INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GentleKiller EDR-Killer Powering The Gentlemen
| 2026-06-30 15:51 CRITICAL LOW
Executive Summary
AI-generated
A sophisticated ransomware group known as The Gentlemen has been identified, leveraging zero-day exploits to disable EDR products and evade detection. According to recent data extraction, the group's primary targets include Southeast Asia, South America, and Western Europe, with a notable concentration in the United States. Notably, the group's founder, Alexander Andreevich Yapaev, a 36-year-old Russian national, has been linked to other prominent ransomware groups such as Qilin, Embargo, LockBit, Medusa, and BlackLock. The Gentlemen's tactics include data leaks, impersonation, and the use of binary protection via Enigma or Themida to evade security tools. With over 504 victims reported, this group poses a significant threat to global cybersecurity.
Technical Mitigations AI-generated
• Implementing Bring Your Own Vulnerable Driver (BYOVD) protection to prevent exploitation of vulnerable kernel drivers.
• Regularly updating and patching endpoint security products, such as EDR solutions, to mitigate the impact of GentleKiller variants.
• Utilizing behavioral analysis and anomaly detection capabilities within EDR solutions to identify and flag suspicious activity indicative of GentleKiller attacks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ex•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
EmbargoEmbargoCarbonCarbonQilinQilin
Target & Sectors
LATAM
LATAM
APAC
APAC
EUROPE
EUROPE
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
late 2025
The Gentlemen ransomware operation emerged in late 2025 and claimed 504 victims.
Click on any entity below to view its context and source!
tactic
Ransomware
Since emerging in late 2025, The Gentlemen has claimed 504 victims and established itself as one of the five most active ransomware operations in Q1 2026.
victims
504 victims
Since emerging in late 2025, The Gentlemen has claimed 504 victims and established itself as one of the five most active ransomware operations in Q1 2026.
Q1 2026
The Gentlemen ransomware operation claimed 504 victims since its emergence in late 2025.
Click on any entity below to view its context and source!
tactic
Ransomware
Since emerging in late 2025, The Gentlemen has claimed 504 victims and established itself as one of the five most active ransomware operations in Q1 2026.
victims
504 victims
Since emerging in late 2025, The Gentlemen has claimed 504 victims and established itself as one of the five most active ransomware operations in Q1 2026.
January 23rd
Huntress disclosed publicly in March 2026 that HavocKiller, a zero-day exploit, was already active in Gentlemen intrusions dating back to January 23rd.
Click on any entity below to view its context and source!
organisation
HavocKiller
HavocKiller, disclosed publicly by Huntress in March 2026, was already active in Gentlemen intrusions dating back to January 23rd.
organisation
Huntress
HavocKiller, disclosed publicly by Huntress in March 2026, was already active in Gentlemen intrusions dating back to January 23rd.
February 2026
ESET had previously hypothesized a zero-day exploit since February 2026, and leaked internal data confirmed this hypothesis.
March 2026
Huntress disclosed publicly a zero-day exploit known as HavocKiller, which was already active in Gentlemen intrusions dating back to January 23rd.
Click on any entity below to view its context and source!
organisation
HavocKiller
HavocKiller, disclosed publicly by Huntress in March 2026, was already active in Gentlemen intrusions dating back to January 23rd.
organisation
Huntress
HavocKiller, disclosed publicly by Huntress in March 2026, was already active in Gentlemen intrusions dating back to January 23rd.
May 2026
Threat actors used the leaked internal data to inform their analysis of The Gentlemen's technical infrastructure, which was later detailed by ESET on June 18.
Click on any entity below to view its context and source!
tactic
Data Leak
ESET published a detailed breakdown of
The Gentlemen
‘s technical infrastructure on June 18, the result of months of incident-level investigation corroborated by the group’s own internal data leak from May 2026.
organisation
ESET
ESET published a detailed breakdown of
The Gentlemen
‘s technical infrastructure on June 18, the result of months of incident-level investigation corroborated by the group’s own internal data leak from May 2026.
June 10
Threat actors associated with LockBit published evidence on June 10 identifying the true identity of hastalamuerte, a group's founder.
Click on any entity below to view its context and source!
malware
Qilin
Brian Krebs published evidence on June 10 of the true identity of hastalamuerte, the group’s founder, identified as 36-year-old Russian national Alexander Andreevich Yapaev, a former affiliate of Qilin, Embargo, LockBit, Medusa, and BlackLock.
source_region
Russian Federation
Brian Krebs published evidence on June 10 of the true identity of hastalamuerte, the group’s founder, identified as 36-year-old Russian national Alexander Andreevich Yapaev, a former affiliate of Qilin, Embargo, LockBit, Medusa, and BlackLock.
malware
Embargo
Brian Krebs published evidence on June 10 of the true identity of hastalamuerte, the group’s founder, identified as 36-year-old Russian national Alexander Andreevich Yapaev, a former affiliate of Qilin, Embargo, LockBit, Medusa, and BlackLock.
organisation
LockBit
Brian Krebs published evidence on June 10 of the true identity of hastalamuerte, the group’s founder, identified as 36-year-old Russian national Alexander Andreevich Yapaev, a former affiliate of Qilin, Embargo, LockBit, Medusa, and BlackLock.
organisation
BlackLock
Brian Krebs published evidence on June 10 of the true identity of hastalamuerte, the group’s founder, identified as 36-year-old Russian national Alexander Andreevich Yapaev, a former affiliate of Qilin, Embargo, LockBit, Medusa, and BlackLock.
June 18
ESET published a detailed breakdown of The Gentlemen's technical infrastructure on June 18, based on months of incident-level investigation corroborated by the group's own internal data leak from May 2026.
