Inside Gentlemen’s EDR killer framework

ESET researchers have conducted a thorough analysis of the advanced EDR-killing toolset used by the ransomware-as-a-service gang known as Gentlemen. Since the beginning of 2026, Gentlemen has emerged as a prominent player in the ransomware landscape, showcasing a sophisticated set of endpoint detection and response (EDR) killers maintained by their operators. Unlike many other top-tier ransomware groups, Gentlemen does not exclusively target victims in the US, but instead focuses on victims across Southeast Asia, South America, and Western Europe.

Despite the recent attention on Gentlemen, detailed analysis of the group’s EDR killers has been lacking until now. Thanks to ESET’s deep insight into the group’s activities, we can offer a comprehensive view of Gentlemen’s EDR-killer development practices. A data leak in May 2026 provided even more information on the group’s operations, confirming that Gentlemen actively develops and maintains a range of EDR killers for their affiliates, including their proprietary framework called GentleKiller, as well as third-party tools like HexKiller, ThrottleBlood, and HavocKiller.

Gentlemen’s ability to quickly adapt to new EDR killer proofs-of-concept, along with their global victim targeting strategy, sets them apart as one of the most technically agile ransomware-as-a-service gangs in 2026. This blogpost aims to provide actionable insights into Gentlemen’s EDR killers, connecting them to real-world samples and tactics used by the group.

Key points highlighted in the blogpost include Gentlemen’s in-house development of EDR killers, their unified evasion strategy across tools, integration of third-party EDR killers, and their global victim targeting approach. The blogpost also delves into Gentlemen’s use of OxideHarvest, a credential stealer used by one of the group’s affiliates.

In addition to detailing Gentlemen’s operations, the blogpost provides insights into the distinction between RaaS operators and affiliates, shedding light on their respective roles and responsibilities within the ransomware ecosystem. Gentlemen’s unique approach of actively developing and providing EDR killers to affiliates sets them apart from other ransomware groups, highlighting their technical sophistication and operational efficiency.

Overall, Gentlemen’s focus on global victim targeting and proactive development of EDR killers for affiliates showcases their unique position in the ransomware landscape, making them a significant player to watch in 2026. Victims are primarily selected based on their FortiGate (mis)configuration rather than their geographic location.

EDR Killers
In February 2026, a previously unknown EDR killer known as GentleKiller was discovered during an intrusion linked to the Gentlemen group. This tool, along with others such as HexKiller, HavocKiller, and ThrottleBlood, are used by Gentlemen affiliates and obtained through unknown means. While GentleKiller is developed in-house by Gentlemen operators, the other EDR killers are likely sourced externally and modified to fit the gang’s toolset. The gang also offers EDR-disabling capabilities as part of their RaaS program, as reported by Group-IB and Check Point.

Defense Evasion Strategy
Gentlemen operators use specific defense evasion techniques for their EDR killers, such as applying advanced binary protection and using filenames that resemble legitimate software vendors in the cybersecurity domain. Executables are designed to impersonate these vendors with fabricated version information, invalid digital signatures, and matching icons. Despite some deviations, most EDR killers follow this standardized pattern.

