The Gentlemen Group develops, maintains and provides to affiliates a proprietary EDR-killers suite called 'GentleKiller', with at least eight variants based on vulnerable or malicious drivers and integrated with third-party tools (HexKiller, ThrottleBlood and HavocKiller). Unified avoidance strategy reinforces impersonation and protection, while victimology shows global distribution not centered on the US
ESET, a global European leader in the cybersecurity market, analyzed the powerful toolset used by ransomware-as-a-service (RaaS) group Gentlemen to evade EDR systems. Since the beginning of 2026, Gentlemen has established itself as one of the most active gangs in the ransomware ecosystem. The group stands out with an advanced set of endpoint detection and response (EDR) disabling tools – tools used to defeat security software – managed directly by operators. Furthermore, unlike most top-tier gangs, Gentlemen does not show a strong predilection for US victims, but targets individuals throughout Southeast Asia, South America and Western Europe. The organization's target countries include some that are usually rarely targeted, such as Thailand, Brazil and France.
"Although numerous articles have been published about Gentlemen in recent months, none of them have focused on a detailed analysis of the techniques used by the group to evade EDR systems. Thanks to the constant visibility at the single incident level provided by ESET, we are able to provide a unique and in-depth insight into the development practices of Gentlemen's EDR-killers. The internal data leak suffered by Gentlemen in May 2026 has given us a better understanding of the internal workings of the group," says Jakub Souček, ESET researcher who monitors EDR killers. “The leak also allowed us to confirm the hypothesis we formulated in February 2026: Gentlemen operators actively develop and maintain a portfolio of EDR killers that they offer to their affiliates, centered on the internal framework, which we have called GentleKiller.”
Additionally, the group integrates third-party or unauthorized tools such as HexKiller, ThrottleBlood, and HavocKiller. These tools are standardized through a shared layer of evasion defense systems, which predominantly impersonate security solution providers using fake version information and copied legitimate certificates and icons. Gentlemen also demonstrates an unusually rapid ability to operationalize newly disclosed Bring Your Own Vulnerable Driver proof-of-concepts, often within days of their public release. In addition to EDR killers, ESET has also identified a credential theft tool called OxideHarvest; This tool was developed by one of Gentlemen's affiliates.
For context, Gentlemen emerged in late 2025 as a Ransomware-as-a-Service (RaaS) operation and quickly became one of the most active ransomware gangs observed in the first quarter of 2026. The group offers affiliates a particularly generous share of 90% of profits. Gentlemen uses a double extortion strategy: in addition to encrypting victims' data, the group also threatens to disclose it if the ransom is not paid.
One of the things that sets Gentlemen apart is the group's willingness to offer affiliates more than just encryption tools – notably, the group also provides EDR killers. Gentlemen represents a different and, so far, little documented approach. Rather than relying on affiliates to source these tools themselves, Gentlemen operators actively develop and manage a portfolio of EDR killers for affiliates.
While the victimology of large RaaS operations is often driven more by affiliate choices than operator-driven strategy, a particular pattern nevertheless emerges. Most major ransomware gangs show a strong and persistent interest in the United States, often accounting for around half of all reported victims. Gentlemen stands out as a notable exception to this trend. Despite being among the five most active ransomware gangs in the first quarter of 2026, its victimology does not show a comparable concentration on the United States. In contrast, Gentlemen affiliates consistently target victims in a wide range of geographically diverse countries, with a significant number of victims coming from regions such as Southeast Asia, South America and Western Europe.
Gentlemen operators apply a specific set of defense system evasion techniques to the gang's various EDR killers. These techniques are applied to compiled samples rather than source code. This gives Gentlemen the ability to protect even EDR killers for which the gang does not possess the source code. GentleKiller is by far the most prevalent EDR killer observed in the Gentlemen ecosystem.
To date, ESET Research has identified eight distinct variants, each posing as a different legitimate product and exploiting a different vulnerable or malicious driver. Despite these surface differences, ESET classifies all these samples under the name GentleKiller due to the high degree of common internal characteristics.
“From a defense perspective, understanding how GentleKiller works allows defenders to develop more effective defensive strategies and also protect themselves against any new features yet to be developed in Gentlemen's arsenal of EDR-killers,” concludes Souček.






