Infoglobez
Live Coverage
Sign in Sign up
Trending: Champions League Transfer News Premier League World Cup
Infoglobez
AI & ML

Ransomware Group Enhances Toolkit with EDR Disabling Tools

The Gentlemen ransomware group now equips affiliates with advanced tools to bypass enterprise security systems, raising concerns for IT defenses.

Jun 19, 2026 | 3 min read
Sign in to save

Recent findings from ESET reveal that The Gentlemen, a prominent ransomware group, has equipped its affiliates with advanced capabilities to disable many enterprise endpoint detection and response (EDR) solutions. This move allows them to amplify their impact on victims by overcoming existing security measures. The stakes in cyber defenses are rising, and groups like The Gentlemen are pushing the envelope, posing significant risks to enterprises that think they're well-protected.

The Rise of The Gentlemen

Since adopting this name last year, The Gentlemen have emerged as a formidable player in the ransomware-as-a-service (RaaS) scene. What sets them apart from other groups is their appealing revenue-sharing model that offers affiliates an impressive 90/10 profit split. This not only incentivizes participation but also invites a broader range of actors into the ransomware marketplace, including those without deep technical expertise. In May, a breach of the group's servers by an unknown entity exposed internal materials that researchers have since analyzed, shedding light on their evolving tactics and the industrialization of cybercrime.

This highlights a concerning trend: as affiliates access more effective tools and support, the overall security environment becomes more challenging. The Gentlemen capitalize on the growing vulnerability landscape, pushing new affiliates into action while simultaneously complicating defense strategies for targeted organizations. It's a vicious cycle where better tools for attackers translate into greater risks for potential victims.

Understanding the EDR Killer Framework

One of the key discoveries from ESET's research revolves around the group’s focus on EDR killers—tools designed to bypass or disable security agents on PCs and servers during cyber incidents. While these tools aren't entirely new, their increasing sophistication has made them integral to successful ransomware operations. Historically, creating or sourcing an effective EDR killer was a significant challenge for affiliates, but this has now changed dramatically.

Introduction of GentleKiller Framework

The recent leak confirmed ESET’s earlier suspicions regarding The Gentlemen's development of an EDR killer framework known as 'GentleKiller.' This framework democratizes access to sophisticated EDR bypass tools, enabling affiliates to use them without needing extensive technical know-how or resources. This shift not only broadens the base of potential attackers but also complicates the defensive posture of enterprises that would typically rely on traditional security measures.

The Gentlemen have also incorporated established third-party tools like HexKiller, ThrottleBlood, and HavocKiller into their offerings, showcasing a disturbing trend where malware is increasingly modular and plug-and-play. As ESET researcher Jakub Souček outlines, this expansion in available tools increases the number of potential affiliates and facilitates more consistent deployment of ransomware, meaning enterprises face a growing number of threats from various skilled attackers.

BYOVD Technique Explained

A significant feature of the GentleKiller framework is its ability to utilize "bring your own vulnerable driver" (BYOVD) strategies. The eight variants of tools include methods to quickly deploy proofs-of-concept that grant kernel-level access by loading vulnerable drivers into memory. The BYOVD principle is relatively straightforward: after successfully gaining administrative control, attackers load outdated, legitimate drivers containing exploitable vulnerabilities, thereby extending their control up to kernel levels. This control directly enables them to target and disable EDR systems.

Research corroborating this vulnerability has emerged over time. Studies have highlighted the weaknesses in EDR defenses, and recent reports indicate that attacks leveraging BYOVD techniques are being increasingly adopted to disrupt EDR solutions by exploiting outdated drivers. (And this is the part most people overlook.) The ease with which an attacker can utilize legitimate tools to achieve malicious ends raises questions about the reliability of current security measures.

Defensive Measures

Souček indicates that the primary defense challenge stems from the necessity of using non-malicious drivers that remain legitimate. The complexity of managing drivers is compounded by the need to stay ahead of attackers who continually innovate. To combat these tactics, enterprises should implement protective measures like Hypervisor-Protected Code Integrity (HVCI) and Kernel-mode Code Integrity (KMCI), which complicate the loading of obsolete or unsafe drivers.

However, defensive strategies can't afford to be reactive; they need to be proactive. Companies should enforce strict driver policies that include continuous audits, elimination of unnecessary drivers, and regular updates or removals of vulnerable ones. Prevention is key—restricting the installation of unsafe drivers significantly diminishes the effectiveness of EDR killer tools.

Implications and Future Outlook

What this means for you, if you're working in this space, is that ransomware threats are increasingly sophisticated and accessible. The combination of refined EDR killing techniques with a lower barrier to entry for affiliates could mark a new phase of ransomware attacks that are more frequent and damaging. Cybersecurity isn't just a technical requirement anymore; it’s a boardroom priority.

Companies must prepare and adapt their security measures to counter these emerging strategies. As groups like The Gentlemen continue to evolve, so must defensive tactics. It's not just about having the latest tools but understanding the threat landscape and being agile enough to respond quickly. Organizations must invest in both technology and training, fostering a culture of security awareness that keeps employees vigilant against these rising threats.

Source: Robert Johnson · www.csoonline.com
Sign in to join the discussion.