The Gentlemen RaaS Platform Enhances Arsenal with EDR Killer Framework
The Gentlemen's new EDR killer, 'GentleKiller', arms affiliates with advanced intrusion tools.

The ransomware group known as The Gentlemen has equipped its affiliates with a potent EDR killer framework, according to research by ESET. Dubbed 'GentleKiller', this tool significantly lowers the technical barrier for affiliates, enabling them to bypass enterprise endpoint defenses more effectively.
The Gentlemen, a ransomware-as-a-service (RaaS) platform, disrupted by a breach in May, has grown in prominence due to its lucrative 90/10 revenue split model. This leak offered researchers a glimpse into the operational mechanics of the group, revealing the sophistication behind their EDR killer framework.
EDR killers, tools designed to disable or evade endpoint security measures, are not novel. However, The Gentlemen's approach simplifies their use. Affiliates are handed pre-packaged routines, eliminating the need to develop bespoke solutions. This democratization of EDR evasion is significant, as noted by ESET's Jakub Souček, who highlighted how these tools expand the affiliate pool and support consistent deployment of ransomware encryptors.
A core feature of 'GentleKiller' is its use of the 'Bring Your Own Vulnerable Driver' (BYOVD) tactic. By loading an outdated, vulnerable driver, attackers gain kernel-level privileges, allowing direct targeting of EDR processes. This method, bundled with evasions for 400 processes from 48 vendors, underscores the framework's comprehensive nature.
The threat of BYOVD has been acknowledged before. A 2024 study by Trellix and recent findings by Huntress have shown vulnerabilities in EDR defenses. Yet, the challenge remains, as these methods exploit legitimate drivers still in use. Souček advises implementing Hypervisor-Protected Code Integrity (HVCI) and Kernel-mode Code Integrity (KMCI) to prevent such drivers' misuse.
To counteract these threats, enterprises should enforce strict driver policies and regularly audit and update their systems. This proactive approach can mitigate the risk posed by EDR killers.



