
Oltenia Ransomware: Gentlemen Group Deploys EDR Killers to Evade Defenses (June 2024)
Oltenia: What Happened
The Romanian energy provider Oltenia was targeted in a high-severity ransomware attack attributed to the Gentlemen ransomware-as-a-service (RaaS) group. The attackers employed a suite of endpoint detection and response (EDR) killer tools, notably a custom utility named GentleKiller, which exists in at least eight distinct variants. These tools were used to systematically disable security products from multiple vendors, allowing the ransomware deployment to proceed without interruption. The campaign is linked to a malware botnet comprising over 1,570 compromised hosts, enabling the group to orchestrate widespread data encryption across high-value targets.
Attack Vector & Technical Detail
The Gentlemen group’s attack methodology centers on the use of multiple EDR bypass techniques, with a particular focus on disabling endpoint security controls. The custom GentleKiller utility, in its various forms, is engineered to terminate security processes and services, effectively blinding host-based defenses. The attackers leveraged MITRE ATT&CK tactics TA0005 (Defense Evasion), TA0001 (Initial Access), and TA0007 (Discovery) to facilitate lateral movement and persistence within the target environment. While no specific CVEs or IOCs were provided in the current incident data, the campaign’s linkage to a botnet of over 1,570 hosts suggests initial access may have been achieved through compromised endpoints or malware delivery infrastructure. The group’s operational sophistication is further evidenced by their ability to deploy multiple EDR killer variants tailored to different security products.
Confirmed Impact
The confirmed impact of the attack includes the disabling of security defenses across Oltenia’s infrastructure, leading to successful ransomware deployment and data encryption. The campaign’s global reach and focus on high-value organizations raise concerns about sector-wide vulnerabilities, particularly in critical infrastructure. The attackers’ ability to neutralize a range of security products increases the risk of undetected lateral movement and data exfiltration. Regulatory implications are significant, especially for energy sector organizations operating in the European Union, where data protection and incident reporting requirements are stringent.
What This Means for Your Organization
This incident highlights the evolving threat posed by ransomware operators who actively target and neutralize endpoint security solutions. Organizations relying solely on EDR or antivirus products for defense are at increased risk, as attackers develop custom utilities to bypass these controls. It is critical to implement layered security architectures, including network segmentation, behavioral monitoring, and rapid incident response capabilities. Regular validation of security controls and proactive threat hunting for signs of EDR tampering or process termination are essential to detect and mitigate similar attacks.
Detection & Response
- Immediate: Audit and monitor all endpoint security solutions for signs of unauthorized process termination or service disruption.
- Hunt: Search for evidence of custom EDR killer utilities, such as GentleKiller variants, and anomalous process activity linked to MITRE tactics TA0005, TA0001, and TA0007.
- Patch: N/A (no CVE-specific exploits identified in this incident).
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

