GentleKiller is an in-house endpoint security disabling framework used by the Gentlemen ransomware-as-a-service operation, also tracked as Storm-2697. It is designed to neutralize antivirus and EDR protections prior to follow-on intrusion activity and ransomware deployment. The framework has been observed in at least eight variants, each masquerading as a different legitimate product while abusing a different vulnerable or malicious signed kernel driver through Bring Your Own Vulnerable Driver techniques. Reported variants target more than 400 security-related processes associated with 48 endpoint products.
Operationally, GentleKiller installs and starts a kernel-mode driver as a Windows service, then communicates with that driver through native Windows interfaces to obtain privileged kernel capabilities. Depending on the variant and driver, those capabilities enable direct process termination, unloading or disabling of security components, and deletion of protected files. Multiple variants reportedly maintain a recurring scan-and-kill loop at short intervals to suppress recovery of terminated security software. The framework has also been described as sharing common strings, obfuscation patterns, and process-killing logic across variants, indicating a reusable development template that allows rapid substitution of newly abused drivers.
GentleKiller is closely associated with the Gentlemen affiliate ecosystem and appears to be centrally developed, maintained, and distributed by the operators rather than sourced independently by affiliates. Reporting indicates the group rapidly incorporated newly disclosed BYOVD proof-of-concepts into the framework within days of public release, reflecting an agile development pipeline. The tooling is commonly staged alongside other anti-security utilities in Gentlemen intrusions and forms part of a broader defense-evasion portfolio that also includes externally sourced EDR killers.
The framework targets Windows environments and is used in human-operated ransomware intrusions affecting a wide range of sectors, with reporting on the broader Gentlemen operation highlighting manufacturing, healthcare, financial services, technology, business services, consumer services, and critical infrastructure among impacted industries. GentleKiller’s role is primarily pre-encryption defense suppression, enabling subsequent credential theft, data exfiltration, lateral movement, and ransomware execution by Gentlemen affiliates.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ESET documents GentleKiller's Cleaner variant dropping this driver without the trailing .sys extension, and CVE-2019-6494 describes IOCTL 0x8016E000 allowing low-privileged users to delete files regardless of access controls.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In June 2026, BleepingComputer documented TheGentlemen group shipping a custom EDR killers framework called GentleKiller, with eight separate variants targeting more than 400 security processes across 48 endpoint products.
Their primary tool, nicknamed GentleKiller, comes in at least eight distinct flavors. Each variant is heavily disguised as a different legitimate corporate product, and each abuses a different validly signed driver.
Gentlemen’s operators build, maintain, and centrally distribute a full portfolio of EDR killers, anchored by an in-house framework ESET has named GentleKiller.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
ESET’s assessment is that all three were acquired externally by the operators and then standardized with the same defense evasion layer applied to GentleKiller: binary protection via Enigma or Themida, filenames mimicking security vendors, fabricated version information, copied digital signatures, and matching icons.
Use Case Privileges Operating System Impair defenses through a signed kernel driver abused by an EDR killer.
The loader unpacks its real payload in memory using self-modifying code.
This includes binary protection using Enigma or Themida and using file names that resemble well-known cybersecurity vendors, right down to their version information, digital signatures, and icons.
Defense Evasion T1036 Masquerading EDR killers impersonate Kaspersky, Valorant, FACEIT, Symantec, etc.
Defense Evasion T1036.001 Invalid Code Signature Copied invalid signatures from legitimate executables
It either terminates each running process directly, unloads the EDR’s own kernel driver, deletes service registry keys to prevent restart, or all three.
Delete protected files and impair defenses through a vulnerable kernel driver.
He just hands Windows a file the system already trusts... a trusted-but-flawed file... Windows will still happily load it.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A framework used by The Gentlemen to disable or evade endpoint detection and response protections.
A custom kernel-mode EDR killer framework used to disable endpoint protection before ransomware deployment. It uses signed vulnerable Windows drivers to gain kernel privileges, then terminates EDR/AV processes, unloads security drivers, and removes service registry keys to prevent restart.
An in-house BYOVD-based EDR/AV killer framework with at least eight variants used to terminate security products before encryption.
A tool used by The Gentlemen RaaS operation to disable endpoint security by abusing validly signed vulnerable drivers in BYOVD attacks and terminating security-software processes across many vendors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.