
The Gentlemen RaaS Ransomware: GentleKiller EDR Framework Disables 400 Security Processes (March 2025)
The Gentlemen RaaS: What Happened
The Gentlemen ransomware-as-a-service (RaaS) group has conducted a widespread campaign since March 2025, leveraging a custom suite of endpoint detection and response (EDR) killing tools known as GentleKiller. Led by Alexander Andreevich Yapaev (alias hastalamuerte), the group has targeted organizations globally, with confirmed impact on over 500 victims. The attackers systematically disabled security defenses prior to ransomware deployment, resulting in hundreds of successful infections and significant operational disruption across affected networks.
Attack Vector & Technical Detail
The Gentlemen group’s primary tactic involved bring your own vulnerable driver (BYOVD) attacks, exploiting multiple vulnerable drivers to gain kernel-level access and disable security controls. Notable IOCs associated with this campaign include eb.sys, nseckrnl.sys, GameDriverX64.sys, stpm_old.sys, stpm_new.sys, dmx.sys, 360netmon_wfp.sys, IMFForceDelete.sys, PoisonX.sys, googleApiUtil64.sys, ThrottleBlood.sys, havoc.sys, and hrwfpdrv.sys. The GentleKiller framework was observed terminating approximately 400 security-related processes spanning 48 distinct security products. This activity aligns with MITRE ATT&CK tactics TA0005 (Defense Evasion), TA0003 (Persistence), and TA0007 (Discovery), enabling the ransomware payload to execute without interference from endpoint protection solutions.
Confirmed Impact
The campaign’s impact has been global, with hundreds of organizations experiencing ransomware infections and subsequent data encryption. The disabling of such a broad array of security processes has left networks exposed, complicating incident response and recovery efforts. While specific organization names have not been disclosed, the scale and sophistication of the attack raise concerns for regulatory compliance, incident reporting obligations, and potential data privacy violations in multiple jurisdictions.
What This Means for Your Organization
The Gentlemen RaaS campaign demonstrates the increasing threat posed by adversaries leveraging BYOVD techniques to neutralize security controls before deploying ransomware. Organizations should review their endpoint protection strategies, ensuring that vulnerable drivers are identified and blocked, and that EDR solutions are configured to detect and prevent unauthorized driver loading. Proactive monitoring for known IOCs and behavioral indicators associated with GentleKiller is essential to reduce risk and limit potential impact.
Detection & Response
- Immediate: Audit and restrict the loading of unsigned or vulnerable drivers across all endpoints.
- Hunt: Search for presence of IOCs such as eb.sys, nseckrnl.sys, and GameDriverX64.sys within system directories and active processes.
- Patch: N/A (no specific CVEs were provided for remediation).
Source: https://thehackernews.com/2026/06/the-gentlemen-raas-uses-gentlekiller.html
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

