GentleKiller is a Windows endpoint-security disabling framework developed and maintained by operators of The Gentlemen ransomware-as-a-service operation and distributed to its affiliates. It is used after compromise to impair antivirus and endpoint detection and response protections before ransomware deployment. The associated operation is tracked as Storm-2697 by Microsoft and GOLD SHERWOOD by Sophos.
The framework includes at least eight variants that abuse different vulnerable or malicious kernel drivers. Its bring-your-own-vulnerable-driver (BYOVD) implementations load legitimately signed but vulnerable drivers and exploit their exposed functionality to disable security software at kernel level. GentleKiller repeatedly enumerates and terminates processes using a target list containing more than 400 process names associated with 48 security products, including Microsoft Defender, CrowdStrike, Sophos, and ESET. Specialized variants include Network Blocker, which abuses a signed Qihoo driver, and Cleaner, which uses a vulnerable IObit force-delete driver to remove protected files; the latter vulnerability is associated with CVE-2019-6494.
GentleKiller variants masquerade as legitimate security, anti-cheat, and corporate software through fabricated version information, vendor icons, and copied but invalid digital signatures. Commercial packers, including Enigma and Themida, provide an additional evasion layer. The operators centrally maintain these tools and have incorporated newly disclosed driver-abuse techniques within days of public release. GentleKiller is distinct from The Gentlemen's encryptors and from externally sourced EDR killers supplied alongside it.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ESET documents GentleKiller's Cleaner variant dropping this driver without the trailing .sys extension, and CVE-2019-6494 describes IOCTL 0x8016E000 allowing low-privileged users to delete files regardless of access controls.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET’s investigation, published in June 2026, identified a collection of EDR-disabling tools maintained by the Gentlemen operators. This includes an internally developed framework called GentleKiller.
EDR killers (BYOVD) — ESET a documenté en juin 2026 la fourniture aux affiliés d’une suite d’outils exploitant des drivers vulnérables. Variantes observées par la CTU : GentleKiller – Watchdog, GentleKiller – Javelin, GentleKiller – G11 et GentleKiller – FACEIT Anti-Cheat.
Operational ownership does not imply common code authorship. G12 and G13 show technical continuity with the GentleKiller line.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell GentleKiller and related tools are console-based executables that run visibly and emit debug strings during execution.
T1106 Native API User-mode components interact directly with kernel drivers via DeviceIoControl and other native Windows APIs to perform privileged actions.
The method is called bring your own vulnerable driver (BYOVD). Each build loads a legitimately signed but flawed kernel driver, then abuses it to kill security processes from inside the kernel, beyond the reach of user-mode protections.
Use Case Privileges Operating System Impair defenses through a signed kernel driver abused by an EDR killer.
T1027 Obfuscated Files or Information Some executables are protected with packers (e.g., Enigma, Themida) and custom control-flow obfuscation.
To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.
ESET counted at least eight GentleKiller variants, each impersonating a different legitimate product, with names lifted from games and security brands such as Valorant, FACEIT and Kaspersky... To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.
T1036.001 Masquerading: Invalid Code Signature The protection applied to Gentlemen’s EDR killers adds an invalid code signature as part of the impersonation strategy.
It either terminates each running process directly, unloads the EDR’s own kernel driver, deletes service registry keys to prevent restart, or all three.
The RaaS operators provide affiliates with a suite of custom and publicly available EDR-killing tools that abuse vulnerable drivers via the BYOVD (Bring Your Own Vulnerable Driver) technique.
He just hands Windows a file the system already trusts... a trusted-but-flawed file... Windows will still happily load it.
Attackers staged tools in the C:\PerfLogs directory ... not commonly scrutinized by security controls or administrators.
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An internally developed framework maintained by The Gentlemen operators to interfere with endpoint detection and response products that could detect or stop their attacks. ESET documented it in June 2026; the content does not establish its first discovery date or provide framework-specific implementation details.
Endpoint detection-and-response security-tool killer reportedly adopted by the Gentlemen ransomware group.
An endpoint detection and response (EDR) security-tool disabling utility reportedly employed by The Gentlemen ransomware group.
Suite d’outils de neutralisation EDR fournie aux affiliés de The Gentlemen. Elle abuse de pilotes vulnérables (BYOVD) et se décline notamment en variantes déguisées en composants anti-triche ou Watchdog afin de désactiver les défenses avant le chiffrement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.