VMTech
Discuss a project

The Gentlemen centralized GentleKiller to disable about 400 security processes

The Gentlemen centralized GentleKiller to disable about 400 security processes

Colleagues, a cybersecurity alert: the RaaS operation The Gentlemen has centralized an EDR-killer, GentleKiller.

ESET reports GentleKiller spoofs security products (versions, signatures, icons) and targets ≈400 processes from 48 vendors. Operators rapidly integrate PoC BYOVD exploits and abuse legitimate drivers, including PoisonX.sys. The OxideHarvest stealer is also observed stealing data from multiple browsers.

CERT/CC warned about vulnerable signed UEFI applications — admins should update DBX and monitor driver trust.

Why it matters: centralized EDR neutralization lowers the entry bar for affiliates and raises the risk of widespread attacks.

What steps do you consider priority to defend against BYOVD attacks?

#cybersecurity #ransomware #EDR #BYOVD

Open analytics
On the site 1 views
min read 1 19.06.2026
On Instagram 4 views
On Instagram 1 reach
Instagram

The Gentlemen centralized GentleKiller to disable about 400 security processes

Open the post on Instagram ↗