GentleKiller
GentleKiller is the most prevalent EDR killer in the Gentlemen ecosystem, with multiple variants impersonating different legitimate products and targeting various security solutions. The tool is designed for ease of deployment and operational flexibility for affiliates, with shared internal characteristics and minimal modifications across variants. GentleKiller targets over 400 processes related to 48 products, showcasing its widespread impact in the cybersecurity landscape. Vendor Targeted processes
Acronis acronis_agent.exe, BackupAndRecoveryAgent.exe, managementagenthost.exe, mms.exe
AlienVault alienvault-agent.exe, osqueryd.exe
Avast afwServ.exe, aswEngSrv.exe, aswidsagent.exe, aswToolsSvc.exe, AvastSvc.exe, AvastUI.exe, avastsvc.exe, avastui.exe, bccavsvc.exe, wsc_proxy.exe
AVG AVGUI.exe, AVGSvc.exe, avgnt.exe, avgsvca.exe, avgToolsSvc.exe
Binary Defense BinaryDefenseAgent.exe
Bitdefender Arrakis3.exe, BDAvScanner.exe, BDFsTray.exe, BDFileServer.exe, BDLived2.exe, BDLogger.exe, BDScheduler.exe, BDStatistics.exe, bdagent.exe, bdemsrv.exe, bdntwrk.exe, bdredline.exe, bdregsvr2.exe, bdservicehost.exe
Blumira BlumiraAgent.exe
Bromium BromiumDaemon.exe, BrDifxapi.exe
Carbon Black cb.exe, cbcomms.exe, cbdefense.exe, carbonsensor.exe, RepMgr.exe
Cisco Talos cfrutil.exe, CiscoAMPCEFWDriver.exe, cisco_amp_connector.exe, immunet.exe
CrowdStrike ARWSRVC.EXE, ARCUpdate.exe, CSFalconContainer.exe, CSFalconService.exe, CSFalconUI.exe, csfalcondataprotect.exe, csfalcondaterepair.exe, REPRSVC.EXE
Cynet CynetEPS.exe, CynetMS.exe, CynetSvc.exe
Cybereason ActiveConsole.exe, cybereason.exe, CybereasonActiveProbe.exe, CybereasonCR.exe
Cyvera CyveraConsole.exe, CyveraService.exe, CyvrAgentSvc.exe, CyvrFsFlt.exe, cyvrfsflt.exe
Cylance/BlackBerry CylanceSvc.exe
Darktrace DarktraceTSA.exe
Deep Instinct DeepInstinct.exe, DeepInstinctService.exe, DIAgentService.exe
Elastic a2guard.exe, a2service.exe
ESET eamonm.exe, eamsi.exe, ecls.exe, efwd.exe, egui.exe, eguiProxy.exe, ekrn.exe, ekrnEpfw.exe, ERAAgent.exe, EraAgentSvc.exe
Fortinet firesvc.exe, firetray.exe, FortiTray.exe, fortiedr.exe, fw.exe
G DATA GDDServer.exe, QHPISVR.EXE, QUHLPSVC.EXE, SAPISSVC.EXE
Heimdal HeimdalsecurityAgent.exe
Huntress HuntressAgent.exe, HuntressRMM.exe
Kaspersky avp.exe, avpsus.exe, avpui.exe, kavfs.exe, kavfsscs.exe, kavfswh.exe, kavfswp.exe, kavtray.exe, klactprx.exe, klcsldcl.exe, klcsweb.exe, klnagent.exe, klnagchk.exe, klscctl.exe, klserver.exe, klwtblfs.exe, kpf4ss.exe, ksde.exe, ksdeui.exe, vapm.exe
LogRhythm LogProcessorService.exe
McAfee/Trellix AGMService.exe, AGSService.exe, masvc.exe, macmnsvc.exe, McAfeeAgent.exe, mcshield.exe, mfeann.exe, mfevtps.exe, mfetp.exe, mfeepehost.exe, mfefire.exe, mfemactl.exe, mfemacsvc.exe, mfemgr.exe, mfemms.exe, MgntSvc.exe, ModuleCoreService.exe, tepfsvc.exe
Microsoft Defender MSASCui.exe, MSASCuiL.exe, MpDefenderCoreService.exe, MsMpEng.exe, MsMpSvc.exe, MsSense.exe, msascuil.exe, msseces.exe, NisSrv.exe, nissrv.exe, SecurityHealthService.exe, SecurityHealthSystray.exe, SenseCncProxy.exe, SenseIR.exe, SenseNdr.exe, SenseSampleUploader.exe, smartscreen.exe, windefend.exe
