{"id":15903,"date":"2026-06-20T01:43:38","date_gmt":"2026-06-20T01:43:38","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15903"},"modified":"2026-06-20T01:43:39","modified_gmt":"2026-06-20T01:43:39","slug":"inside-gentss-edr-killer-framework","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15903","title":{"rendered":"Inside Gents\u2019s EDR killer framework"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>ESET researchers analyzed the sturdy EDR-killing toolset of the ransomware-as-a-service gang Gents. For the reason that starting of 2026, Gents has emerged as one of the crucial lively gangs within the ransomware ecosystem. The group distinguishes itself by a mature, operator-maintained set of endpoint detection and response (EDR) killers, i.e., instruments for disrupting safety software program. Moreover, in contrast to most top-tier gangs, Gents doesn&#8217;t exhibit a powerful US-centric victimology, as a substitute focusing on victims throughout Southeast Asia, South America, and Western Europe.<\/p>\n<p>Whereas there have been a number of studies masking Gents in latest months, they haven&#8217;t centered on an in depth evaluation of the group\u2019s EDR killers. Due to ESET\u2019s continued incident-level visibility, we will nonetheless present a uniquely deep view into Gents\u2019s EDR-killer improvement practices. The interior knowledge leak that Gents suffered in Might 2026 then gave us much more perception into the internal workings of the group.<\/p>\n<p>The leak additionally allowed us to verify our speculation from February 2026 that Gents operators actively develop and keep a portfolio of EDR killers that they provide to associates, centered round their in-house framework we have now named GentleKiller. Additionally they incorporate third-party or leaked instruments reminiscent of HexKiller, ThrottleBlood, and HavocKiller. These instruments are standardized by a shared defense-evasion layer, impersonating predominantly safety distributors utilizing faux model info, and copied respectable certificates and icons. Gents additionally demonstrates a capability to unusually rapidly operationalize newly disclosed Deliver Your Personal Weak Driver (BYOVD) proofs-of-concept, usually inside days of public launch.<\/p>\n<p>On this blogpost, we share our findings on Gents\u2019s suite of EDR killers gained by intensive analysis and corroborated by the latest leak. We goal to supply actionable insights by connecting the EDR killer packages to precise samples, and tying the leaked knowledge to ways, methods, and procedures (TTPs). Our findings spotlight Gents as one of the crucial technically agile ransomware-as-a-service (RaaS) gangs lively in 2026.<\/p>\n<blockquote>\n<p><strong>Key factors of the blogpost:<\/strong><\/p>\n<ul>\n<li>Gents operators develop and keep an EDR-killer suite offered on to associates.<\/li>\n<li>GentleKiller is an in\u2011home framework with not less than eight variants abusing totally different weak or malicious drivers.<\/li>\n<li>Gents operators apply a unified evasion technique throughout instruments that standardizes impersonation and safety.<\/li>\n<li>Third\u2011social gathering EDR killers (HexKiller, ThrottleBlood, and HavocKiller) are operationally built-in.<\/li>\n<li>Gents can quickly adapt newly launched EDR killer proofs-of-concept (PoCs).<\/li>\n<li>The gang\u2019s victimology is globally distributed and notably not US\u2011centered.<\/li>\n<li>Gents additionally makes use of OxideHarvest, a credential stealer maintained by one of many group\u2019s associates.<\/li>\n<\/ul>\n<\/blockquote>\n<p>All through this blogpost, we check with RaaS <strong>operators<\/strong> and <strong>associates<\/strong>.<\/p>\n<p><strong>Operators<\/strong> are liable for growing the ransomware payload, managing decryption keys, sustaining the devoted leak web site, usually negotiating the ransom cost with victims, and providing different tooling and providers for a month-to-month price or a proportion from the ransom cost (sometimes 5\u201320%).<\/p>\n<p><strong>Associates<\/strong> lease ransomware providers from operators, deploy encryptors to victims\u2019 networks, and are additionally liable for knowledge exfiltration.<\/p>\n<h2>Gents profile<\/h2>\n<p>Gents emerged in late 2025 as a RaaS operation and rapidly grew into one of the crucial lively ransomware gangs noticed in Q1 2026. The gang affords a beneficiant 90% share to associates. Group-IB <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.group-ib.com\/blog\/hastalamuerte-gentlemen-raas-ttps\/\" target=\"_blank\" rel=\"noopener\">disclosed<\/a> that Gents was based by <span style=\"font-family: courier new, courier, monospace;\">hastalamuerte<\/span>, a disgruntled former Qilin affiliate. PRODAFT <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/PRODAFT\/status\/1979181639050596793\" target=\"_blank\" rel=\"noopener\">tweeted<\/a> on October 17<sup>th<\/sup>, 2025 that Gents operators have been beforehand associates of Qilin, Embargo, LockBit, Medusa, and BlackLock. On June 10<sup>th<\/sup>, 2026 Brian Krebs <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2026\/06\/who-runs-the-ransomware-group-the-gentlemen\/\" target=\"_blank\" rel=\"noopener\">shared proof<\/a> of <span style=\"font-family: courier new, courier, monospace;\">hastalamuerte<\/span>\u2019s true id.<\/p>\n<p>Gents makes use of double extortion \u2013 along with encrypting the sufferer knowledge, the group additionally threatens to leak it if the ransom shouldn&#8217;t be paid. For encryption, the operators provide a variant written in Go focusing on Home windows, Linux, and different platforms, and an ESXi variant written in C.<\/p>\n<p>One of many issues that units Gents aside is the gang\u2019s willingness to supply extra than simply encryptors to associates \u2013 specifically, the gang additionally supplies EDR killers. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/edr-killers-explained-beyond-the-drivers\/\" target=\"_blank\" rel=\"noopener\">Latest ESET analysis<\/a> has proven that, in most ransomware intrusions, the duty for locating a dependable EDR killer sometimes falls on particular person associates, not the RaaS operators themselves. Solely a small variety of exceptions to this mannequin have been documented. One notable case is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/shifting-sands-ransomhub-edrkillshifter\/\">RansomHub<\/a>, which invested in growing its personal EDR killer from scratch, EDRKillShifter, after which provided it to associates by the affiliate panel.<\/p>\n<p>Gents represents a special, and to this point underreported, method. Slightly than counting on associates to supply their very own EDR killers, Gents operators actively develop and keep a portfolio of EDR killers for associates. This portfolio combines an in-house developed software, which we named GentleKiller, together with externally sourced or leaked tooling, standardized by a shared evasion layer and staged in a constant method.<\/p>\n<p>ESET researchers hypothesized that GentleKiller was an inside software again in February 2026, and this was later supported by studies from <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.group-ib.com\/blog\/hastalamuerte-gentlemen-raas-ttps\/\" target=\"_blank\" rel=\"noopener\">Group-IB<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/2026\/dfir-report-the-gentlemen\/\" target=\"_blank\" rel=\"noopener\">Verify Level<\/a> \u2013 each point out that the gang supplies EDR-killing capabilities to its (verified) associates. The <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/2026\/thus-spoke-the-gentlemen\/\" target=\"_blank\" rel=\"noopener\">just lately leaked inside knowledge<\/a> of the gang offered the ultimate piece of proof: within the leaks, <span style=\"font-family: courier new, courier, monospace;\">zeta88<\/span> (one other alias utilized by <span style=\"font-family: courier new, courier, monospace;\">hastalamuerte<\/span>), the chief of the gang, brazenly talks about sustaining and offering EDR-killer packages.