ESET Details Gentlemen Ransomware Gang’s EDR-Killer Toolkit

Summary
ESET researchers detail how the Gentlemen ransomware group maintains and supplies affiliates with a standardized suite of EDR killers, including its in-house GentleKiller framework and externally sourced tools.
Key points
- Leaked internal data corroborated ESET’s assessment that Gentlemen operators develop and maintain EDR-killer packages for affiliates.
- GentleKiller has at least eight variants that abuse different vulnerable or malicious drivers to disable security products.
- The suite also incorporates HexKiller, ThrottleBlood, and HavocKiller, adapted with a shared evasion layer.
- Samples commonly impersonate legitimate software vendors using fake version details, icons, and copied certificates; some are packed with Enigma or Themida.
- Researchers say Gentlemen has operationalized newly disclosed BYOVD proofs of concept within days.
- ESET linked the Rust credential stealer OxideHarvest to a Gentlemen affiliate; it can collect credentials from specified hosts and browser profiles.
Article Details
- Attack Vectors
- GentleKiller and other EDR killers abuse vulnerable or malicious drivers to disrupt endpoint security products; some drivers are installed and started as services before exploitation.
- Gentlemen applies defense evasion to compiled EDR-killer samples, including vendor impersonation, fabricated version information, copied icons and certificates, packers, and code obfuscation.
- OxideHarvest uses supplied credentials to log into specified hosts and steals credentials from browser profiles.
- Defensive Notes
- Use incident-level investigation and analysis to attribute EDR-killer samples accurately; the article warns that isolated samples may otherwise be misattributed.
- Understand GentleKiller’s behavior and driver-abuse patterns to inform defenses against existing and future EDR-killer variants.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA1 | 12500f6c87ce62712a0ed6652c57468d15c14223 | SHA-1 of the IObit IMF ForceDelete filter driver abused by the GentleKiller Cleaner variant. |
| SHA1 | 1fa071303fb846308571e64727501fb98b1c2be6 | SHA-1 of the vulnerable driver abused by HavocKiller. |
| SHA1 | 2f86898528c6cab3540c486a9bfaa0c029b73950 | SHA-1 of a Themida-protected GentleKiller Network Blocker variant. |
| SHA1 | 331879f5eec8892bbd896f90bdbb1bad0bf63bd6 | SHA-1 of a GentleKiller Javelin variant abusing Safetica’s newer driver. |
| SHA1 | 56bee9df5833a637f5c54d5911df98b0812fe643 | SHA-1 of the PoisonX rootkit used by the GentleKiller G11 variant. |
| SHA1 | 5aa3124e5c4921e5edfc60133b5d71da21b07da3 | SHA-1 of a Themida-protected GentleKiller Valorant variant. |
| SHA1 | 68fec379f2ae76c3d2ce913f7be650cea1d06990 | SHA-1 of the newer Safetica Process Monitor driver abused by the GentleKiller Javelin variant. |
| SHA1 | 711ef221526997039e804a18db9647c91680bbe2 | SHA-1 of the older Safetica Process Monitor driver abused by the GentleKiller Javelin variant. |
| SHA1 | 7131b377e96016dc1911020c9f95b1b4d042d7b4 | SHA-1 of ThrottleBlood incorporated into Gentlemen operations with its evasion layer. |
| SHA1 | 7556ae58c215b8245a43f764f0676c7a8f0fdd1a | SHA-1 of an anti-cheat driver abused by the GentleKiller Valorant variant. |
| SHA1 | 82ed942a52cdcf120a8919730e00ba37619661a3 | SHA-1 of a driver abused by ThrottleBlood. |
| SHA1 | 8ae6bd18b129061f63642531f1b684cf0383c75d | SHA-1 of a GentleKiller Kaspersky-variant sample. |
| SHA1 | 96f0dbf52aed0afd43e44500116b04b674f7358e | SHA-1 of Zemana’s WatchDog Antimalware driver abused by the GentleKiller WatchDog variant. |
| SHA1 | 9ad51ad97c01e97ab59214116740785e0f6320a8 | SHA-1 of a Qihoo 360 driver abused by the GentleKiller Network Blocker variant. |
| SHA1 | a11ee9cdc59e5caa59aefd27b30d104f3ad68e62 | SHA-1 of a Themida-protected GentleKiller WatchDog variant. |
| SHA1 | a19117175dbc9ba4d23b5dce8415e299a2e32192 | SHA-1 of the GentleKiller Cleaner variant. |
| SHA1 | a5cf917ec4a7dfbdfa43621398604805d860c718 | SHA-1 of an OxideHarvest credential-stealer sample. |
