HexKiller is a Windows BYOVD-based EDR-killing utility used in ransomware intrusions to disable endpoint security products before follow-on actions such as data theft or ransomware deployment. It has been associated with the Warlock ransomware ecosystem and was later observed as part of The Gentlemen affiliate-facing evasion toolkit, where it was staged alongside the group’s in-house GentleKiller framework and standardized with a shared disguise and packing layer.
Its core function is defense evasion: it loads an abused signed but vulnerable kernel driver and uses kernel-level access to terminate or interfere with security processes, allowing attackers to suppress EDR and antivirus protections that would otherwise hinder intrusion activity. Reporting places HexKiller among externally sourced tools incorporated by The Gentlemen rather than malware developed in-house by that group. In Gentlemen operations, it was one of several third-party EDR killers integrated into a modular suite that also included other borrowed tools, reflecting a broader trend of ransomware operators and affiliates reusing interchangeable BYOVD utilities.
HexKiller targets Windows environments and is relevant primarily in post-compromise ransomware tradecraft, where privileged attackers deploy it after initial access to weaken host defenses. Its observed use by multiple ransomware-linked actors and its reliance on vulnerable-driver abuse make it notable as part of the wider ecosystem of kernel-assisted security-disabling tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gentlemen offers a whole portfolio: GentleKiller, the in-house framework, in at least eight variants HexKiller, previously tied to the Warlock gang.
Gentlemen offers a whole portfolio: GentleKiller, the in-house framework, in at least eight variants HexKiller, previously tied to the Warlock gang.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
ESET’s assessment is that all three were acquired externally by the operators and then standardized with the same defense evasion layer applied to GentleKiller: binary protection via Enigma or Themida, filenames mimicking security vendors, fabricated version information, copied digital signatures, and matching icons.
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell GentleKiller and related tools are console-based executables that run visibly and emit debug strings during execution.
T1027 Obfuscated Files or Information Some executables are protected with packers (e.g., Enigma, Themida) and custom control-flow obfuscation.
To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.
Stealth T1036 Masquerading Gentlemen’s EDR killers are protected by impersonating legitimate vendors through filenames, version information, icons, and copied digital certificates.
T1036.001 Masquerading: Invalid Code Signature The protection applied to Gentlemen’s EDR killers adds an invalid code signature as part of the impersonation strategy.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A third-party BYOVD EDR killer integrated into The Gentlemen's evasion stack.
A named EDR-killer tool included in the Gentlemen toolkit portfolio and previously associated with the Warlock gang.
An externally sourced EDR killer absorbed into Gentlemen’s tooling suite and fitted with Gentlemen’s evasion layer. It abuses the Baidu Antivirus BdApi driver to disable endpoint protections.
An externally sourced EDR killer integrated into Gentlemen’s affiliate suite. It abuses a Baidu Antivirus driver to disable defenses and was previously attributed exclusively to the Warlock gang.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.