<\/p>\n<p>Other than confirming our suspicion about GentleKiller, the leaked knowledge additionally allowed us to hyperlink a credential stealer we named OxideHarvest to Gents; particularly, to one in all its associates.<\/p>\n<h3>Victimology<\/h3>\n<p>Whereas the victimology of enormous RaaS operations is commonly formed extra by associates\u2019 decisions than by operator-led technique, one specific sample nonetheless tends to emerge. Most main ransomware gangs present a powerful and protracted give attention to the US, which regularly accounts for roughly half of all introduced victims. This US-centric bias is clear throughout a number of distinguished teams, together with Qilin, DragonForce, and Akira, and has successfully develop into the norm amongst top-tier ransomware operations.<\/p>\n<p>Gents stands out as a notable exception to this pattern. Regardless of rating among the many 5 most lively ransomware gangs in Q1 2026, its victimology doesn&#8217;t exhibit a comparable US focus. As a substitute, Gents associates constantly goal victims throughout a broad and geographically numerous vary of nations, with a major variety of victims coming from areas reminiscent of Southeast Asia, South America, and Western Europe. Certainly, the gang\u2019s focusing on consists of some in any other case uncommon nations like Thailand, Brazil, and France.<\/p>\n<p>The just lately leaked knowledge supplies proof that relating to selecting victims, Gents makes use of a centralized method of sorting by viable candidates after which distributing them to associates. Victims are chosen based on their FortiGate (mis)configuration quite than their geographical location.<\/p>\n<h2>EDR Killers<\/h2>\n<p>In February 2026, we noticed a beforehand undocumented EDR killer deployed by a Gents affiliate and staged in a listing named <span style=\"font-family: courier new, courier, monospace;\">GentlemenCollection<\/span>. We named this software GentleKiller. On the time, we hypothesized that it was not an affiliate-specific artifact however quite a software offered to associates by the Gents operators. Since then, we have now noticed the identical staging sample (dropping GentleKiller and different EDR killers to the <span style=\"font-family: courier new, courier, monospace;\">GentlemenCollection<\/span> listing) a number of instances throughout unrelated intrusions that we investigated, constantly involving Gents associates. In parallel, two independently printed studies by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.group-ib.com\/blog\/hastalamuerte-gentlemen-raas-ttps\/\">Group-IB<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/2026\/dfir-report-the-gentlemen\/\">Verify Level<\/a> assessed that the Gents operators explicitly provide EDR-disabling capabilities as a part of their RaaS program.<\/p>\n<p>Taken collectively, these observations allowed us to conclude that GentleKiller is a part of an EDR-killer suite maintained by the Gents operators. This was later confirmed within the group\u2019s leaked knowledge.<\/p>\n<p>In addition to GentleKiller, the suite additionally accommodates HexKiller, HavocKiller, and ThrottleBlood; all ESET names for EDR killers utilized by associates of rival gangs too and obtained by Gents through unknown means. We additionally noticed DemoKiller in a number of intrusions, however this EDR killer didn&#8217;t exhibit any ties to Gents and due to this fact we exclude it from the gang\u2019s suite and as a substitute think about it affiliate-specific. The next a part of the blogpost covers these instruments in additional element and locations them into the broader EDR-killer ecosystem. Whereas these instruments are operationally built-in into Gents intrusions, we assess with excessive confidence that solely GentleKiller is developed in-house by the Gents operators, whereas the remaining EDR killers have been seemingly sourced externally and subsequently modified and standardized to suit the operators\u2019 toolset. Our evaluation is predicated on:<\/p>\n<ul>\n<li>GentleKiller showing primarily in Gents-related intrusions, usually deployed to the <span style=\"font-family: courier new, courier, monospace;\">GentlemenCollection<\/span> listing,<\/li>\n<li>steady improvement with clear entry to the supply code that enables creating new variants and supporting newly emerged PoCs, and<\/li>\n<li>third-party reporting mentioning Gents providing EDR-killing capabilities to trusted associates.<\/li>\n<\/ul>\n<h3>Protection evasion technique<\/h3>\n<p>Gents operators apply a particular set of protection evasion methods to the gang\u2019s varied EDR killers. These methods are utilized to compiled samples quite than supply code. This offers Gents the choice to guard even the EDR killers whose supply code the gang doesn&#8217;t possess.<\/p>\n<p>All of the EDR killers which are a part of Gents\u2019s portfolio comply with these defense-evasion patterns, which factors to a standardized technique, particularly:<\/p>\n<ul>\n<li>Superior binary safety (Enigma or Themida) is utilized to a good portion of the samples we detected. The filename suffix usually identifies the strategy used (Enigma, Themida, or none).<\/li>\n<li>Filenames are chosen to carefully resemble these of well-known software program distributors, significantly corporations working within the cybersecurity area.<\/li>\n<li>Executables impersonate the distributors by having the next attributes, all matching the identical vendor or product:<\/li>\n<\/ul>\n<p style=\"margin-top: 0.4em; margin-bottom: 0; padding-left: 40px; font-size: 0.9em; display: flex; align-items: flex-start; gap: 0.6em;\"><span style=\"color: #00a0a0; font-size: 1em; line-height: 1.4em; flex-shrink: 0;\">\u25cb<\/span> <span style=\"margin: 0;\">fabricated model info,<\/span><\/p>\n<p style=\"margin-top: 0.4em; margin-bottom: 0; padding-left: 40px; font-size: 0.9em; display: flex; align-items: flex-start; gap: 0.6em;\"><span style=\"color: #00a0a0; font-size: 1em; line-height: 1.4em; flex-shrink: 0;\">\u25cb<\/span> <span style=\"margin: 0;\">invalid digital signatures copied from respectable executables, and<\/span><\/p>\n<p style=\"margin-top: 0.4em; margin-bottom: 0; padding-left: 40px; font-size: 0.9em; display: flex; align-items: flex-start; gap: 0.6em;\"><span style=\"color: #00a0a0; font-size: 1em; line-height: 1.4em; flex-shrink: 0;\">\u25cb<\/span> <span style=\"margin: 0;\">icons matching these of the impersonated distributors.<\/span><\/p>\n<p>Though a small variety of samples deviate from this method, seemingly resulting from inconsistent improvement practices, the overwhelming majority of noticed EDR killers adhere to this sample. In Desk\u00a01, we present how the suffixes work. Later within the blogpost, we clarify how the suffixes are appended to filenames.<\/p>\n<p style=\"text-align: center;\"><em>Desk\u00a01. Naming sample of the EDR killers maintained by Gents<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"155\"><strong>Suffix<\/strong><\/td>\n<td width=\"155\"><strong>Safety<\/strong><\/td>\n<td width=\"155\"><strong>Pretend signature<\/strong><\/td>\n<td width=\"155\"><strong>Pretend model info<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"155\"><span style=\"font-family: courier new, courier, monospace;\">1<\/span><\/td>\n<td width=\"155\">Enigma<\/td>\n<td width=\"155\">Sure<\/td>\n<td width=\"155\">Sure<\/td>\n<\/tr>\n<tr>\n<td width=\"155\"><span style=\"font-family: courier new, courier, monospace;\">2<\/span><\/td>\n<td width=\"155\">Themida<\/td>\n<td width=\"155\">Sure<\/td>\n<td width=\"155\">Sure<\/td>\n<\/tr>\n<tr>\n<td width=\"155\"><span style=\"font-family: courier new, courier, monospace;\">Mild<\/span><\/td>\n<td width=\"155\">None<\/td>\n<td width=\"155\">Sure<\/td>\n<td width=\"155\">Sure<\/td>\n<\/tr>\n<tr>\n<td width=\"155\"><span style=\"font-family: courier new, courier, monospace;\">Clear<\/span><\/td>\n<td width=\"155\">None<\/td>\n<td width=\"155\">No<\/td>\n<td width=\"155\">No<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>GentleKiller<\/h3>\n<p>GentleKiller is by far essentially the most prevalent EDR killer noticed within the Gents ecosystem. On the time of writing, we&#8217;re conscious of not less than eight distinct variants, every impersonating a special respectable product and abusing a special weak or malicious driver. Regardless of these surface-level variations, we classify all of those samples underneath the GentleKiller umbrella resulting from a excessive diploma of shared inside traits.