Welivesecurity
Gentlemen Ransomware Uses Advanced EDR Killers to Evade Detection
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Gentlemen ransomware-as-a-service (RaaS) gang has developed a sophisticated suite of endpoint detection and response (EDR) killers, including a tool called GentleKiller, which has at least eight variants. These tools are designed to disable security defenses during attacks, targeting over 400 processes associated with 48 security products. The group has been particularly active in 2026, focusing on victims in Southeast Asia, South America, and Western Europe. An internal data leak in May 2026 provided insights into their operations, confirming the use of both proprietary and third-party EDR killers. Gentlemen employs the 'bring your own vulnerable driver' (BYOVD) technique to elevate privileges and disable security engines. The gang has also been linked to previous attacks, including a compromise of the Romanian energy provider Oltenia. Security teams report that only 14% of successful attacks trigger alerts, indicating a significant evasion capability. The threat landscape remains critical as Gentlemen continues to refine its tools and tactics.
Key Points: • Gentlemen RaaS has developed multiple EDR-killing tools, including GentleKiller with at least eight variants. • The gang targets over 400 processes from 48 security vendors, employing advanced evasion techniques. • An internal data leak revealed insights into their operations and tool development practices.