foothold and privilege escalation stages.

GentleKiller: The Core Tool

  • Central role: Used to disrupt detection, allowing encryption and data exfiltration to proceed with reduced friction.
  • Variant count: At least eight distinct variants have been identified.
  • Impersonation targets: The tool pretends to be various security or protection products to blend into normal system activity. Reported impersonations include brands and products that resemble familiar security suites.
  • Operational pattern: Each variant tends to carry the same essential capabilities—though with different payloads and driver interactions—resulting in a flexible, easily swappable toolkit in response to defenders’ updates.

Driver-based privilege escalation and persistence

  • BYOVD technique: Gentlemen’s EDR killers rely on bring-your-own-vulnerable-driver methods to elevate privileges and disable parts of the security stack.
  • Kernel-level access: Variants leverage specific vulnerable drivers to execute with higher privileges, enabling deeper control over the affected host.

Variant names and drivers used

  • Documentation indicates multiple named variants and driver payloads under the GentleKiller umbrella, with each variant pairing a distinct driver to achieve kernel privileges.
  • Shared characteristics: Despite differences in drivers, variants exhibit common strings, uniform code obfuscation methods, and similar logic for terminating competing processes.

Process targeting and vendor reach

  • Broad target set: GentleKiller variants are reported to focus on hundreds of processes linked to dozens of security tools and vendors.
  • Notable targets include major security and defense vendors, illustrating an approach designed to degrade a wide range of protective measures rather than a single product line.
  • Vendor examples: Microsoft, CrowdStrike, SentinelOne, Palo Alto Networks, Sophos, Trend Micro, ESET, Bitdefender, McAfee/Trellix, and Kaspersky are among the entities observed in the targeting scope.

Binaries, protection, and trust abuse

  • Packing and protection: The EDR killer binaries are protected using commercial packers and protectors, complicating reverse engineering and forensic analysis.
  • Authentic signatures: Researchers note the use of stolen digital signatures from legitimate software, which adds a layer of trust abuse to bypass initial checks and approvals.

External tools in the toolkitIn addition to GentleKiller, the threat group has integrated several external utilities to broaden effectiveness, redundancy, or situational adaptability.

  • HexKiller: Previously associated with other threat groups, HexKiller is incorporated to widen the evasive toolkit.
  • ThrottleBlood: Linked to past campaigns involving MesudaLocker and DragonForce, this tool supports additional evasion or propagation capabilities.
  • HavocKiller: Appeared in other ransomware operations and integrated to diversify the toolkit.
  • OxideHarvest: A Rust-based credential-stealer tool believed to be developed outside the core group, contributing additional credential exfiltration capabilities.

Operational strategy and deployment context

  • FortiGate focus: Analyses indicate the Gentlemen operation routes its targeting decisions through the configuration and state of FortiGate endpoints, highlighting a preference for specific enterprise security environments.
  • FortiBleed backdrop: The emphasis on FortiGate configurations occurs against the backdrop of credential exposure risks associated with Fortinet VPN devices identified in recent disclosures.
  • Notable campaigns: The gang has been linked to the compromise of critical infrastructure entities and large corporate networks, illustrating a campaign history that spans multiple sectors and incident types.
  • Proliferation of botndrive: The operation has been observed leveraging a SystemBC proxy botnet to extend reach and persistence across victim environments.

Associated activity and ecosystem connections

  • Prior intrusions: The Gentlemen group has been connected to a sequence of intrusions that involved various downstream effects, including system compromise, encryption deployments, and data exfiltration.
  • Proxy and remote access tools: The use of proxy-based architectures and remote access proxies underscores an emphasis on maintaining persistence and stealth within affected networks.
  • Attribution and collaboration: While multiple tools and families are present in the toolkit, researchers emphasize a modular approach that allows the core EDR killers to be augmented or swapped with external components as needed.

Impact and observability notes

  • Detection challenges: The combination of impersonation, code obfuscation, and driver-based elevation complicates timely detection, contributing to higher chances that initial footholds remain unseen.
  • Coverage breadth: The wide range of targeted processes and vendors implies that defenders must monitor a broad surface area, including less obvious security endpoints and driver-layer activity.
  • Tool resilience: The inclusion of multiple, independent tooling elements—each with its own drivers and stubs—creates redundancy that can help the operators adapt to defensive changes without rewriting the core payloads.

Observations and context

  • Campaign diversity: The Gentlemen operation demonstrates a pattern of evolving toolsets that blend legitimate software impersonation, kernel-level techniques, and external companions to maintain flexibility in the face of patching and threat intelligence.
  • Infrastructure ties: The use of external tools and botnet-based networking points to a broader ecosystem of capabilities where modular components can be reused or repurposed across different attack scenarios.
  • Cross-era continuity: The toolkit’s continued development mirrors a long-running strategy among ransomware operators to combine stealth with aggressive data handling, ensuring encryption and exfiltration phases proceed with limited disruption from defenders.

ConclusionGentlemen ransomware represents a multifaceted approach to evading modern endpoint protections. By stitching together a core EDR-killer framework with a suite of external tools, credential theft options, and driver-based escalation methods, the operators create a versatile platform capable of penetrating diverse security environments. The targeting emphasis on FortiGate configurations and the history of disruptive campaigns underscore the need for broad monitoring of driver activity, process behavior, and credential-access techniques to understand and observe this evolving threat landscape.

Stay Updated

Get the next deep dive in your inbox

Subscribe for product analysis, engineering explainers, and practical guides published on TechLogHub.

See what launched this week

One email a week: new and trending developer tools, fresh comparisons, and what shipped. Unsubscribe in one click.