<\/p>\n<p>When abstracting away the impersonation layer and the precise drivers used, the underlying code reveals quite a few structural and behavioral commonalities that strongly counsel the usage of a shared improvement template. This template is reused throughout variants, with solely minimal modifications. The defining traits of the template embrace:<\/p>\n<ul>\n<li>constant strings throughout variants,<\/li>\n<li>terminating processes periodically in a loop,<\/li>\n<li>focusing on a broad set of safety options, and<\/li>\n<li>using equivalent code obfuscation.<\/li>\n<\/ul>\n<p>An instance of GentleKiller\u2019s output is illustrated in Determine\u00a01, and a code snippet exhibiting the code obfuscation is depicted in Determine\u00a02.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 1. Output window spawned by GentleKiller\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/gentlemen\/figure-1.png\" alt=\"Figure 1. Output window spawned by GentleKiller\" width=\"\" height=\"\"\/><figcaption><em>Determine 1. Output window spawned by GentleKiller<\/em><\/figcaption><\/figure>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 2. Code obfuscation implemented by GentleKiller\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/gentlemen\/figure-2.png\" alt=\"Figure 2. Code obfuscation implemented by GentleKiller\" width=\"\" height=\"\"\/><figcaption><em>Determine 2. Code obfuscation applied by GentleKiller<\/em><\/figcaption><\/figure>\n<p>This design prioritizes ease of deployment and operational flexibility for associates, whereas minimizing improvement effort for the operators. It permits the Gents operators to combine abused drivers into their toolset very quickly after an EDR killer PoC is disclosed. This was the case with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/posts\/mse75_github-j3h4ckunknownkiller-poc-exploit-activity-7433165497858367488-3YJ-\/\">UnknownKiller<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/medium.com\/@jehadbudagga\/reverse-engineering-a-0day-used-against-crowdstrike-edr-a5ea1fbe3fd4\">PoisonKiller<\/a>, which have been adopted inside a matter of days.<\/p>\n<p>Whereas some builds don\u2019t goal all of the processes recognized to GentleKiller, the overall set, offered in Desk\u00a02, is constant. We leveraged AI to map the method names to their corresponding distributors, and acknowledge that there is perhaps minor inconsistencies. General, GentleKiller targets greater than 400 processes that the AI mapped to 48 merchandise.<\/p>\n<p style=\"text-align: center;\"><em>Desk\u00a02. An entire record of course of names focused by GentleKiller, mapped to their corresponding distributors<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Vendor<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><strong>Focused processes<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Acronis<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">acronis_agent.exe, BackupAndRecoveryAgent.exe, managementagenthost.exe, mms.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>AlienVault<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">alienvault-agent.exe, osqueryd.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Avast<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">afwServ.exe, aswEngSrv.exe, aswidsagent.exe, aswToolsSvc.exe, AvastSvc.exe, AvastUI.exe, avastsvc.exe, avastui.exe, bccavsvc.exe, wsc_proxy.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>AVG<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">AVGUI.exe, AVGSvc.exe, avgnt.exe, avgsvca.exe, avgToolsSvc.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Binary Protection<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">BinaryDefenseAgent.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Bitdefender<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">Arrakis3.exe, BDAvScanner.exe, BDFsTray.exe, BDFileServer.exe, BDLived2.exe, BDLogger.exe, BDScheduler.exe, BDStatistics.exe, bdagent.exe, bdemsrv.exe, bdntwrk.exe, bdredline.exe, bdregsvr2.exe, bdservicehost.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Blumira<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">BlumiraAgent.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Bromium<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">BromiumDaemon.exe, BrDifxapi.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Carbon Black<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">cb.exe, cbcomms.exe, cbdefense.exe, carbonsensor.exe, RepMgr.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Cisco Talos<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">cfrutil.exe, CiscoAMPCEFWDriver.exe, cisco_amp_connector.exe, immunet.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>CrowdStrike<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">ARWSRVC.EXE, ARCUpdate.exe, CSFalconContainer.exe, CSFalconService.exe, CSFalconUI.exe, csfalcondataprotect.exe, csfalcondaterepair.exe, REPRSVC.EXE<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Cynet<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">CynetEPS.exe, CynetMS.exe, CynetSvc.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Cybereason<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">ActiveConsole.exe, cybereason.exe, CybereasonActiveProbe.exe, CybereasonCR.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Cyvera<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">CyveraConsole.exe, CyveraService.exe, CyvrAgentSvc.exe, CyvrFsFlt.exe, cyvrfsflt.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Cylance\/BlackBerry<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">CylanceSvc.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Darktrace<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">DarktraceTSA.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Deep Intuition<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">DeepInstinct.exe, DeepInstinctService.exe, DIAgentService.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Elastic<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">a2guard.exe, a2service.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>ESET<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">eamonm.exe, eamsi.exe, ecls.exe, efwd.exe, egui.exe, eguiProxy.exe, ekrn.exe, ekrnEpfw.exe, ERAAgent.exe, EraAgentSvc.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Fortinet<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">firesvc.exe, firetray.exe, FortiTray.exe, fortiedr.exe, fw.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>G DATA<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">GDDServer.exe, QHPISVR.EXE, QUHLPSVC.EXE, SAPISSVC.EXE<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Heimdal<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">HeimdalsecurityAgent.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Huntress<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">HuntressAgent.exe, HuntressRMM.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Kaspersky<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">avp.exe, avpsus.exe, avpui.exe, kavfs.exe, kavfsscs.exe, kavfswh.exe, kavfswp.exe, kavtray.exe, klactprx.exe, klcsldcl.exe, klcsweb.exe, klnagent.exe, klnagchk.exe, klscctl.exe, klserver.exe, klwtblfs.exe, kpf4ss.exe, ksde.exe, ksdeui.exe, vapm.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>LogRhythm<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">LogProcessorService.