LIVE NEWS
  • GTA 6 early access offers are taking gamers’ crypto
  • How to turn computing power into a financial asset
  • Energy security is back—and other top takeaways from the Atlantic Council’s biggest-ever energy forum
  • Ask Stuart Kirk a question: Where should I invest?
  • House to vote on landmark bill that boosts DOD and VA benefits for some while cutting others
  • Red squirrel sickness reports in Tweeddale under investigation
  • Turkey detains 209 in raids in the capital ahead of July’s NATO summit
  • US Senate Passes Housing Bill With Four-Year Fed CBDC Ban
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»GentleKiller Framework Disables Victims’ Security Software
Cybersecurity

GentleKiller Framework Disables Victims’ Security Software

primereportsBy primereportsJune 22, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
GentleKiller Framework Disables Victims’ Security Software
Share
Facebook Twitter LinkedIn Pinterest Email


One of the most active ransomware gangs of 2026 has been handing its affiliates a ready-made toolkit for switching off victims’ security software before the encryption begins.

New analysis from ESET detailed the endpoint detection and response (EDR) killer suite of The Gentlemen, a ransomware-as-a-service operation (RaaS), built around an in-house framework the researchers named GentleKiller.

GentleKiller’s job is to disable endpoint protection. ESET found it targeting more than 400 processes across roughly 48 security products, from Microsoft Defender and CrowdStrike to Sophos and ESET’s own tools, killing them at the kernel level so the ransomware could run unchecked.

Borrowed Drivers, Kernel Power

The method is called bring your own vulnerable driver (BYOVD). Each build loads a legitimately signed but flawed kernel driver, then abuses it to kill security processes from inside the kernel, beyond the reach of user-mode protections.

ESET counted at least eight GentleKiller variants, each impersonating a different legitimate product, with names lifted from games and security brands such as Valorant, FACEIT and Kaspersky, and each abusing a different driver.

To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.

Read more: Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month

A Suite, Not a Single Tool

What makes Gentlemen unusual is that its operators, not its affiliates, build and maintain the EDR killers. ESET said most ransomware crews leave affiliates to find their own; only a handful, such as RansomHub, supply one. Gentlemen offers a whole portfolio:

  • GentleKiller, the in-house framework, in at least eight variants

  • HexKiller, previously tied to the Warlock gang

  • ThrottleBlood, seen in MedusaLocker and DragonForce intrusions

  • HavocKiller, which abuses a Huawei audio driver

The three borrowed tools were each re-skinned with Gentlemen’s shared evasion layer. GentleKiller itself moved faster still, with the operators turning newly disclosed driver exploits into working variants within days of release.

Inside the Gentlemen Operation

Gentlemen surfaced in late 2025, founded by a former Qilin affiliate, and lures affiliates with an unusually large 90% cut.

ESET confirmed the operator-run model partly through a May data leak, in which the gang’s leader openly discussed maintaining the EDR-killer packages. Unusually, it does not concentrate on US victims, picking targets across Southeast Asia, South America and Western Europe by their exposed FortiGate configurations.

ESET said understanding how GentleKiller works helps defenders prepare even for variants not yet built. In practice, defenses against such BYOVD attacks center on blocking known-vulnerable drivers and alerting whenever a protected security process is suddenly shut down.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe friendship of Alan Greenspan and Ayn Rand : NPR
Next Article BOJ hike barely dents Bitcoin; Polymarket puts 99.95% odds above $56K
primereports
  • Website

Related Posts

Cybersecurity

GTA 6 early access offers are taking gamers’ crypto

June 23, 2026
Cybersecurity

Court rules SAVE database illegal, orders it dismantled

June 22, 2026
Cybersecurity

AryStinger botnet infected thousands of D-Link routers worldwide

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • GTA 6 early access offers are taking gamers’ crypto
  • How to turn computing power into a financial asset
  • Energy security is back—and other top takeaways from the Atlantic Council’s biggest-ever energy forum
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.