Ransomware operators have been observed using bring-your-own-vulnerable-driver (BYOVD) techniques and custom anti-security tools to shut down endpoint protections before encrypting enterprise networks. Kaspersky documented a MedusaLocker intrusion in Brazil in which attackers accessed an SMTP server over RDP with valid administrative credentials, used Mimikatz to extract NTLM hashes, and moved laterally with pass-the-hash via PowerShell-based WMI and SMB execution before deploying a new AV-killer tool, All.exe. That tool loaded a renamed TechPowerUp ThrottleStop.sys driver (ThrottleBlood.sys), exploited vulnerable IOCTLs for physical memory read/write, hijacked kernel execution through NtAddAtom, and repeatedly terminated products from Microsoft Defender, CrowdStrike, SentinelOne, Sophos, Symantec, Bitdefender, ESET, Avast, AVG, McAfee, Panda, Quick Heal, and Kaspersky; the driver issue was assigned CVE-2025-7771.
A separate report on The Gentlemen ransomware described a similar pattern in enterprise attacks across the Asia-Pacific region, where the group likely gained entry through an exposed FortiGate device or stolen credentials, then conducted Active Directory reconnaissance, used PsExec for lateral movement, established persistence with AnyDesk, abused GPO and NETLOGON for domain-wide deployment, and exfiltrated data with WinSCP for double extortion. TrendAI said the group evolved from generic anti-AV tooling to customized variants tailored to the security products installed in each victim environment, while also disabling Windows Defender and recovery mechanisms before dropping README-GENTLEMEN.txt and encrypting files with the .7mtzhh extension. Together, the incidents show ransomware crews increasingly pairing credential abuse and lateral movement with vulnerable-driver abuse and bespoke defense evasion to maximize encryption success.

Get the actors, campaigns, and ATT&CK mapping behind it.
11 events from the most recent confirmed update back to the earliest known activity.
Before encryption, the attackers disabled Windows Defender real-time monitoring, added exclusions, enabled Remote Desktop access, and distributed the ransomware through the domain NETLOGON share. The payload dropped README-GENTLEMEN.txt and appended the .7mtzhh extension to encrypted files.
The investigation found likely staging of collected files in C:\ProgramData\data, numerous WebDAV connections, and probable exfiltration with WinSCP over encrypted channels, including transfers of sensitive internal documentation.
The attackers used PsExec for lateral movement, installed AnyDesk for persistent access, modified registry settings affecting NTLM, Restricted Admin, and RDP security, and used Group Policy tools to push malicious configurations across the domain.
The group initially used All.exe with ThrottleBlood.sys to kill protected security processes, later used PowerRun.exe for high-privilege disabling of defenses, and introduced a customized tool named Allpatch2.exe to target specific security agents in victim environments.
During the August 2025 campaign, the attackers used Advanced IP Scanner, mass account enumeration scripts, encoded PowerShell to identify the PDC, and Nmap executed from a compromised FortiGate administrative account to map the environment.
The investigation found an internet-accessible FortiGate server likely served as the attackers' entry point, though compromised credentials were also considered a possible initial access vector.
Trend Micro investigated an August 2025 ransomware campaign attributed to The Gentlemen, an emerging and previously undocumented group targeting enterprise environments across 17 countries, especially in the Asia-Pacific region.
Kaspersky said the AV-killer tool abusing the vulnerable ThrottleStop.sys driver had been observed in real-world attacks since at least October 2024, with victims concentrated in Russia, Belarus, Kazakhstan, Ukraine, and Brazil.
The legitimate TechPowerUp ThrottleStop.sys driver later abused in BYOVD attacks was signed with a valid DigiCert EV Code Signing certificate.
Kaspersky reported that the vulnerable driver issue in ThrottleStop.sys was assigned CVE-2025-7771 and said the vendor was preparing a patch.
In a Brazil ransomware intrusion, attackers accessed a mail server over RDP with valid administrative credentials, used Mimikatz and pass-the-hash for lateral movement, disabled endpoint protections with All.exe and the renamed ThrottleBlood.sys driver, and then deployed a MedusaLocker variant.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.