GentleKiller is an in-house endpoint detection and response (EDR) killer framework operated and supplied to affiliates by the The Gentlemen ransomware-as-a-service ecosystem. It is designed to disable endpoint protection before ransomware deployment. At least eight variants have been observed, sharing process-targeting and evasion characteristics while impersonating legitimate security, anti-cheat, and enterprise software products.
GentleKiller employs bring-your-own-vulnerable-driver techniques, loading legitimately signed but vulnerable kernel drivers, and in some variants malicious drivers or rootkits, to obtain kernel-level capabilities for terminating protected security processes. Its process-target list covers more than 400 process names associated with approximately 48 security products, including major antivirus and EDR platforms. Variants repeatedly scan for and terminate targeted processes, suppressing recovery of endpoint defenses.
The framework uses a common masquerading layer, including vendor-like presentation, fabricated version metadata, invalid copied signatures, matching icons, and commercial packers. The Gentlemen operators have demonstrated rapid integration of newly disclosed vulnerable-driver exploitation techniques into the framework. GentleKiller is principally associated with Windows ransomware intrusions and is used as a defense-evasion component preceding data theft and ransomware encryption by The Gentlemen affiliates.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ESET documents GentleKiller's Cleaner variant dropping this driver without the trailing .sys extension, and CVE-2019-6494 describes IOCTL 0x8016E000 allowing low-privileged users to delete files regardless of access controls.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET said in June that the group had begun using a new endpoint detection and response killer called GentleKiller.
EDR killers (BYOVD) — ESET a documenté en juin 2026 la fourniture aux affiliés d’une suite d’outils exploitant des drivers vulnérables. Variantes observées par la CTU : GentleKiller – Watchdog, GentleKiller – Javelin, GentleKiller – G11 et GentleKiller – FACEIT Anti-Cheat.
Operational ownership does not imply common code authorship. G12 and G13 show technical continuity with the GentleKiller line.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell GentleKiller and related tools are console-based executables that run visibly and emit debug strings during execution.
T1106 Native API User-mode components interact directly with kernel drivers via DeviceIoControl and other native Windows APIs to perform privileged actions.
The method is called bring your own vulnerable driver (BYOVD). Each build loads a legitimately signed but flawed kernel driver, then abuses it to kill security processes from inside the kernel, beyond the reach of user-mode protections.
Use Case Privileges Operating System Impair defenses through a signed kernel driver abused by an EDR killer.
T1027 Obfuscated Files or Information Some executables are protected with packers (e.g., Enigma, Themida) and custom control-flow obfuscation.
To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.
ESET counted at least eight GentleKiller variants, each impersonating a different legitimate product, with names lifted from games and security brands such as Valorant, FACEIT and Kaspersky... To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.
T1036.001 Masquerading: Invalid Code Signature The protection applied to Gentlemen’s EDR killers adds an invalid code signature as part of the impersonation strategy.
It either terminates each running process directly, unloads the EDR’s own kernel driver, deletes service registry keys to prevent restart, or all three.
The RaaS operators provide affiliates with a suite of custom and publicly available EDR-killing tools that abuse vulnerable drivers via the BYOVD (Bring Your Own Vulnerable Driver) technique.
He just hands Windows a file the system already trusts... a trusted-but-flawed file... Windows will still happily load it.
Attackers staged tools in the C:\PerfLogs directory ... not commonly scrutinized by security controls or administrators.
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Endpoint detection-and-response security-tool killer reportedly adopted by the Gentlemen ransomware group.
An endpoint detection and response (EDR) security-tool disabling utility reportedly employed by The Gentlemen ransomware group.
Suite d’outils de neutralisation EDR fournie aux affiliés de The Gentlemen. Elle abuse de pilotes vulnérables (BYOVD) et se décline notamment en variantes déguisées en composants anti-triche ou Watchdog afin de désactiver les défenses avant le chiffrement.
Ransomware ecosystem associated with defense evasion through vulnerable drivers and tooling intended to disable endpoint detection and response protections before ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.