#
ESETresearch analyzed the robust EDR-killer toolset of the RaaS gang Gentlemen. Thanks to our continued incident-level visibility, we could provide a uniquely deep view into the group’s EDR-killer development practices.
welivesecurity.com/en/eset-res…Gentlemen was one of the most active RaaS gangs in Q1 2026. Unlike the majority of top-tier gangs, which target the US [🇺🇸], Gentlemen goes after victims across Southeast Asia, South America, and Western Europe.
Gentlemen operators develop and maintain a suite of EDR killers, combining an in-house tool, GentleKiller, with externally sourced tooling (HexKiller, ThrottleBlood, and HavocKiller). The gang applies a standardized set of defense evasion techniques across its portfolio.
GentleKiller is Gentlemen’s most prevalent EDR killer. We found eight distinct variants of the tool, each impersonating a different legitimate product. Across all builds, GentleKiller targets more than 400 processes, which we mapped with the help of AI to 48 products.
We hypothesized that GentleKiller was an internal tool in February 2026, and the recent leak of Gentlemen data confirmed our suspicions. The leaked data also allowed us to link one of Gentlemen’s affiliates to a credential stealer we named OxideHarvest.
IoCs available in our GitHub repo:
github.com/eset/malware-ioc/tr…ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen
www.welivesecurity.com
Luca Sironi
in reply to Lorenzo • • •per colpa di questi grandi loacker, ci perderemo pure DecTalk 😐
#retrocomputing
Lorenzo likes this.