| SHA1 | b0b912a3fd1c05d72080848ec4c92880004021a1 | SHA-1 of the NSecsoft NSecKrnl driver abused by the GentleKiller FACEIT Anti-Cheat variant. |
| SHA1 | ba914fe77b177b45799403b16dd14765c510a074 | SHA-1 of a custom rootkit used by the GentleKiller Kaspersky variant. |
| SHA1 | cf4d74df17a91b4a36a2911b22afec5d8fa93a01 | SHA-1 of HexKiller incorporated into Gentlemen operations with its evasion layer. |
| SHA1 | d29670e684e40ddc89b47010c37cbc96737035b6 | SHA-1 of a GentleKiller G11 variant. |
| SHA1 | d4b19141102015d436321e6f26976e98183cfd27 | SHA-1 of an OxideHarvest credential-stealer sample. |
| SHA1 | d605994fc72a2bb59b5cfb1624a1b9170eca73a2 | SHA-1 of an Enigma-protected GentleKiller FACEIT Anti-Cheat variant. |
| SHA1 | ec296f9501ad71e430810cb5cdc38d954d4ba536 | SHA-1 of the Baidu Antivirus BdApi driver abused by HexKiller. |
| SHA1 | ef9cd06683159397f099caa244e94e6eaad96eba | SHA-1 of a GentleKiller Javelin variant abusing both Safetica drivers. |
| SHA1 | f0537cbb773ae12100b36731e7c39f5a9d852b14 | SHA-1 of HavocKiller incorporated into Gentlemen operations with its evasion layer. |
| SHA1 | f11aebccb9a86a7e2e653f90baec697f233c255f | SHA-1 of a GentleKiller Javelin variant abusing Safetica’s older driver. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationSome samples use Enigma or Themida protection and custom control-flow obfuscation.T1036 · MasqueradingGentlemen’s EDR killers impersonate legitimate vendors through filenames, version information, icons, and copied certificates.T1036.001 · Invalid Code SignatureThe article describes invalid copied digital signatures as part of the EDR killers’ vendor-impersonation strategy.T1059.003 · Windows Command ShellThe article identifies GentleKiller and related tools as console-based executables that run visibly and emit debug strings.T1106 · Native APIUser-mode components communicate with kernel drivers through DeviceIoControl and other native Windows APIs.T1543.003 · Windows ServiceThe EDR killers install and start vulnerable or malicious drivers as services before exploiting them.T1685 · Disable or Modify ToolsGentleKiller and other EDR killers aim to bypass or disable security products such as EDRs.
People
Brian KrebsShared evidence of hastalamuerte’s true identity on June 10, 2026.hastalamuerteGroup-IB reported that hastalamuerte founded Gentlemen; the article identifies this handle as the gang leader.zeta88The article identifies zeta88 as another alias used by hastalamuerte and says the leader discussed maintaining and providing EDR-killer packages.
Threat Actors
AkiraRansomware group cited as an example of a gang with a strong US victim focus.BlackLockNamed as a group whose affiliates reportedly included Gentlemen operators before the operation began.DragonForceRansomware gang discussed in the victimology comparison; its affiliates were also reported to use ThrottleBlood.EmbargoNamed as a group whose affiliates reportedly included Gentlemen operators before the operation began.hastalamuerteIdentified in the article as Gentlemen’s leader and, according to Group-IB, its founder.LockBitNamed as a group whose affiliates reportedly included Gentlemen operators before the operation began.MedusaNamed as a group whose affiliates reportedly included Gentlemen operators before the operation began.MedusaLockerIts affiliates were repeatedly observed using ThrottleBlood.QilinRansomware group mentioned as a prior affiliation of Gentlemen’s founder and as a comparison in victimology.quantNamed Gentlemen affiliate associated with maintaining buildx641, identified as OxideHarvest.RansomHubRansomware operation cited as a comparison for providing an in-house EDR killer to affiliates.The GentlemenRansomware-as-a-service gang that maintains and provides EDR killers to affiliates and uses double extortion.WarlockRansomware gang previously associated with HexKiller, which was also found in Gentlemen intrusions.zeta88Explicitly identified as another alias used by Gentlemen leader hastalamuerte.
