The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
Gentlemen ransomware-as-a-service (RaaS) uses a suite of endpoint detection and response (EDR) killers to impair system defenses before deploying the encryptor. The Gentlemen group has developed eight variants of GentleKiller, targeting 400 processes associated with 48 di…
Intelligence analysis by Qwen 2.5 (3B)

The Gentlemen RaaS operation is developing and maintaining a suite of EDR-terminating tools for its affiliates to use in attacks. They have created a framework called GentleKiller that impersonates legitimate vendors using fake version information, copied certificates, and icons.
The Gentlemen RaaS group is making tools that pretend to be security programs, but are actually bad guys trying to stop them from working properly. They do this by copying fake information and using special drivers to trick the system.
Analysis
{"# A Sophisticated Attack Framework":"The Gentlemen RaaS operation has developed a suite of endpoint detection and response (EDR) killers, including eight variants of GentleKiller, to target security processes. These tools are designed to evade detection by impersonating legitimate vendors.","
Impersonation Techniques":"GentleKiller uses fake version information, copied certificates, and icons to mimic legitimate products. This approach makes it difficult for EDR systems to identify the malicious activity.","
Targeted Security Processes":"The Gentlemen RaaS operation targets 400 processes associated with 48 distinct security programs. These include Kaspersky, FACEIT Anti-Cheat, and other popular security vendors' products. The use of BYOVD (Bring Your Own Vulnerable Driver) techniques further complicates detection.","# Operational Flexibility":"The Gentlemen RaaS group centralizes the EDR-killer function by offering a standardized suite to affiliates. This decision makes it easier for affiliates to integrate these tools into their operations, reducing development effort and operational flexibility.","# BYOVD Attacks":"The Gentlemen RaaS operation has used BYOVD techniques in multiple campaigns, including one that targeted CrowdStrike Falcon EDR. The use of drivers like 'PoisonX.sys' allows them to terminate security tooling before deploying the encryptor.","# Vulnerable UEFI Applications":"CERT/CC issued an advisory about vulnerabilities in vendor-signed UEFI applications that can be exploited for Secure Boot bypass via BYOVD attacks. This highlights the importance of updating the UEFI Forbidden Signature Database (DBX) to prevent vulnerable applications from executing during boot."}
Key points
- GentleKiller is a suite of eight variants used by The Gentlemen RaaS operation to target security processes
- The Gentlemen RaaS group uses BYOVD techniques in their attacks, targeting popular security vendors' products
- CERT/CC issued an advisory about vulnerabilities in vendor-signed UEFI applications that can be exploited for Secure Boot bypass via BYOVD attacks
If The Gentlemen RaaS can continue to develop these sophisticated EDR-terminating tools, it could make their job easier for affiliates, potentially leading to more successful attacks.
The use of BYOVD techniques and fake information by The Gentlemen RaaS group poses a significant threat to security systems. It also highlights the need for robust EDR frameworks and regular updates to UEFI applications.



