GentleKiller is an in-house endpoint security disabling framework used by the The Gentlemen ransomware-as-a-service operation and distributed to affiliates as a standardized pre-encryption defense-evasion capability. It is designed to disable antivirus and EDR products at kernel level before ransomware deployment, distinguishing The Gentlemen from many other ransomware programs that leave such tooling to affiliates.
The framework uses bring-your-own-vulnerable-driver techniques to load legitimately signed but vulnerable or malicious kernel drivers, then abuses those drivers to terminate or otherwise impair security software. Public reporting attributes at least eight GentleKiller variants to the framework, each masquerading as a different legitimate product while using a different driver. Across observed variants, GentleKiller targets more than 400 process names associated with roughly 48 security products, and repeatedly scans for and kills matching processes in a persistent loop. Variants have been documented abusing drivers associated with products from vendors including Kaspersky, FACEIT Anti-Cheat, Riot Valorant, Javelin or Safetica, Zemana, Qihoo 360, and IObit, as well as the PoisonX rootkit.
GentleKiller binaries share a common evasion layer that uses vendor impersonation, fabricated version metadata, copied but invalid signatures, matching icons, and commercial protectors such as Enigma or Themida to hinder inspection and attribution. The framework has also been noted for rapid operationalization of newly disclosed BYOVD proof-of-concepts, indicating an agile development pipeline. In addition to GentleKiller, The Gentlemen has operationally integrated other externally sourced EDR-killing tools into its broader ecosystem, but GentleKiller is the primary internally developed framework.
GentleKiller is associated with ransomware intrusions targeting organizations across Southeast Asia, South America, and Western Europe, reflecting The Gentlemen’s broader victimology and target-selection practices. It runs on Windows systems and functions as a specialized anti-security utility used during the early stages of ransomware operations to clear the way for follow-on credential theft, lateral movement, data exfiltration, and encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ESET documents GentleKiller's Cleaner variant dropping this driver without the trailing .sys extension, and CVE-2019-6494 describes IOCTL 0x8016E000 allowing low-privileged users to delete files regardless of access controls.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New analysis from ESET detailed the endpoint detection and response (EDR) killer suite of The Gentlemen, built around an in-house framework the researchers named GentleKiller. GentleKiller's job is to disable endpoint protection.
Operational ownership does not imply common code authorship. G12 and G13 show technical continuity with the GentleKiller line.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell GentleKiller and related tools are console-based executables that run visibly and emit debug strings during execution.
T1106 Native API User-mode components interact directly with kernel drivers via DeviceIoControl and other native Windows APIs to perform privileged actions.
The method is called bring your own vulnerable driver (BYOVD). Each build loads a legitimately signed but flawed kernel driver, then abuses it to kill security processes from inside the kernel, beyond the reach of user-mode protections.
Use Case Privileges Operating System Impair defenses through a signed kernel driver abused by an EDR killer.
T1027 Obfuscated Files or Information Some executables are protected with packers (e.g., Enigma, Themida) and custom control-flow obfuscation.
To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.
ESET counted at least eight GentleKiller variants, each impersonating a different legitimate product, with names lifted from games and security brands such as Valorant, FACEIT and Kaspersky... To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.
T1036.001 Masquerading: Invalid Code Signature The protection applied to Gentlemen’s EDR killers adds an invalid code signature as part of the impersonation strategy.
It either terminates each running process directly, unloads the EDR’s own kernel driver, deletes service registry keys to prevent restart, or all three.
Delete protected files and impair defenses through a vulnerable kernel driver.
He just hands Windows a file the system already trusts... a trusted-but-flawed file... Windows will still happily load it.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related kernel-assisted killer family referenced as the earlier or broader line to which G12 and G13 are compared. It is described as sharing periodic process scanning, a broad security-product target list, consistent obfuscation, and multiple variants built around different drivers.
A bring-your-own-vulnerable-driver (BYOVD) framework used to load obscure, legitimately signed vulnerable drivers in order to bypass driver blocklists and facilitate kernel-level compromise or security control disablement.
An offensive framework referenced for technique overlap with Cruciferra's BYOVD approach.
A tool associated with The Gentlemen RaaS that bundles multiple drivers, including PoisonX.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.