Welivesecurity Gentlemen Ransomware Uses Advanced EDR Killers to Evade Detection
Article Content
- •Gentlemen RaaS has developed multiple EDR-killing tools, including GentleKiller with at least eight variants.
- •The gang targets over 400 processes from 48 security vendors, employing advanced evasion techniques.
- •An internal data leak revealed insights into their operations and tool development practices.
The Gentlemen ransomware-as-a-service (RaaS) gang has developed a sophisticated suite of endpoint detection and response (EDR) killers, including a tool called GentleKiller, which has at least eight variants. These tools are designed to disable security defenses during attacks, targeting over 400 processes associated with 48 security products. The group has been particularly active in 2026, focusing on victims in Southeast Asia, South America, and Western Europe. An internal data leak in May 2026 provided insights into their operations, confirming the use of both proprietary and third-party EDR killers. Gentlemen employs the 'bring your own vulnerable driver' (BYOVD) technique to elevate privileges and disable security engines. The gang has also been linked to previous attacks, including a compromise of the Romanian energy provider Oltenia. Security teams report that only 14% of successful attacks trigger alerts, indicating a significant evasion capability. The threat landscape remains critical as Gentlemen continues to refine its tools and tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (25)
Following this threat?
Track Gentlemen, DemoKiller and Complexul Energetic Oltenia in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Rise of AI-Powered Ransomware Threatens Multiple Sectors Recent research reveals the emergence of AI-driven ransomware, significantly lowering the cost and expertise needed for cybercriminals to launch attacks. An exposed server linked to the Gentlemen ransomware group contained 3.1 terabytes of stolen data from over 30 organizations across various sectors, including…
Veradigm Data Breach Exposes Patient Information via Vendor Compromise Veradigm, a healthcare technology company, reported a data breach involving a third-party vendor's systems, where hackers accessed personal data, including Social Security numbers, of some patients. The breach was disclosed in an 8-K filing with the SEC on September 8, 2026. The unauthorized party obtained credentials…