ESET Details Gentlemen Ransomware Gang’s EDR-Killer Toolkit

· Original article ↗

Summary

ESET researchers detail how the Gentlemen ransomware group maintains and supplies affiliates with a standardized suite of EDR killers, including its in-house GentleKiller framework and externally sourced tools.

Key points

  • Leaked internal data corroborated ESET’s assessment that Gentlemen operators develop and maintain EDR-killer packages for affiliates.
  • GentleKiller has at least eight variants that abuse different vulnerable or malicious drivers to disable security products.
  • The suite also incorporates HexKiller, ThrottleBlood, and HavocKiller, adapted with a shared evasion layer.
  • Samples commonly impersonate legitimate software vendors using fake version details, icons, and copied certificates; some are packed with Enigma or Themida.
  • Researchers say Gentlemen has operationalized newly disclosed BYOVD proofs of concept within days.
  • ESET linked the Rust credential stealer OxideHarvest to a Gentlemen affiliate; it can collect credentials from specified hosts and browser profiles.

Article Details

Attack Vectors
  • GentleKiller and other EDR killers abuse vulnerable or malicious drivers to disrupt endpoint security products; some drivers are installed and started as services before exploitation.
  • Gentlemen applies defense evasion to compiled EDR-killer samples, including vendor impersonation, fabricated version information, copied icons and certificates, packers, and code obfuscation.
  • OxideHarvest uses supplied credentials to log into specified hosts and steals credentials from browser profiles.
Defensive Notes
  • Use incident-level investigation and analysis to attribute EDR-killer samples accurately; the article warns that isolated samples may otherwise be misattributed.
  • Understand GentleKiller’s behavior and driver-abuse patterns to inform defenses against existing and future EDR-killer variants.

Indicators of compromise

TypeIndicatorContext
SHA112500f6c87ce62712a0ed6652c57468d15c14223SHA-1 of the IObit IMF ForceDelete filter driver abused by the GentleKiller Cleaner variant.
SHA11fa071303fb846308571e64727501fb98b1c2be6SHA-1 of the vulnerable driver abused by HavocKiller.
SHA12f86898528c6cab3540c486a9bfaa0c029b73950SHA-1 of a Themida-protected GentleKiller Network Blocker variant.
SHA1331879f5eec8892bbd896f90bdbb1bad0bf63bd6SHA-1 of a GentleKiller Javelin variant abusing Safetica’s newer driver.
SHA156bee9df5833a637f5c54d5911df98b0812fe643SHA-1 of the PoisonX rootkit used by the GentleKiller G11 variant.
SHA15aa3124e5c4921e5edfc60133b5d71da21b07da3SHA-1 of a Themida-protected GentleKiller Valorant variant.
SHA168fec379f2ae76c3d2ce913f7be650cea1d06990SHA-1 of the newer Safetica Process Monitor driver abused by the GentleKiller Javelin variant.
SHA1711ef221526997039e804a18db9647c91680bbe2SHA-1 of the older Safetica Process Monitor driver abused by the GentleKiller Javelin variant.
SHA17131b377e96016dc1911020c9f95b1b4d042d7b4SHA-1 of ThrottleBlood incorporated into Gentlemen operations with its evasion layer.
SHA17556ae58c215b8245a43f764f0676c7a8f0fdd1aSHA-1 of an anti-cheat driver abused by the GentleKiller Valorant variant.
SHA182ed942a52cdcf120a8919730e00ba37619661a3SHA-1 of a driver abused by ThrottleBlood.
SHA18ae6bd18b129061f63642531f1b684cf0383c75dSHA-1 of a GentleKiller Kaspersky-variant sample.
SHA196f0dbf52aed0afd43e44500116b04b674f7358eSHA-1 of Zemana’s WatchDog Antimalware driver abused by the GentleKiller WatchDog variant.
SHA19ad51ad97c01e97ab59214116740785e0f6320a8SHA-1 of a Qihoo 360 driver abused by the GentleKiller Network Blocker variant.
SHA1a11ee9cdc59e5caa59aefd27b30d104f3ad68e62SHA-1 of a Themida-protected GentleKiller WatchDog variant.
SHA1a19117175dbc9ba4d23b5dce8415e299a2e32192SHA-1 of the GentleKiller Cleaner variant.
SHA1a5cf917ec4a7dfbdfa43621398604805d860c718SHA-1 of an OxideHarvest credential-stealer sample.
SHA1b0b912a3fd1c05d72080848ec4c92880004021a1SHA-1 of the NSecsoft NSecKrnl driver abused by the GentleKiller FACEIT Anti-Cheat variant.
SHA1ba914fe77b177b45799403b16dd14765c510a074SHA-1 of a custom rootkit used by the GentleKiller Kaspersky variant.
SHA1cf4d74df17a91b4a36a2911b22afec5d8fa93a01SHA-1 of HexKiller incorporated into Gentlemen operations with its evasion layer.
SHA1d29670e684e40ddc89b47010c37cbc96737035b6SHA-1 of a GentleKiller G11 variant.
SHA1d4b19141102015d436321e6f26976e98183cfd27SHA-1 of an OxideHarvest credential-stealer sample.
SHA1d605994fc72a2bb59b5cfb1624a1b9170eca73a2SHA-1 of an Enigma-protected GentleKiller FACEIT Anti-Cheat variant.
SHA1ec296f9501ad71e430810cb5cdc38d954d4ba536SHA-1 of the Baidu Antivirus BdApi driver abused by HexKiller.
SHA1ef9cd06683159397f099caa244e94e6eaad96ebaSHA-1 of a GentleKiller Javelin variant abusing both Safetica drivers.
SHA1f0537cbb773ae12100b36731e7c39f5a9d852b14SHA-1 of HavocKiller incorporated into Gentlemen operations with its evasion layer.
SHA1f11aebccb9a86a7e2e653f90baec697f233c255fSHA-1 of a GentleKiller Javelin variant abusing Safetica’s older driver.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