Morphisec MorphisecService.exe
Norton/Symantec ccApp.exe, ccSvcHst.exe, ccsvchst.exe, ns.exe, nsservice.exe, nortonsecurity.exe, rtvscan.exe, SepMasterService.exe, sepWscSvc64.exe, smc.exe, SmcGui.exe, snac.exe, SymCorpUI.exe, SymWSC.exe
OSSEC/Wazuh ossec-agent.exe, wazuh-agent.exe
Palo Alto Networks (Traps/Cortex) cortexService.exe, trapsagent.exe, trapsd.exe, Traps.exe
Panda Security panda_url_filtering.exe, pavfnsvr.exe, pavsrv.exe, psanhost.exe, PSANHost.EXE, pselamsvc.EXE, PSUAMain.EXE, PSUAService.EXE, pangps.exe
Qualys qualys-cloud-agent.exe, QualysAgent.exe
Rapid7 ir_agent.exe, rapid7_endpoint.exe
Red Canary RedCanaryAgent.exe
Sangfor CSAAgent.exe, CSAService.exe, SangforAgent.exe, SangforCSA.exe, SangforEDR.exe, SangforInterface.exe, SangforMonitor.exe, SangforProtect.exe, SangforService.exe, SangforTray.exe, SangforUD.exe
SentinelOne Sentinel.exe, SentinelAgent.exe, SentinelAgentWorker.exe, SentinelCtl.exe, SentinelHelperService.exe, SentinelMemoryScanner.exe, SentinelPowerShellExtension.exe, SentinelRanger.exe, SentinelServiceHost.exe, SentinelStaticEngine.exe, SentinelStaticEngineScanner.exe, SentinelUI.exe
SonicWall SonicWallClientProtectionService.exe, swc_service.exe
Sophos hmpalert.exe, McsAgent.exe, McsClient.exe, SavApi.exe, SAVAdminService.exe, SAVService.exe, SEDService.exe, SophosADSyncService.exe, SophosClean.exe, SophosCleanM64.exe, SophosFIMService.exe, SophosFS.exe, SophosHealth.exe, SophosLiveQueryService.exe, SophosMTR.exe, SophosMTRExtension.exe, SophosNetFilter.exe, SophosNtpService.exe, SophosOsquery.exe, SophosOsqueryExtension.exe, Sophos.PolicyEvaluation.Service.exe, SophosSafestore64.exe, SophosUI.exe, SophosUpdateMgr.exe, sophosav.exe, sophossps.exe, SSPService.exe
Tanium TaniumClient.exe, TaniumCX.exe, tanclient.exe
ThreatLocker ThreatLockerConsent.exe, threatlockerservice.exe, threatlockertray.exe
TrendAI coreFrameworkHost.exe, coreServiceShell.exe, NTRTScan.exe, ntrtscan.exe, Ntrtscan.exe, OfcService.exe, ofcDdaSvr.exe, PccNTMon.exe, PccNt.exe, TISafe.exe, TISafeSvc.exe, TmCCSF.exe, tmicAgentSetting.exe, TMBMSRV.exe, Tmbmsrv.exe, tm_netsrv.exe, TmListen.exe, tmntsrv.exe, TmPfw.exe, tmproxy.exe, TmProxy.exe, TmPreFilter.exe, TmSSClient.exe, TmsaInstance64.exe, TmWscSvc.exe, VOneAgentConsole.exe, VOneAgentConsoleTray.exe
Uptycs VectorAgent.exe, UptycsAgent.exe
Varonis DatAdvantage.exe, VaronisAgent.exe
WatchGuard wlcsservice.exe
Webroot WRSA.exe, WRSkyClient.exe, WRSVC.exe, wrsa.exe
Windows Sysinternals Sysmon.exe, Sysmon64.exe
Zscaler zlclient.exe The tool logs into specified hosts using the credentials provided, utilizes multithreading, and extracts credentials into the designated output file. The output of the –help command for OxideHarvest is depicted in Figure 9, and Table 5 displays its configuration for targeting specific credentials. Rewrite the sentence as follows:

Please rewrite the sentence.

Leave a Reply

Your email address will not be published. Required fields are marked *