The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The Gentlemen ransomware-as-a-service (RaaS) operation is utilizing a sophisticated suite of EDR-terminating tools, centered around the GentleKiller framework, to disable security defenses before deploying ransomware. They achieve this by rapidly operationalizing newly disclosed proof-of-concept (PoC) exploits, often within days of release, and employing a variety of third-party tools like HexKiller and ThrottleBlood. The group, led by Alexander Andreevich Yapaev, has already impacted over 500 victims globally, primarily in Southeast Asia, South America, and Western Europe, and is known for its technical agility and focus on bypassing detection.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
