INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

GentleKiller EDR-Killer Powering The Gentlemen

| 2026-06-30 15:51 CRITICAL LOW
Executive Summary
AI-generated
A sophisticated ransomware group known as The Gentlemen has been identified, leveraging zero-day exploits to disable EDR products and evade detection. According to recent data extraction, the group's primary targets include Southeast Asia, South America, and Western Europe, with a notable concentration in the United States. Notably, the group's founder, Alexander Andreevich Yapaev, a 36-year-old Russian national, has been linked to other prominent ransomware groups such as Qilin, Embargo, LockBit, Medusa, and BlackLock. The Gentlemen's tactics include data leaks, impersonation, and the use of binary protection via Enigma or Themida to evade security tools. With over 504 victims reported, this group poses a significant threat to global cybersecurity.
Technical Mitigations AI-generated
• Implementing Bring Your Own Vulnerable Driver (BYOVD) protection to prevent exploitation of vulnerable kernel drivers. • Regularly updating and patching endpoint security products, such as EDR solutions, to mitigate the impact of GentleKiller variants. • Utilizing behavioral analysis and anomaly detection capabilities within EDR solutions to identify and flag suspicious activity indicative of GentleKiller attacks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ex•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
EmbargoEmbargoCarbonCarbonQilinQilin
Target & Sectors
LATAM LATAM APAC APAC EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎late 2025
The Gentlemen ransomware operation emerged in late 2025 and claimed 504 victims.
tactic Ransomware
victims 504 victims
‎Q1 2026
The Gentlemen ransomware operation claimed 504 victims since its emergence in late 2025.
tactic Ransomware
victims 504 victims
‎January 23rd
Huntress disclosed publicly in March 2026 that HavocKiller, a zero-day exploit, was already active in Gentlemen intrusions dating back to January 23rd.
organisation HavocKiller
organisation Huntress
‎February 2026
ESET had previously hypothesized a zero-day exploit since February 2026, and leaked internal data confirmed this hypothesis.
‎March 2026
Huntress disclosed publicly a zero-day exploit known as HavocKiller, which was already active in Gentlemen intrusions dating back to January 23rd.
organisation HavocKiller
organisation Huntress
‎May 2026
Threat actors used the leaked internal data to inform their analysis of The Gentlemen's technical infrastructure, which was later detailed by ESET on June 18.
tactic Data Leak
organisation ESET
‎June 10
Threat actors associated with LockBit published evidence on June 10 identifying the true identity of hastalamuerte, a group's founder.
malware Qilin
source_region Russian Federation
malware Embargo
organisation LockBit
organisation BlackLock
‎June 18
ESET published a detailed breakdown of The Gentlemen's technical infrastructure on June 18, based on months of incident-level investigation corroborated by the group's own internal data leak from May 2026.
tactic Data Leak
organisation ESET
‎2026/06/30
The Gentlemen ransomware group has centralized the function of disabling endpoint security tools, offering affiliates a ready-to-use, standardized EDR-killer suite.
organisation EDR
organisation HexKiller
organisation Baidu Antivirus
organisation GentlemenCollection
infrastructure Fortigate
organisation GentleKiller
organisation Kaspersky
organisation CrowdStrike
organisation SentinelOne
organisation Microsoft Defender
organisation Sophos
organisation PoC
organisation PoisonKiller
organisation UnknownKiller
organisation ThrottleBlood
organisation OxideHarvest
organisation Opera
organisation SecurityAffairs
Tactical Metrics
Metrics
victims
504
Victims
Metrics
infrastructure
‎Fortigate
Affected Product
Intelligence Sources
Security Affairs 2026-06-20
Mastodon MalwareTech 2026-06-30