AcronisAcronisAlienVaultAlienVaultAvastAvastAVGAVGBaidugoogleApiUtil64.sys, Baidu Antivirus BdApi driverBinary DefenseBinary DefenseBitdefenderBitdefenderBlumiraBlumiraBromiumBromiumCarbon BlackCarbon BlackCisco TalosCisco TalosCrowdStrikeCrowdStrikeCybereasonCybereasonCylance/BlackBerryCylance/BlackBerryCynetCynetCyveraCyveraDarktraceDarktraceDeep InstinctDeep InstinctElasticElasticESETESET researchers analyzed the robust EDR-killing toolset of the ransomware-as-a-service gang Gentlemen.FortinetFortinetG DATAG DATAHeimdalHeimdalHuaweihavoc.sys, Huawei Audio driverHuntressHuntressIObitIMFForceDelete, IObit’s IMF ForceDelete filter driver (PoC); the driver is dropped without the trailing .sys extensionKasperskyKasperskyLogRhythmLogRhythmMcAfee/TrellixMcAfee/TrellixMicrosoftMicrosoft DefenderMorphisecMorphisecOSSEC/WazuhOSSEC/WazuhPalo Alto NetworksPalo Alto Networks (Traps/Cortex)Panda SecurityPanda SecurityQihoo 360 Technology360netmon_wfp.sys, a vulnerable driver by Qihoo 360 Technology (PoC)QualysQualysRapid7Rapid7Red CanaryRed CanarySafeticastpm_(old|new).sys, two vulnerable ProcessMonitor Driver samples by Safetica (PoC)SangforSangforSentinelOneSentinelOneSonicWallSonicWallSophosSophosSymantecNorton/SymantecTaniumTaniumTechPowerUp LLCThrottleBlood.sys, driver by TechPowerUp LLCThreatLockerThreatLockerTrendAITrendAIUptycsUptycsVaronisVaronisWatchGuardWatchGuardWebrootWebrootWindows SysinternalsWindows SysinternalsZemanadmx.sys, Zemana’s WatchDog Antimalware Driver (PoC)ZscalerZscaler

Products

Tools

buildx641However, as Check Point noted, a Gentlemen affiliate named quant maintains a tool referred to as buildx641, whose naming and functionality immediately reminded us of OxideHarvest.DemoKillerWe also saw DemoKiller in several intrusions, but this EDR killer did not exhibit any ties to Gentlemen and therefore we exclude it from the gang’s suite and instead consider it affiliate-specific.EDRKillShifterOne notable case is RansomHub, which invested in developing its own EDR killer from scratch, EDRKillShifter, and then offered it to affiliates through the affiliate panel.EnigmaAdvanced binary protection (Enigma or Themida) is applied to a significant portion of the samples we detected.GentleKillerof EDR killers that they offer to affiliates, centered around their in-house framework we have named GentleKiller.HavocKillerThey also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller.HexKillerThey also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller.OxideHarvestGentlemen also uses OxideHarvest, a credential stealer maintained by one of the group’s affiliates.PoisonKillerThis was the case with UnknownKiller and PoisonKiller, which were adopted within a matter of days.ThemidaAdvanced binary protection (Enigma or Themida) is applied to a significant portion of the samples we detected.ThrottleBloodThey also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller.UnknownKillerThis was the case with UnknownKiller and PoisonKiller, which were adopted within a matter of days.

Countries

Related Articles