Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2209+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
NEWS

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

The Gentlemen ransomware-as-a-service operation distributes a sophisticated EDR-killing toolkit called GentleKiller to affiliates, capable of terminating...

Dylan H.

News Desk

June 19, 2026
3 min read

The Gentlemen ransomware-as-a-service (RaaS) operation has been identified maintaining a comprehensive suite of endpoint detection and response (EDR) killing tools, branded internally as GentleKiller, which the group distributes to affiliates to disable security defenses prior to ransomware deployment.

Security researchers tracking the group have found that this mature toolset targets over 400 distinct security-related processes, representing one of the most extensive EDR evasion frameworks observed in active ransomware campaigns.

The GentleKiller EDR Evasion Framework

GentleKiller operates as a multi-stage EDR termination suite distributed to The Gentlemen affiliates as part of their RaaS package. Unlike simpler tools that rely on a handful of kill commands, this framework includes:

  • Process enumeration and classification — systematically identifies running security software before termination
  • Service manipulation — disables Windows services associated with endpoint security platforms
  • Driver abuse — leverages vulnerable signed drivers (BYOVD technique) to terminate protected processes
  • Registry persistence removal — strips auto-start entries for security tools to prevent recovery after reboot
  • Shadow copy deletion — removes VSS snapshots to prevent data recovery post-encryption

The framework targets processes from major security vendors including CrowdStrike, SentinelOne, Carbon Black, Sophos, Trend Micro, ESET, Malwarebytes, and dozens of others across both consumer and enterprise categories.

Affiliate Distribution Model

The Gentlemen operate a structured affiliate program where GentleKiller is bundled with the encryptor payload as a pre-attack preparation toolkit. Affiliates receive:

  1. The GentleKiller executable suite
  2. A target process list updated by the core team
  3. Deployment guides for different operating environments
  4. Customer support through dark web infrastructure

This model reflects a broader trend in the RaaS ecosystem toward professionalizing anti-detection capabilities — treating EDR evasion as a distributed service rather than a per-affiliate challenge.

Why This Matters for Defenders

The systematic nature of GentleKiller poses a significant challenge to organizations relying primarily on endpoint-based detection. When an attacker can reliably kill EDR processes before deploying ransomware, the entire detection-and-response chain is severed at its most critical moment.

Security teams should consider layered defense strategies that do not depend on endpoint agents being active:

  • Network-based anomaly detection — identify lateral movement and C2 communication before agents are killed
  • Immutable logging — ensure security logs are shipped to remote SIEM systems that cannot be tampered with locally
  • Tamper protection enforcement — modern EDR platforms offer kernel-level tamper protection that resists user-mode termination attempts
  • Privileged access control — limit who can install or execute unsigned drivers, blocking the BYOVD vector
  • Deception technology — honeypot processes that alert on enumeration before evasion occurs

The Gentlemen's Growing Infrastructure

The group has been linked to attacks against at least 478 victims globally, with a claimed ability for the ransomware to spread worm-like across networks. The GentleKiller framework is central to their operational doctrine, allowing affiliates with limited technical capability to effectively neutralize enterprise-grade security stacks.

Security researchers recommend organizations verify that tamper protection is enabled across all EDR deployments and that security event logs are being forwarded to remote, write-protected storage that local processes cannot modify or delete.

#Ransomware#Cybercrime#EDR Evasion#The Hacker News#Endpoint Security

Related Articles

ThreatsDay: Game Cheat Spyware, Spirals Ransomware, Chrome Sync Stalking

This week's threat roundup covers NuGet packages poisoned with game-cheat spyware, the Spirals ransomware deploying network-wide in under 24 hours, and...

5 min read

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

A 41-year-old former cybersecurity professional has been sentenced to 70 months in federal prison for conspiring with the now-defunct BlackCat ransomware...

4 min read

Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More

This week's threat roundup covers the Usbliter8 iPhone boot exploit, NarwhalRAT spread via fake Microsoft alerts, The Gentlemen ransomware's GentleKiller...

5 min read
Back to all News