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>McAfee\/Trellix<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">AGMService.exe, AGSService.exe, masvc.exe, macmnsvc.exe, McAfeeAgent.exe, mcshield.exe, mfeann.exe, mfevtps.exe, mfetp.exe, mfeepehost.exe, mfefire.exe, mfemactl.exe, mfemacsvc.exe, mfemgr.exe, mfemms.exe, MgntSvc.exe, ModuleCoreService.exe, tepfsvc.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Microsoft Defender<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">MSASCui.exe, MSASCuiL.exe, MpDefenderCoreService.exe, MsMpEng.exe, MsMpSvc.exe, MsSense.exe, msascuil.exe, msseces.exe, NisSrv.exe, nissrv.exe, SecurityHealthService.exe, SecurityHealthSystray.exe, SenseCncProxy.exe, SenseIR.exe, SenseNdr.exe, SenseSampleUploader.exe, smartscreen.exe, windefend.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Morphisec<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">MorphisecService.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Norton\/Symantec<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">ccApp.exe, ccSvcHst.exe, ccsvchst.exe, ns.exe, nsservice.exe, nortonsecurity.exe, rtvscan.exe, SepMasterService.exe, sepWscSvc64.exe, smc.exe, SmcGui.exe, snac.exe, SymCorpUI.exe, SymWSC.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>OSSEC\/Wazuh<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">ossec-agent.exe, wazuh-agent.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Palo Alto Networks (Traps\/Cortex)<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">cortexService.exe, trapsagent.exe, trapsd.exe, Traps.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Panda Safety<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">panda_url_filtering.exe, pavfnsvr.exe, pavsrv.exe, psanhost.exe, PSANHost.EXE, pselamsvc.EXE, PSUAMain.EXE, PSUAService.EXE, pangps.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Qualys<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">qualys-cloud-agent.exe, QualysAgent.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Rapid7<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">ir_agent.exe, rapid7_endpoint.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Crimson Canary<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">RedCanaryAgent.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Sangfor<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">CSAAgent.exe, CSAService.exe, SangforAgent.exe, SangforCSA.exe, SangforEDR.exe, SangforInterface.exe, SangforMonitor.exe, SangforProtect.exe, SangforService.exe, SangforTray.exe, SangforUD.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>SentinelOne<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">Sentinel.exe, SentinelAgent.exe, SentinelAgentWorker.exe, SentinelCtl.exe, SentinelHelperService.exe, SentinelMemoryScanner.exe, SentinelPowerShellExtension.exe, SentinelRanger.exe, SentinelServiceHost.exe, SentinelStaticEngine.exe, SentinelStaticEngineScanner.exe, SentinelUI.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>SonicWall<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">SonicWallClientProtectionService.exe, swc_service.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Sophos<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">hmpalert.exe, McsAgent.exe, McsClient.exe, SavApi.exe, SAVAdminService.exe, SAVService.exe, SEDService.exe, SophosADSyncService.exe, SophosClean.exe, SophosCleanM64.exe, SophosFIMService.exe, SophosFS.exe, SophosHealth.exe, SophosLiveQueryService.exe, SophosMTR.exe, SophosMTRExtension.exe, SophosNetFilter.exe, SophosNtpService.exe, SophosOsquery.exe, SophosOsqueryExtension.exe, Sophos.PolicyEvaluation.Service.exe, SophosSafestore64.exe, SophosUI.exe, SophosUpdateMgr.exe, sophosav.exe, sophossps.exe, SSPService.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Tanium<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">TaniumClient.exe, TaniumCX.exe, tanclient.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>ThreatLocker<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">ThreatLockerConsent.exe, threatlockerservice.exe, threatlockertray.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>TrendAI<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">coreFrameworkHost.exe, coreServiceShell.exe, NTRTScan.exe, ntrtscan.exe, Ntrtscan.exe, OfcService.exe, ofcDdaSvr.exe, PccNTMon.exe, PccNt.exe, TISafe.exe, TISafeSvc.exe, TmCCSF.exe, tmicAgentSetting.exe, TMBMSRV.exe, Tmbmsrv.exe, tm_netsrv.exe, TmListen.exe, tmntsrv.exe, TmPfw.exe, tmproxy.exe, TmProxy.exe, TmPreFilter.exe, TmSSClient.exe, TmsaInstance64.exe, TmWscSvc.exe, VOneAgentConsole.exe, VOneAgentConsoleTray.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Uptycs<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">VectorAgent.exe, UptycsAgent.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Varonis<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">DatAdvantage.exe, VaronisAgent.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>WatchGuard<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">wlcsservice.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Webroot<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">WRSA.exe, WRSkyClient.exe, WRSVC.exe, wrsa.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Home windows Sysinternals<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">Sysmon.exe, Sysmon64.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 150.656px;\" width=\"151\"><strong>Zscaler<\/strong><\/td>\n<td style=\"width: 485.344px;\" width=\"492\"><span style=\"font-family: courier new, courier, monospace;\">zlclient.exe<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>GentleKiller variants<\/h3>\n<p>Every GentleKiller variant impersonates a special product and abuses a special malicious or weak driver. Desk\u00a03 supplies a listing of the eight GentleKiller variants we have now noticed to this point. The <span style=\"font-family: courier new, courier, monospace;\"><suffix\/><\/span> refers back to the naming sample defined in Desk\u00a01. Drivers\u2019 filenames check with how GentleKiller drops them to disk.<\/p>\n<p style=\"text-align: center;\"><em>Desk\u00a03. Record of GentleKiller variants<\/em><\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"123\"><strong>Variant title<\/strong><\/td>\n<td width=\"208\"><strong>Filenames<\/strong><\/td>\n<td width=\"290\"><strong>Abused driver<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"123\"><strong>Kaspersky<\/strong><\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">Kasp<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"290\"><span style=\"font-family: courier new, courier, monospace;\">eb.sys<\/span>, a rootkit (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/BlackSnufkin\/BYOVD\/tree\/main\/UnknownKiller\">PoC<\/a>)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><strong>FACEIT Anti-Cheat<\/strong><\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">FaceIT<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"290\"><span style=\"font-family: courier new, courier, monospace;\">nseckrnl.sys<\/span>, NSecsoft NSecKrnl driver (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/BlackSnufkin\/BYOVD\/tree\/main\/NSec-Killer\">PoC<\/a>)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><strong>Valorant<\/strong><\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">Valorant<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"290\"><span style=\"font-family: courier new, courier, monospace;\">GameDriverX64.sys<\/span>, an anti-cheat driver (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/BlackSnufkin\/BYOVD\/tree\/main\/GameDriverX64-Killer\">PoC<\/a>)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><strong>Javelin<\/strong><\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">EAAntiCheat<suffix>.exe<\/suffix><\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">EASolo<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"290\"><span style=\"font-family: courier