HexKiller
HexKiller is an externally sourced or leaked EDR-killing tool used in ransomware intrusions. ESET reported it as part of the Gentlemen ransomware-as-a-service group’s standardized EDR-killer suite provided to affiliates, alongside ThrottleBlood and HavocKiller. Gentlemen wraps these third-party tools in a shared defense-evasion layer that impersonates trusted, predominantly security, vendors using fake version information, copied or invalid signatures, legitimate-looking certificates and icons, and in many cases commercial packers such as Enigma or Themida to hinder detection and analysis. HexKiller had previously been tied to the Warlock gang. The content also notes that HexKiller is one of several independent projects using the Baidu Antivirus driver BdApiUtil.sys, indicating BYOVD-style defensive evasion. High-confidence details in the provided content do not further specify HexKiller’s standalone infection vector, target industries, or distinct process-killing scope beyond its role as an EDR killer used by ransomware operators.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group also incorporates third-party or leaked tools named HexKiller, ThrottleBlood and HavocKiller.
The suite also carries three tools that Gentlemen obtained from outside sources. HexKiller had been tied to the Warlock gang.
The suite also carries three tools that Gentlemen obtained from outside sources. HexKiller had been tied to the Warlock gang.
Techniques & procedures
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Privilege Escalation
1 technique
Privilege Escalation
Stealth
3 techniques
Stealth
Many samples also receive commercial packing through Enigma or Themida, recorded in a filename suffix.
Defense Impairment
1 technique
Defense Impairment
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An externally sourced EDR-killer tool used within Gentlemen’s tooling suite; previously associated with the Warlock gang.
A third-party or leaked EDR-killing tool incorporated into The Gentlemen ransomware group's standardized defense-evasion toolkit.
A third-party or leaked EDR-killing tool incorporated into The Gentlemen ransomware group's standardized defense-evasion toolkit.
Independent EDR killer codebase that abuses the Baidu Antivirus driver BdApiUtil.sys.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.