GMER is a legitimate Windows rootkit detection and removal utility that threat actors abuse to identify and forcibly terminate processes, including antivirus and endpoint detection and response components. It is a dual-use security tool rather than a malware family; its rootkit-scanning functionality does not make it a rootkit.
Ransomware operators deploy GMER after compromising systems to impair endpoint defenses before subsequent malicious activity. Its use has been observed in Ryuk, Trigona, and NoEscape intrusions. In Ryuk attacks, operators used it to locate processes and attempt to shut down antivirus protection after ransomware execution was blocked. Trigona affiliates deployed it alongside other defense-impairment utilities before using a custom data-exfiltration tool. NoEscape attackers included it among several tools and drivers used in attempts to disable antivirus and EDR. These uses establish GMER's role as an abused post-compromise utility, not as the ransomware payload or an initial-access mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"They then deployed GMER, a 'rootkit detector' tool... used by ransomware actors to find and shut down hidden processes... and antivirus software..."
10 distinct techniques documented for this family, organized by ATT&CK tactic.
More sophisticated affiliates weaponize legitimate anti-rootkit programs, such as GMER and PC Hunter. These tools were originally built to remove deep-kernel malware, but their elevated privileges make them ideal weapons for terminating active security processes.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool used by the attackers as part of disabling endpoint protections prior to data theft and ransomware deployment.
A tool used by the attackers in conjunction with vulnerable-driver techniques to disable or bypass endpoint protection.
Tool referenced in the context of BYOVD/defense-evasion used by ransomware groups to disable security products prior to encryption.
A rootkit scanner noted here as usable for forcibly terminating processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.