Malware
Vendors
AcronisAcronisAlienVaultAlienVaultAvastAvastAVGAVGBaidugoogleApiUtil64.sys, Baidu Antivirus BdApi driverBinary DefenseBinary DefenseBitdefenderBitdefenderBlumiraBlumiraBromiumBromiumCarbon BlackCarbon BlackCisco TalosCisco TalosCrowdStrikeCrowdStrikeCybereasonCybereasonCylance/BlackBerryCylance/BlackBerryCynetCynetCyveraCyveraDarktraceDarktraceDeep InstinctDeep InstinctElasticElasticESETESET researchers analyzed the robust EDR-killing toolset of the ransomware-as-a-service gang Gentlemen.FortinetFortinetG DATAG DATAHeimdalHeimdalHuaweihavoc.sys, Huawei Audio driverHuntressHuntressIObitIMFForceDelete, IObit’s IMF ForceDelete filter driver (PoC); the driver is dropped without the trailing .sys extensionKasperskyKasperskyLogRhythmLogRhythmMcAfee/TrellixMcAfee/TrellixMicrosoftMicrosoft DefenderMorphisecMorphisecOSSEC/WazuhOSSEC/WazuhPalo Alto NetworksPalo Alto Networks (Traps/Cortex)Panda SecurityPanda SecurityQihoo 360 Technology360netmon_wfp.sys, a vulnerable driver by Qihoo 360 Technology (PoC)QualysQualysRapid7Rapid7Red CanaryRed CanarySafeticastpm_(old|new).sys, two vulnerable ProcessMonitor Driver samples by Safetica (PoC)SangforSangforSentinelOneSentinelOneSonicWallSonicWallSophosSophosSymantecNorton/SymantecTaniumTaniumTechPowerUp LLCThrottleBlood.sys, driver by TechPowerUp LLCThreatLockerThreatLockerTrendAITrendAIUptycsUptycsVaronisVaronisWatchGuardWatchGuardWebrootWebrootWindows SysinternalsWindows SysinternalsZemanadmx.sys, Zemana’s WatchDog Antimalware Driver (PoC)ZscalerZscaler
Products
ESXiFor encryption, the operators offer a variant written in Go targeting Windows, Linux, and other platforms, and an ESXi variant written in C.FACEIT Anti-CheatFACEIT Anti-CheatFortiGateVictims are chosen primarily based on their FortiGate (mis)configuration rather than their geographical location.LinuxFor encryption, the operators offer a variant written in Go targeting Windows, Linux, and other platforms, and an ESXi variant written in C.Microsoft WindowsFor encryption, the operators offer a variant written in Go targeting Windows, Linux, and other platforms, and an ESXi variant written in C.ValorantValorant
Tools
buildx641However, as Check Point noted, a Gentlemen affiliate named quant maintains a tool referred to as buildx641, whose naming and functionality immediately reminded us of OxideHarvest.DemoKillerWe also saw DemoKiller in several intrusions, but this EDR killer did not exhibit any ties to Gentlemen and therefore we exclude it from the gang’s suite and instead consider it affiliate-specific.EDRKillShifterOne notable case is RansomHub, which invested in developing its own EDR killer from scratch, EDRKillShifter, and then offered it to affiliates through the affiliate panel.EnigmaAdvanced binary protection (Enigma or Themida) is applied to a significant portion of the samples we detected.GentleKillerof EDR killers that they offer to affiliates, centered around their in-house framework we have named GentleKiller.HavocKillerThey also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller.HexKillerThey also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller.OxideHarvestGentlemen also uses OxideHarvest, a credential stealer maintained by one of the group’s affiliates.PoisonKillerThis was the case with UnknownKiller and PoisonKiller, which were adopted within a matter of days.ThemidaAdvanced binary protection (Enigma or Themida) is applied to a significant portion of the samples we detected.ThrottleBloodThey also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller.UnknownKillerThis was the case with UnknownKiller and PoisonKiller, which were adopted within a matter of days.
Countries
BrazilIndeed, the gang’s targeting includes some otherwise unusual countries like Thailand, Brazil, and France.FranceIndeed, the gang’s targeting includes some otherwise unusual countries like Thailand, Brazil, and France.ThailandIndeed, the gang’s targeting includes some otherwise unusual countries like Thailand, Brazil, and France.United StatesMost major ransomware gangs show a strong and persistent focus on the United States, which frequently accounts for roughly half of all announced victims.