Click on any entity below to view its context and source!
tactic
Data Leak
ESET published a detailed breakdown of
The Gentlemen
‘s technical infrastructure on June 18, the result of months of incident-level investigation corroborated by the group’s own internal data leak from May 2026.
organisation
ESET
ESET published a detailed breakdown of
The Gentlemen
‘s technical infrastructure on June 18, the result of months of incident-level investigation corroborated by the group’s own internal data leak from May 2026.
2026/06/30
The Gentlemen ransomware group has centralized the function of disabling endpoint security tools, offering affiliates a ready-to-use, standardized EDR-killer suite.
Click on any entity below to view its context and source!
organisation
EDR
My deep-dive technical analysis of a zero-day exploit being ....
My deep-dive technical analysis of a zero-day exploit being used by The Gentlemen ransomware group to disable EDR products
https://
expel.com/blog/not-very-gentle
manly-analyzing-a-zero-day-exploit-used-by-the-gentlemen-ransomware-to-disable-targets-edrs/
Inside GentleKiller: The EDR-Killer Powering The Gentlemen
The Gentlemen equips affiliates with a centralized EDR-killer suite, rapidly weaponizing BYOVD exploits to disable security tools before ransomware attacks.
organisation
HexKiller
HexKiller, previously associated exclusively with the Warlock ransomware gang, uses a Baidu Antivirus driver and appeared in Gentlemen intrusions staged in the same GentlemenCollection directory as GentleKiller.
organisation
Baidu Antivirus
HexKiller, previously associated exclusively with the Warlock ransomware gang, uses a Baidu Antivirus driver and appeared in Gentlemen intrusions staged in the same GentlemenCollection directory as GentleKiller.
organisation
GentlemenCollection
HexKiller, previously associated exclusively with the Warlock ransomware gang, uses a Baidu Antivirus driver and appeared in Gentlemen intrusions staged in the same GentlemenCollection directory as GentleKiller.
infrastructure
Fortigate
The leaked data suggests this isn’t random: the group selects victims primarily based on FortiGate misconfiguration rather than geography, and centrally distributes targets to affiliates.
organisation
GentleKiller
The centerpiece of that suite is GentleKiller, an in-house framework with at least eight distinct variants.
organisation
Kaspersky
The eight variants target drivers from Kaspersky, FACEIT Anti-Cheat, Valorant, Javelin, Safetica, Zemana, Qihoo 360, IObit, and the PoisonX rootkit.
organisation
CrowdStrike
Across all variants, GentleKiller hunts for over 400 processes belonging to 48 distinct security products, including CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Carbon Black, and ESET itself.
organisation
SentinelOne
Across all variants, GentleKiller hunts for over 400 processes belonging to 48 distinct security products, including CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Carbon Black, and ESET itself.
organisation
Microsoft Defender
Across all variants, GentleKiller hunts for over 400 processes belonging to 48 distinct security products, including CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Carbon Black, and ESET itself.
organisation
Sophos
Across all variants, GentleKiller hunts for over 400 processes belonging to 48 distinct security products, including CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Carbon Black, and ESET itself.
organisation
PoC
“It allows the Gentlemen operators to integrate abused drivers into their toolset very soon after an EDR killer PoC is disclosed.
organisation
PoisonKiller
This was the case with
UnknownKiller
and
PoisonKiller
, which were adopted within a matter of days.”
organisation
UnknownKiller
The UnknownKiller and PoisonKiller proof-of-concepts were both adopted within days of their public release.
organisation
ThrottleBlood
ThrottleBlood, more commonly seen in
MedusaLocker
and
DragonForce
affiliate attacks, uses a TechPowerUp driver.
organisation
OxideHarvest
ESET also found a Rust-based credential stealer called OxideHarvest, also tracked as buildx641, linked to one of the group’s affiliates.
organisation
Opera
It targets Chrome, Edge, Firefox, Brave, Opera, OperaGX, Vivaldi, Waterfox, and a dozen other browsers, using supplied credentials to log into specified hosts, pull browser credentials, and write them to an output file.
organisation
SecurityAffairs
“This decision makes Gentlemen an attractive operator for affiliates as it materially lowers the entry barrier for them, making their job consequently easier.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, The Gentlemen)
Tactical Metrics
Metrics
victims
504
Victims
Click for context!
Since emerging in late 2025, The Gentlemen has claimed 504 victims and established itself as one of the five most active ransomware operations in Q1 2026.
Metrics
infrastructure
Fortigate
Affected Product
The leaked data suggests this isn’t random: the group selects victims primarily based on FortiGate misconfiguration rather than geography, and centrally distributes targets to affiliates.
Intelligence Sources
Security Affairs
2026-06-20
Inside GentleKiller: The EDR-Killer Powering The Gentlemen
Security Affairs
Mastodon MalwareTech
2026-06-30
My deep-dive technical analysis of a zero-day exploit being ...
Mastodon MalwareTech
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T15:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
22x
organisation
Identified Entity
EDR
entity
9x
timeline
Temporal Reference
June 10
date
3x
tactic
Cyber Operation Type
Ransomware
tactic
3x
target region
Target Region
EUROPE
region
3x
malware
Malware Payload
Qilin
tool
2x
target region
Target Country
United States
country
2x
attribution
Attributing Entity
Hastalamuerte’s Telegram ID
authority
2x
industry
Targeted Sector
Government
sector
Contextual Telemetry
Context Block
6 METRICS
source region
Origin Country
Russian Federation
country
victims
Victims
504
victims
infrastructure
Affected Product
Fortigate
software
general metric
Qihoo
360
qihoo
general metric
Processes
400
processes
general metric
Distinct Security Products
48
distinct security products
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.