new, courier, monospace;\">stpm_(outdated|new).sys<\/span>, two weak ProcessMonitor Driver samples by Safetica (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/BlackSnufkin\/BYOVD\/tree\/main\/STProcessMonitor-Killer\">PoC<\/a>)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><strong>WatchDog<\/strong><\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">BitD<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"290\"><span style=\"font-family: courier new, courier, monospace;\">dmx.sys<\/span>, Zemana\u2019s WatchDog Antimalware Driver (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/ReCryptLLC\/CVE-2022-42045\/\">PoC<\/a>)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><strong>Community Blocker<\/strong><\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">MB<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"290\"><span style=\"font-family: courier new, courier, monospace;\">360netmon_wfp.sys<\/span>, a weak driver by Qihoo 360 Expertise (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/kyxiaxiang\/360WFP_Exploit\">PoC<\/a>)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><strong>Cleaner<\/strong><\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">Deletor.exe<\/span><\/td>\n<td width=\"290\"><span style=\"font-family: courier new, courier, monospace;\">IMFForceDelete<\/span>, IObit\u2019s IMF ForceDelete filter driver (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/ZeroMemoryEx\/CVE-2025-26125\/\">PoC<\/a>); the driving force is dropped with out the trailing <span style=\"font-family: courier new, courier, monospace;\">.sys<\/span> extension<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><strong>G11<\/strong><\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">G11<suffix>.exe<\/suffix><\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">Symantec<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"290\">PoisonX, a rootkit (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/BlackSnufkin\/BYOVD\/tree\/main\/PoisonX-Killer\">PoC<\/a>)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Third-party EDR killers<\/h2>\n<p>Other than the internally developed GentleKiller, Gents has integrated a number of third-party options into its suite, summarized in Desk\u00a04 and described within the following sections. The <span style=\"font-family: courier new, courier, monospace;\"><suffix\/><\/span> refers back to the naming sample defined in Desk\u00a01. Driver filenames check with how the related EDR killers drop them to disk.<\/p>\n<p style=\"text-align: center;\"><em>Desk\u00a04. Record of third-party EDR killers provided by Gents<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"113\"><strong>ESET title for the EDR killer<\/strong><\/td>\n<td width=\"198\"><strong>Filenames<\/strong><\/td>\n<td width=\"331\"><strong>Abused driver<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"113\"><strong>HexKiller<\/strong><\/td>\n<td width=\"198\"><span style=\"font-family: courier new, courier, monospace;\">Avast<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"331\"><span style=\"font-family: courier new, courier, monospace;\">googleApiUtil64.sys<\/span>, Baidu Antivirus BdApi driver<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>ThrottleBlood<\/strong><\/td>\n<td width=\"198\"><span style=\"font-family: courier new, courier, monospace;\">Despatched<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"331\"><span style=\"font-family: courier new, courier, monospace;\">ThrottleBlood.sys<\/span>, driver by TechPowerUp LLC<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>HavocKiller<\/strong><\/td>\n<td width=\"198\"><span style=\"font-family: courier new, courier, monospace;\">HwAudKiller.exe<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">Sophos<suffix>.exe<\/suffix><\/span><\/td>\n<td width=\"331\"><span style=\"font-family: courier new, courier, monospace;\">havoc.sys<\/span>, Huawei Audio driver<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4>HexKiller<\/h4>\n<p>HexKiller is an EDR killer that we beforehand assessed as being unique to the Warlock gang. Due to this fact, its look inside Gents intrusions is sudden and noteworthy.<\/p>\n<p>We discovered HexKiller staged alongside GentleKiller binaries throughout the <span style=\"font-family: courier new, courier, monospace;\">GentlemenCollection<\/span> listing. However, its presence in Gents intrusions doesn&#8217;t, by itself, suggest direct collaboration or operational overlap between the Gents and Warlock gangs. It&#8217;s believable that Gents operators obtained HexKiller by oblique means, reminiscent of non-public exchanges, secondary distribution channels, or pattern leaks, with none want for direct interplay with Warlock. We due to this fact don\u2019t think about this to be proof of a deeper relationship between the 2 teams.<\/p>\n<h4>ThrottleBlood<\/h4>\n<p>This EDR killer has been repeatedly noticed in intrusions carried out by MedusaLocker associates, and, much less regularly, by DragonForce associates. Moreover, it was <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/i\/unmasking-the-gentlemen-ransomware.html\">linked<\/a> to Gents by Development Micro in September 2025.<\/p>\n<p>At current, we shouldn&#8217;t have adequate proof to conclusively decide the origin of ThrottleBlood. In our telemetry, it seems prominently deployed throughout a number of MedusaLocker intrusions and sporadically in DragonForce-related exercise. These incidents present little operational overlap past the usage of ThrottleBlood itself. One doable rationalization is that ThrottleBlood is commercially distributed on underground markets, or alternatively a software developed by MedusaLocker operators and shared with their associates, a few of whom may have ties to DragonForce.<\/p>\n<p>Neither speculation, nonetheless, totally explains how a ThrottleBlood pattern appeared in Gents\u2019s possession. In consequence, we can not rule out the opportunity of Gents buying the software by it leaking past the initially meant context. What we state with excessive confidence, nonetheless, is that Gents didn&#8217;t develop this EDR killer in-house.<\/p>\n<h4>HavocKiller<\/h4>\n<p>HavocKiller is the ultimate addition to Gents\u2019s EDR-killer arsenal. Whereas the software was publicly <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.huntress.com\/blog\/w2-malvertising-to-kernel-mode-edr-kill\">disclosed<\/a> by Huntress on March 19<sup>th<\/sup>, 2026, ESET telemetry confirms its use in real-world intrusions relationship again to not less than January 23<sup>rd<\/sup>, 2026, indicating that it had been operational for weeks previous to public reporting. We will additionally corroborate Huntress\u2019s evaluation concerning its goal: in all instances noticed by ESET, the deployment of HavocKiller was a part of ransomware-related exercise.<\/p>\n<p>Primarily based on its technical traits, we assess that HavocKiller shouldn&#8217;t be developed by the Gents operators themselves, however as a substitute was obtained by exterior means. Though the samples have been staged throughout the <span style=\"font-family: courier new, courier, monospace;\">GentlemenCollection<\/span> listing and Gents\u2019s commonplace set of protection evasion methods was utilized to them, the underlying implementation differs considerably from GentleKiller. This strongly means that HavocKiller represents a third-party EDR killer that was tailored operationally, however its structure doesn&#8217;t match into Gents\u2019s framework.