×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET Research investigates the Gentlemen ransomware author group and its defense evasion tools

Customer Press Room

ESET Research investigates the Gentlemen ransomware author group and its defense evasion tools

by Grandangolo Communications / Thursday, 18 June 2026 / Published in Eset

The Gentlemen Group develops, maintains and provides to affiliates a proprietary EDR-killers suite called 'GentleKiller', with at least eight variants based on vulnerable or malicious drivers and integrated with third-party tools (HexKiller, ThrottleBlood and HavocKiller). Unified avoidance strategy reinforces impersonation and protection, while victimology shows global distribution not centered on the US

ESET, a global European leader in the cybersecurity market, analyzed the powerful toolset used by ransomware-as-a-service (RaaS) group Gentlemen to evade EDR systems. Since the beginning of 2026, Gentlemen has established itself as one of the most active gangs in the ransomware ecosystem. The group stands out with an advanced set of endpoint detection and response (EDR) disabling tools – tools used to defeat security software – managed directly by operators. Furthermore, unlike most top-tier gangs, Gentlemen does not show a strong predilection for US victims, but targets individuals throughout Southeast Asia, South America and Western Europe. The organization's target countries include some that are usually rarely targeted, such as Thailand, Brazil and France.

"Although numerous articles have been published about Gentlemen in recent months, none of them have focused on a detailed analysis of the techniques used by the group to evade EDR systems. Thanks to the constant visibility at the single incident level provided by ESET, we are able to provide a unique and in-depth insight into the development practices of Gentlemen's EDR-killers. The internal data leak suffered by Gentlemen in May 2026 has given us a better understanding of the internal workings of the group," says Jakub Souček, ESET researcher who monitors EDR killers. “The leak also allowed us to confirm the hypothesis we formulated in February 2026: Gentlemen operators actively develop and maintain a portfolio of EDR killers that they offer to their affiliates, centered on the internal framework, which we have called GentleKiller.”

Additionally, the group integrates third-party or unauthorized tools such as HexKiller, ThrottleBlood, and HavocKiller. These tools are standardized through a shared layer of evasion defense systems, which predominantly impersonate security solution providers using fake version information and copied legitimate certificates and icons. Gentlemen also demonstrates an unusually rapid ability to operationalize newly disclosed Bring Your Own Vulnerable Driver proof-of-concepts, often within days of their public release. In addition to EDR killers, ESET has also identified a credential theft tool called OxideHarvest; This tool was developed by one of Gentlemen's affiliates.

For context, Gentlemen emerged in late 2025 as a Ransomware-as-a-Service (RaaS) operation and quickly became one of the most active ransomware gangs observed in the first quarter of 2026. The group offers affiliates a particularly generous share of 90% of profits. Gentlemen uses a double extortion strategy: in addition to encrypting victims' data, the group also threatens to disclose it if the ransom is not paid.

One of the things that sets Gentlemen apart is the group's willingness to offer affiliates more than just encryption tools – notably, the group also provides EDR killers. Gentlemen represents a different and, so far, little documented approach. Rather than relying on affiliates to source these tools themselves, Gentlemen operators actively develop and manage a portfolio of EDR killers for affiliates.

While the victimology of large RaaS operations is often driven more by affiliate choices than operator-driven strategy, a particular pattern nevertheless emerges. Most major ransomware gangs show a strong and persistent interest in the United States, often accounting for around half of all reported victims. Gentlemen stands out as a notable exception to this trend. Despite being among the five most active ransomware gangs in the first quarter of 2026, its victimology does not show a comparable concentration on the United States. In contrast, Gentlemen affiliates consistently target victims in a wide range of geographically diverse countries, with a significant number of victims coming from regions such as Southeast Asia, South America and Western Europe.

Gentlemen operators apply a specific set of defense system evasion techniques to the gang's various EDR killers. These techniques are applied to compiled samples rather than source code. This gives Gentlemen the ability to protect even EDR killers for which the gang does not possess the source code. GentleKiller is by far the most prevalent EDR killer observed in the Gentlemen ecosystem.

To date, ESET Research has identified eight distinct variants, each posing as a different legitimate product and exploiting a different vulnerable or malicious driver. Despite these surface differences, ESET classifies all these samples under the name GentleKiller due to the high degree of common internal characteristics.

“From a defense perspective, understanding how GentleKiller works allows defenders to develop more effective defensive strategies and also protect themselves against any new features yet to be developed in Gentlemen's arsenal of EDR-killers,” concludes Souček.

Tagged under: Eset

About Grandangolo Communications

What you can read next

ESET Research discovers new variants of AsyncRAT, a favorite tool of cybercriminals
ESET Research reports: Latin American banking Trojans spread to Europe
ESET was recognized as a Top Player in Radicati's 2024 Market Quadrant for the APT Protection segment

Customer Press Room

  • Arrow Electronics has been awarded by Equinix as Distributor of the Year 2025 for the EMEA region

    Arrow Electronics, a global supplier of technology...
  • SentinelOne makes the Purple AI Agentic Investigation solution available to all customers, bringing the latest generation AI directly into the SOC

    The investigations, started autonomously and without need...
  • Acronis TRU reveals the ongoing evolution of the INC ransomware group

    A recent report published by Acronis Threat ...
  • Imprivata presents the Agentic Identity Management solution to protect and govern the access of AI agents

    Imprivata, a leading company in Ac...
  • ESET Research: China-linked FishMonger upgrades its arsenal and targets governments in Asia and Latin America

    ESET has discovered two new Windows variants of the...

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP