Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 2 actors

GentleKiller

GentleKiller is a self-developed endpoint detection and response (EDR) killer used by the Gentlemen ransomware-as-a-service group and described as the most prevalent EDR-killing tool in that ecosystem. It was first observed in a staging directory named GentlemenCollection and is assessed as the only EDR killer in the suite developed in-house by Gentlemen operators, who centrally maintain and distribute EDR-killer packages to affiliates.

ESET reported at least eight GentleKiller variants. Each variant impersonates a different legitimate product and abuses a different vulnerable or malicious kernel driver. Observed variants include Kaspersky, FACEIT Anti-Cheat, Valorant, Javelin, WatchDog, Network Blocker, Cleaner, and G11. The associated abused drivers mentioned in the reporting include eb.sys, nseckrnl.sys, GameDriverX64.sys, stpm_old.sys, stpm_new.sys, dmx.sys, 360netmon_wfp.sys, IObit’s IMF ForceDelete filter driver, and PoisonX. The malware targets more than 400 process names mapped to 48 security products, including products from Microsoft Defender, CrowdStrike, SentinelOne, Sophos, Trend Micro, ESET, and Palo Alto Networks.

Across variants, GentleKiller reportedly shares the same underlying characteristics, including a timer-based or periodic process-termination loop, shared strings, and identical code obfuscation, indicating a reused development template. The broader Gentlemen evasion model also uses vendor-like filenames, fabricated version information, copied invalid digital signatures, matching legitimate-looking icons, and sometimes Enigma or Themida packing to hinder detection and analysis.

GentleKiller is associated with the Gentlemen ransomware group, which emerged in late 2025 and became highly active in 2026. Gentlemen uses double extortion and targets organizations globally, with reported victim concentrations in Southeast Asia, South America, and Western Europe, including Thailand, Brazil, and France. Reporting states victim selection is driven primarily by FortiGate misconfigurations rather than geography. High-confidence indicators in the content are primarily the malware name, its observed variant names, and the abused driver filenames listed above.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Gentlemen

GentleKiller is by far the most prevalent EDR killer observed in the Gentlemen ecosystem. At the time of writing, we are aware of at least eight distinct variants, each impersonating a different legitimate product and abusing a different vulnerable or malicious driver.

via eset welivesecurity blogwelivesecurity.com
The Gentlemen

The most prevalent EDR killer in the group's ecosystem is GentleKiller, a self-developed tool with at least eight variants targeting more than 400 processes.

via govinfosecuritygovinfosecurity.com
MITRE ATT&CK

Techniques & procedures

13 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

2 techniques
T1059.003Windows Command ShellEvidence1

MITRE ATT&CK techniques ... T1059.003 Command and Scripting Interpreter: Windows Command Shell GentleKiller and related tools are console-based executables that run visibly and emit debug strings during execution.

T1106Native APIEvidence1

MITRE ATT&CK techniques ... T1106 Native API User-mode components interact directly with kernel drivers via DeviceIoControl and other native Windows APIs to perform privileged actions.

Persistence

1 technique
T1543.003Windows ServiceEvidence1

MITRE ATT&CK techniques ... T1543.003 Create or Modify System Process: Windows Service The EDR killers install and start vulnerable or malicious drivers as services prior to exploitation.

Privilege Escalation

1 technique
T1543.003Windows ServiceEvidence1

MITRE ATT&CK techniques ... T1543.003 Create or Modify System Process: Windows Service The EDR killers install and start vulnerable or malicious drivers as services prior to exploitation.

Stealth

6 techniques
T1027Obfuscated Files or InformationEvidence3

MITRE ATT&CK techniques ... T1027 Obfuscated Files or Information Some executables are protected with packers (e.g., Enigma, Themida) and custom control-flow obfuscation.

T1027.002Software PackingEvidence1

Many samples also receive commercial packing through Enigma or Themida, recorded in a filename suffix.

T1036MasqueradingEvidence4

MITRE ATT&CK techniques ... T1036 Masquerading Gentlemen’s EDR killers are protected by impersonating legitimate vendors through filenames, version information, icons, and copied digital certificates.

T1036.001Invalid Code SignatureEvidence1

MITRE ATT&CK techniques ... T1036.001 Masquerading: Invalid Code Signature The protection applied to Gentlemen’s EDR killers adds an invalid code signature as part of the impersonation strategy.

T1070.004File DeletionEvidence2

The overarching defense-evasion strategy includes applying advanced protection to executable files, spoofing trusted vendors' identities and manipulating file attributes to make the EDR-killing tools harder to detect and analyze.

T1211Exploitation for Defense EvasionEvidence3

Although each variant impersonates a different legitimate product and abuses a different vulnerable or malicious driver ... It allows the operators to incorporate newly abused drivers into their toolset within days of a proof of concept being disclosed.

Defense Impairment

1 technique
T1553.002Code SigningEvidence1

These tools are standardized through a shared defense-evasion layer, impersonating predominantly security vendors using fake version information, and copied through legitimate certificates and icons.

Impact

1 technique
T1489Service StopEvidence1

Although each variant impersonates a different legitimate product and abuses a different vulnerable or malicious driver, they all share the same underlying characteristics, including terminating processes periodically ...

Other

2 techniques
T1562Impair DefensesEvidence3

The Gentlemen Ransomware Gang Standardizes EDR Killing ... researchers who found that the extortionists have turned EDR killing into a tactical advantage.

T1562.001Disable or Modify ToolsEvidence1

The most prevalent EDR killer in the group's ecosystem is GentleKiller, a self-developed tool with at least eight variants targeting more than 400 processes... they all share the same underlying characteristics, including terminating processes periodically.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

help net securityNews
Jun 18, 2026
GentleKiller targets more than 400 security processes across 48 products - Help Net Security

An in-house EDR-killer framework used by the Gentlemen ransomware operation to disable endpoint detection and response products. It has at least eight variants, impersonates legitimate security products, abuses vulnerable or malicious kernel drivers, and targets more than 400 process names associated with 48 security products.

Read more
bank info securityNews
Jun 18, 2026
The Gentlemen Ransomware Gang Standardizes EDR Killing

A self-developed endpoint detection and response killing tool used in The Gentlemen ransomware ecosystem. It has at least eight variants, targets more than 400 processes, periodically terminates processes, uses identical code obfuscation across variants, impersonates legitimate products, and abuses different vulnerable or malicious drivers.

Read more
govinfosecurityNews
Jun 18, 2026
The Gentlemen Ransomware Gang Standardizes EDR Killing

A self-developed endpoint security disabling tool used by The Gentlemen ransomware ecosystem. It has at least eight variants, impersonates legitimate products, abuses different vulnerable or malicious drivers, periodically terminates processes, and uses code obfuscation to evade detection.

Read more
eset welivesecurity blogNews
Jun 18, 2026
Killing me gently: Inside Gentlemen’s EDR killer framework

An in-house EDR-killing framework used by the Gentlemen ransomware operation to disable or terminate security products by abusing vulnerable or malicious drivers. It is offered to affiliates and has multiple variants impersonating legitimate software vendors.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping13

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.