<\/p>\n<h2>OxideHarvest<\/h2>\n<p>We additionally detected a number of deployments of a software we named OxideHarvest, a credential stealer written in Rust. Since Rust shouldn&#8217;t be the programming language of selection for Gents, we don&#8217;t attribute the software to the group. Nevertheless, as Verify Level <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/2026\/thus-spoke-the-gentlemen\/\">famous<\/a>, a Gents affiliate named <span style=\"font-family: courier new, courier, monospace;\">quant<\/span> maintains a software known as <span style=\"font-family: courier new, courier, monospace;\">buildx641<\/span>, whose naming and performance instantly reminded us of OxideHarvest. Certainly, after additional investigation, we discovered an OxideHarvest pattern named <span style=\"font-family: courier new, courier, monospace;\">buildx641.exe<\/span> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.virustotal.com\/gui\/file\/95b46edaf566a13d118cb3452a65b024fddbcdcecfd9cfa61269239cf1909c13\">uploaded to VirusTotal<\/a>; we conclude that buildx641 and OxideHarvest are the identical software.<\/p>\n<p>OxideHarvest comes wrapped inside totally different packers, usually mimicking respectable software program in model info and icon (related, however not equivalent, to what Gents does with GentleKiller). The protected payload is a straightforward, easy credential stealer. To operate, OxideHarvest requires the consumer to specify the record of hosts (<span style=\"font-family: courier new, courier, monospace;\">-i<\/span>), username (<span style=\"font-family: courier new, courier, monospace;\">-u<\/span>), password (<span style=\"font-family: courier new, courier, monospace;\">-p<\/span>), variety of threads (<span style=\"font-family: courier new, courier, monospace;\">-t<\/span>), and an output file (<span style=\"font-family: courier new, courier, monospace;\">-o<\/span>) as command line choices. The software then makes use of the provided credentials to log into the required hosts (handed as a newline-delimited textual content file), employs multithreading, and exfiltrates credentials into the provided output file. Determine\u00a09 reveals the results of the <span style=\"font-family: courier new, courier, monospace;\">&#8211;help<\/span> command of OxideHarvest, and Desk\u00a05 reveals its configuration dictating which credentials are focused.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 3. The help of OxideHarvest\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/gentlemen\/figure-3.png\" alt=\"Figure 3. The help of OxideHarvest\" width=\"\" height=\"\"\/><figcaption><em>Determine 3. The assistance of OxideHarvest<\/em><\/figcaption><\/figure>\n<p style=\"text-align: center;\"><em>Desk\u00a05. Embedded configuration of OxideHarvest<\/em><\/p>\n<pre class=\"language-markup\" style=\"font-family: 'Courier New', Courier, monospace; font-size: 80%;\"><code>{\n    \"chronium_browsers\": [\n        [\n            \"Google Chrome\",\n            \"GoogleChromeUser Data\",\n            true\n        ],\n        [\n            \"Google Chrome Beta\",\n            \"GoogleChrome BetaUser Data\",\n            true\n        ],\n        [\n            \"ChromeBeta\",\n            \"GoogleChrome SxSUser Data\",\n            true\n        ],\n        [\n            \"Chromium\",\n            \"ChromiumUser Data\",\n            true\n        ],\n        [\n            \"Microsoft Edge\",\n            \"MicrosoftEdgeUser Data\",\n            true\n        ],\n        [\n            \"Torch\",\n            \"TorchUser Data\",\n            true\n        ],\n        [\n            \"Comodo\",\n            \"ComodoDragonUser Data\",\n            true\n        ],\n        [\n            \"Nichrome\",\n            \"NichromeUser Data\",\n            true\n        ],\n        [\n            \"Maxthon5\",\n            \"Maxthon5Users\",\n            true\n        ],\n        [\n            \"Epic Privacy Browser\",\n            \"Epic Privacy BrowserUser Data\",\n            true\n        ],\n        [\n            \"Vivaldi\",\n            \"VivaldiUser Data\",\n            true\n        ],\n        [\n            \"QIP\",\n            \"QIP SurfUser Data\",\n            true\n        ],\n        [\n            \"Cent\",\n            \"CentBrowserUser Data\",\n            true\n        ],\n        [\n            \"Elements\",\n            \"Elements BrowserUser Data\",\n            true\n        ],\n        [\n            \"TorBro\",\n            \"TorBroProfile\",\n            true\n        ],\n        [\n            \"CryptoTab\",\n            \"CryptoTab BrowserUser Data\",\n            true\n        ],\n        [\n            \"Brave\",\n            \"BraveSoftwareBrave-BrowserUser Data\",\n            true\n        ],\n        [\n            \"Opera\",\n            \"Opera SoftwareOpera Stable\",\n            false\n        ],\n        [\n            \"OperaGX\",\n            \"Opera SoftwareOpera GX Stable\",\n            false\n        ],\n        [\n            \"Opera Neon\",\n            \"Opera SoftwareOpera NeonUser Data\",\n            false\n        ]\n    ],\n    \"gecko_browsers\": [\n        [\n            \"Mozila Firefox\",\n            \"MozillaFirefoxProfiles\",\n            false\n        ],\n        [\n            \"Slim\",\n            \"FlashPeakSlimBrowserProfiles\",\n            false\n        ],\n        [\n            \"PaleMoon\",\n            \"Moonchild ProductionsPale MoonProfiles\",\n            false\n        ],\n        [\n            \"Waterfox\",\n            \"WaterfoxProfiles\",\n            false\n        ],\n        [\n            \"Cyberfox\",\n            \"8pecxstudiosCyberfoxProfiles\",\n            false\n        ],\n        [\n            \"BlackHawk\",\n            \"NETGATE TechnologiesBlackHawkProfiles\",\n            false\n        ],\n        [\n            \"IceCat\",\n            \"MozillaicecatProfiles\",\n            false\n        ],\n        [\n            \"KMeleon\",\n            \"K-Meleon\",\n            false\n        ]\n    ]\n}<\/code><\/pre>\n<h2>Conclusion<\/h2>\n<p>Gents demonstrates an attention-grabbing method: operator-managed EDR killers, prepared to make use of by associates. Whereas most ransomware gangs proceed to delegate EDR killing to associates, Gents has chosen to centralize this operate by providing associates a ready-to-use, standardized EDR-killer suite. This resolution makes Gents a sexy operator for associates because it materially lowers the entry barrier for them, making their job consequently simpler.<\/p>\n<p>This mannequin differs even from the few recognized exceptions within the ecosystem. Within the case of RansomHub, the operators invested in a single EDR killer, EDRKillShifter, developed totally in-house. Gents, in contrast, maintains a various portfolio of EDR killers, mixing authentic improvement (GentleKiller) with quickly tailored third-party or publicly disclosed tooling (HexKiller, ThrottleBlood, and HavocKiller). The constant software of protection evasion methods throughout these instruments additional obscures and complicates easy attribution when samples are noticed in isolation.<\/p>\n<p>As a result of EDR-killer methods proceed to commoditize and flow into throughout underground communities, this blogpost underscores the need of incident-level investigation and evaluation. With out such context, Gents\u2019s EDR killers are prone to be misattributed, or not attributed in any respect, masking the true extent of this operator\u2019s involvement. Due to our steady perception into Gents intrusions, we have been in a position to present safety in opposition to the group\u2019s assaults months earlier than the just lately leaked knowledge confirmed our high-confidence hypotheses on the gang\u2019s EDR-killer suite.<\/p>\n<p>The GentleKiller framework illustrates a deliberate stability between in-house improvement and pragmatic reuse of exterior analysis. Whereas some elements present indicators of rushed implementation or inconsistent polish, the general toolset demonstrates excessive operational effectiveness and tight integration into Gents\u2019s ransomware workflow. The group\u2019s capability to adapt newly printed BYOVD PoCs inside days additional underscores its agility.<\/p>\n<p>From a protection perspective, understanding how GentleKiller works permits defenders to higher design their defensive methods and defend even in opposition to yet-to-be-developed, new additions to Gents\u2019s EDR-killing arsenal.