ThrottleBlood is a Windows bring-your-own-vulnerable-driver tool used to disable endpoint security products during ransomware intrusions. It has been repeatedly observed in MedusaLocker affiliate operations and, less frequently, in DragonForce activity, and was later incorporated by The Gentlemen into its affiliate-facing evasion toolkit as an externally sourced component rather than an in-house development. The tool abuses a signed but vulnerable kernel driver associated with TechPowerUp to gain kernel-level capability and terminate or otherwise neutralize security software, functioning as an EDR killer prior to ransomware deployment. In Gentlemen operations, ThrottleBlood has been wrapped in the group’s broader defense-evasion and impersonation layer alongside other anti-EDR utilities, indicating operational reuse across multiple ransomware ecosystems. Its role is primarily to suppress defensive controls and facilitate subsequent stages such as data theft, encryption, and broader post-compromise activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Known Infection Vectors ... BYOVD kernel driver exploit CVE-2025-7771 ThrottleStop.sys driver for kernel code execution ... Common Vulnerabilities Exploited CVE-2025-7771 TechPowerUp ThrottleStop.sys Kernel code execution via vulnerable driver (BYOVD) High Integrated as ThrottleBlood.sys | The gang also integrates third-party EDR killers HexKiller, ThrottleBlood, and HavocKiller into a standardized, modular evasion suite.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ThrottleBlood, seen in MedusaLocker and DragonForce intrusions.
Besides GentleKiller, the suite also contains HexKiller, HavocKiller, and ThrottleBlood.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
ESET’s assessment is that all three were acquired externally by the operators and then standardized with the same defense evasion layer applied to GentleKiller: binary protection via Enigma or Themida, filenames mimicking security vendors, fabricated version information, copied digital signatures, and matching icons.
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell GentleKiller and related tools are console-based executables that run visibly and emit debug strings during execution.
T1027 Obfuscated Files or Information Some executables are protected with packers (e.g., Enigma, Themida) and custom control-flow obfuscation.
To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.
Stealth T1036 Masquerading Gentlemen’s EDR killers are protected by impersonating legitimate vendors through filenames, version information, icons, and copied digital certificates.
T1036.001 Masquerading: Invalid Code Signature The protection applied to Gentlemen’s EDR killers adds an invalid code signature as part of the impersonation strategy.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A BYOVD EDR killer using the vulnerable ThrottleStop driver for kernel-level security process termination.
A named EDR-killer or security-disabling tool that has been observed in intrusions involving MedusaLocker and DragonForce, and is listed as part of the Gentlemen portfolio.
A third-party EDR killer used in ransomware-related intrusions and incorporated into Gentlemen’s suite. It abuses ThrottleBlood.sys, a driver by TechPowerUp LLC, to impair security tools.
An EDR killer integrated into Gentlemen’s suite that abuses a TechPowerUp LLC driver. It was previously observed in MedusaLocker and DragonForce intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.