The Gentlemen RaaS Platform Enhances Arsenal with EDR Killer Framework

GentleKiller hands The Gentlemen's affiliates a packaged EDR-killing toolkit, no technical expertise required.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
The Gentlemen RaaS Platform Enhances Arsenal with EDR Killer Framework
Share

Key points

  • The Gentlemen ransomware group now supplies affiliates with GentleKiller, an in-house EDR killer framework built on BYOVD techniques.
  • The framework bundles evasions for 400 security processes from 48 vendors across eight variants.
  • A May server breach exposed the group's operations and confirmed ESET's suspicions about the toolkit.
  • ESET researcher Jakub Souček recommends HVCI and KMCI enforcement as the primary technical defense.
  • The group's 90/10 affiliate revenue split has made it one of the most active RaaS platforms, linked to an estimated 300 ransomware attacks.

What is GentleKiller and why does it matter?

GentleKiller is The Gentlemen's own EDR killer framework, handed directly to affiliates as part of the standard package. It's not a single tool. Across eight variants, it deploys bring your own vulnerable driver (BYOVD) techniques, where a legitimate but outdated vendor driver is loaded into memory, extended to kernel level, and used to kill EDR processes outright. The framework covers 400 processes from 48 vendors and also integrates third-party utilities including HexKiller, ThrottleBlood, and HavocKiller.

The effect, as Souček put it via email to the original reporting outlet, is deliberate democratisation: "By providing such tools for affiliates, they lower the entry barrier for less skilled affiliates, who, on top of the encryptor, also receive everything they need to perform intrusions. This naturally expands the affiliate pool and enables consistent encryptor deployment."

We've tracked The Gentlemen across five stories in the last 90 days, including the 19 June report that first mapped GentleKiller's signed-driver abuse and kill list in detail. This story adds ESET's post-breach analysis and Souček's defensive guidance.

Should you worry about BYOVD in your environment?

You should, but the threat isn't new. A 2024 Trellix study flagged EDR vulnerability to this class of attack, and Huntress reported a live BYOVD case earlier this year. What's changed is the packaging. Affiliates who previously had to source or build their own driver-abuse tooling now get it bundled at onboarding. That's an operational shift, not just a technical one.

The core problem Souček identifies is that EDR killers rely on non-malicious drivers that many environments still run legitimately. That makes blocklisting hard. His recommendation: enforce HVCI and KMCI, which restrict unsafe or outdated drivers from loading in the first place, and back those controls with custom allow and block driver policies, continuous auditing of unnecessary drivers, and removal of anything vulnerable. "Preventing the installation of such drivers renders the EDR killer benign," he said.

The group's 90/10 revenue split, unusually generous by RaaS standards, was already drawing affiliates at scale before GentleKiller existed. Adding a polished intrusion toolkit lowers the bar further. The real question for defenders isn't whether BYOVD works; it's whether their driver policies are tight enough to make it irrelevant before an affiliate ever shows up.

© 2026 Threat Vectr