<\/p>\n<blockquote>\n<div><em>For any inquiries about our analysis printed on WeLiveSecurity, please contact us at <a rel=\"nofollow\" target=\"_blank\" style=\"background-color: #f4f4f4;\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/killing-me-gently-inside-gentlemens-edr-killer-framework\/mailto:threatintel@eset.com?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=eset-research&amp;utm_term=en\">threatintel@eset.com<\/a>.\u00a0<\/em><\/div>\n<div><em>ESET Analysis affords non-public APT intelligence studies and knowledge feeds. For any inquiries about this service, go to the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=killing-me-gently-inside-gentlemens-edr-killer-framework&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\">ESET Menace Intelligence<\/a> web page.<\/em><\/div>\n<\/blockquote>\n<h2>IoCs<\/h2>\n<h3>Information<\/h3>\n<table border=\"1\" width=\"643\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><strong>SHA-1<\/strong><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><strong>Filename<\/strong><\/td>\n<td style=\"width: 128.109px;\" width=\"123\"><strong>Detection<\/strong><\/td>\n<td style=\"width: 149.625px;\" width=\"218\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">8AE6BD18B129061F6364<wbr\/>2531F1B684CF0383C75D<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">Kasps.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (Kaspersky variant).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">BA914FE77B177B457994<wbr\/>03B16DD14765C510A074<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">eb.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/Agent.ITG<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">A customized rootkit utilized by the Kaspersky variant of GentleKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">D605994FC72A2BB59B5C<wbr\/>FB1624A1B9170ECA73A2<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">FaceIT1.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (FACEIT Anti-Cheat variant, Enigma-protected).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">B0B912A3FD1C05D72080<wbr\/>848EC4C92880004021A1<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">nseckrnl.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDriver<wbr\/>.NSecsoft.A<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">NSecsoft NSecKrnl driver abused by the FACEIT Anti-Cheat variant of GentleKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">5AA3124E5C4921E5EDFC<wbr\/>60133B5D71DA21B07DA3<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">Valorant2.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (Valorant variant, Themida-protected).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">7556AE58C215B8245A43<wbr\/>F764F0676C7A8F0FDD1A<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">vgk.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDriver<wbr\/>.PerfectWorld.A<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">Tower of Fantasy AntiCheat driver abused by the Valorant variant of GentleKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">331879F5EEC8892BBD89<wbr\/>6F90BDBB1BAD0BF63BD6<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">EASolo2Light.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (Javelin variant abusing Safetica\u2019s newer driver).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">F11AEBCCB9A86A7E2E65<wbr\/>3F90BAEC697F233C255F<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">EASOLO1clear.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (Javelin variant abusing Safetica\u2019s older driver).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">EF9CD06683159397F099<wbr\/>CAA244E94E6EAAD96EBA<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">EAAntiCheatLight<wbr\/>.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (Javelin variant abusing each drivers).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">711EF221526997039E80<wbr\/>4A18DB9647C91680BBE2<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">stpm_old.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDrive<wbr\/>r.Safetica.A<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">Safetica\u2019s Course of Monitor Driver (older) abused by the Javelin variant of GentleKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">68FEC379F2AE76C3D2CE<wbr\/>913F7BE650CEA1D06990<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">stpm_new.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDrive<wbr\/>r.Safetica.H<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">Safetica\u2019s Course of Monitor Driver (newer) abused by the Javelin variant of GentleKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">A11EE9CDC59E5CAA59AE<wbr\/>FD27B30D104F3AD68E62<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">BitD1.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (WatchDog variant, Themida-protected).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">96F0DBF52AED0AFD43E4<wbr\/>4500116B04B674F7358E<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">dmx.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDrive<wbr\/>r.WatchDogDev.C<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">Zemana\u2019s WatchDog Antimalware Driver abused by the WatchDog variant of GentleKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">2F86898528C6CAB3540C<wbr\/>486A9BFAA0C029B73950<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">MB2.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (Community Blocker variant, Themida-protected).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">9AD51AD97C01E97AB592<wbr\/>14116740785E0F6320A8<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">360netmon_wfp.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDrive<wbr\/>r.Qihoo360.A<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">360netmon.sys driver abused by the Community Blocker variant of GentleKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">A19117175DBC9BA4D23B<wbr\/>5DCE8415E299A2E32192<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">Deletor.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (Cleaner variant).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">12500F6C87CE62712A0E<wbr\/>D6652C57468D15C14223<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">IMFForceDelete<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDrive<wbr\/>r.IObit.D.gen<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">IMF ForceDelete filter driver abused by the Cleaner variant of GentleKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">D29670E684E40DDC89B4<wbr\/>7010C37CBC96737035B6<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">Symantec.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.EA<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">GentleKiller (G11 variant).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">56BEE9DF5833A637F5C5<wbr\/>4D5911DF98B0812FE643<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">G11.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/Agent.IYQ<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">PoisonX rootkit utilized by the G11 variant of GentleKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">CF4D74DF17A91B4A36A2<wbr\/>911B22AFEC5D8FA93A01<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">Avast.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win32\/KillAV.NVL<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">HexKiller integrated into Gents modus operandi by including the evasion layer.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">EC296F9501AD71E43081<wbr\/>0CB5CDC38D954D4BA536<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">googleApiUtil64<wbr\/>.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDrive<wbr\/>r.Baidu.B<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">Baidu Antivirus BdApi driver abused by HexKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">7131B377E96016DC1911<wbr\/>020C9F95B1B4D042D7B4<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">Despatched.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.AT<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">ThrottleBlood integrated into Gents modus operandi by including the evasion layer.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">82ED942A52CDCF120A89<wbr\/>19730E00BA37619661A3<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">ThrottleBlood.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDrive<wbr\/>r.GPUZ.B<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">ThrottleStop.sys driver abused by ThrottleBlood.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">F0537CBB773AE12100B3<wbr\/>6731E7C39F5A9D852B14<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">Sophos.exe<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/KillAV.DE<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">HavocKiller integrated into Gents modus operandi by including the evasion layer.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\" width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">1FA071303FB846308571<wbr\/>E64727501FB98B1C2BE6<\/span><\/td>\n<td style=\"width: 163.234px;\" width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">havoc.sys<\/span><\/td>\n<td style=\"width: 128.109px;\" width=\"123\">Win64\/VulnDrive<wbr\/>r.Huawei.D<\/td>\n<td style=\"width: 149.625px;\" width=\"218\">Weak driver abused by HavocKiller.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\"><span style=\"font-family: courier new, courier, monospace;\"><span style=\"font-family: courier new, courier, monospace;\">A5CF917EC4A7DFBDFA43<wbr\/>621398604805D860C718<\/span><\/span><\/td>\n<td style=\"width: 163.234px;\"><span style=\"font-family: courier new, courier, monospace;\">buildx641.exe<\/span><\/td>\n<td style=\"width: 128.109px;\">Win64\/Spy.Agent.AGC<\/td>\n<td style=\"width: 149.625px;\">OxideHarvest.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 192.031px;\"><span style=\"font-family: courier new, courier, monospace;\">D4B19141102015D43632<wbr\/>1E6F26976E98183CFD27<\/span><\/td>\n<td style=\"width: 163.234px;\"><span style=\"font-family: courier new, courier, monospace;\">buildx64.exe<\/span><\/td>\n<td style=\"width: 128.109px;\">Win64\/Spy.Agent.AGC<\/td>\n<td style=\"width: 149.625px;\">OxideHarvest.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>MITRE ATT&amp;CK methods<\/h2>\n<p>This desk was constructed utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/resources\/versions\/\"><em>model 19 <\/em><\/a>of the MITRE ATT&amp;CK framework.<\/p>\n<table style=\"height: 724px;\" border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"113\"><strong>Tactic<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"113\"><strong>ID<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"151\"><strong>Identify<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"265\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 104px;\">\n<td style=\"height: 208px;\" rowspan=\"2\" width=\"113\"><strong>Execution<\/strong><\/td>\n<td style=\"height: 104px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1059\/003\" target=\"_blank\" rel=\"noopener\">T1059.003<\/a><\/td>\n<td style=\"height: 104px;\" width=\"151\">Command and Scripting Interpreter: Home windows Command Shell<\/td>\n<td style=\"height: 104px;\" width=\"265\">GentleKiller and associated instruments are console-based executables that run visibly and emit debug strings throughout execution.<\/td>\n<\/tr>\n<tr style=\"height: 104px;\">\n<td style=\"height: 104px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1106\" target=\"_blank\" rel=\"noopener\">T1106<\/a><\/td>\n<td style=\"height: 104px;\" width=\"151\">Native API<\/td>\n<td style=\"height: 104px;\" width=\"265\">Person-mode elements work together straight with kernel drivers through <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/ioapiset\/nf-ioapiset-deviceiocontrol\">DeviceIoControl<\/a> and different native Home windows APIs to carry out privileged actions.<\/td>\n<\/tr>\n<tr style=\"height: 86px;\">\n<td style=\"height: 86px;\" width=\"113\"><strong>Persistence<\/strong><\/td>\n<td style=\"height: 86px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1543\/003\" target=\"_blank\" rel=\"noopener\">T1543.003<\/a><\/td>\n<td style=\"height: 86px;\" width=\"151\">Create or Modify System Course of: Home windows Service<\/td>\n<td style=\"height: 86px;\" width=\"265\">The EDR killers set up and begin weak or malicious drivers as providers previous to exploitation.<\/td>\n<\/tr>\n<tr style=\"height: 104px;\">\n<td style=\"height: 294px;\" rowspan=\"3\" width=\"113\"><strong>Stealth<\/strong><\/td>\n<td style=\"height: 104px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1036\" target=\"_blank\" rel=\"noopener\">T1036<\/a><\/td>\n<td style=\"height: 104px;\" width=\"151\">Masquerading<\/td>\n<td style=\"height: 104px;\" width=\"265\">Gents\u2019s EDR killers are protected by impersonating respectable distributors by filenames, model info, icons, and copied digital certificates.<\/td>\n<\/tr>\n<tr style=\"height: 104px;\">\n<td style=\"height: 104px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1036\/001\" target=\"_blank\" rel=\"noopener\">T1036.001<\/a><\/td>\n<td style=\"height: 104px;\" width=\"151\">Masquerading: Invalid Code Signature<\/td>\n<td style=\"height: 104px;\" width=\"265\">The safety utilized to Gents\u2019s EDR killers provides an invalid code signature as a part of the impersonation technique.<\/td>\n<\/tr>\n<tr style=\"height: 86px;\">\n<td style=\"height: 86px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1027\" target=\"_blank\" rel=\"noopener\">T1027<\/a><\/td>\n<td style=\"height: 86px;\" width=\"151\">Obfuscated Information or Data<\/td>\n<td style=\"height: 86px;\" width=\"265\">Some executables are protected with packers (e.g., Enigma, Themida) and customized control-flow obfuscation.<\/td>\n<\/tr>\n<tr style=\"height: 86px;\">\n<td style=\"height: 86px;\" width=\"113\"><strong>Protection Impairment<\/strong><\/td>\n<td style=\"height: 86px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1685\/\" target=\"_blank\" rel=\"noopener\">T1685<\/a><\/td>\n<td style=\"height: 86px;\" width=\"151\">Disable or Modify Instruments<\/td>\n<td style=\"height: 86px;\" width=\"265\">GentleKiller and different EDR killers that Gents is in possession of goal to bypass safety merchandise reminiscent of EDRs.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=killing-me-gently-inside-gentlemens-edr-killer-framework&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/eti-eset-threat-intelligence.png\" alt=\"\" width=\"915\" height=\"296\"\/><\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>ESET researchers analyzed the sturdy EDR-killing toolset of the ransomware-as-a-service gang Gents. For the reason that starting of 2026, Gents has emerged as one of the crucial lively gangs within the ransomware ecosystem. The group distinguishes itself by a mature, operator-maintained set of endpoint detection and response (EDR) killers, i.e., instruments for disrupting safety software [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15905,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[628,635,9478,4620],"class_list":["post-15903","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-edr","tag-framework","tag-gentlemens","tag-killer"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15903","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15903"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15903\/revisions"}],"predecessor-version":[{"id":15904,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15903\/revisions\/15904"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15905"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15903"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15903"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15903"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-20 18:50:51 UTC -->