The Gentlemen centralized GentleKiller to disable about 400 security processes

Colleagues, a cybersecurity alert: the RaaS operation The Gentlemen has centralized an EDR-killer, GentleKiller.
ESET reports GentleKiller spoofs security products (versions, signatures, icons) and targets ≈400 processes from 48 vendors. Operators rapidly integrate PoC BYOVD exploits and abuse legitimate drivers, including PoisonX.sys. The OxideHarvest stealer is also observed stealing data from multiple browsers.
CERT/CC warned about vulnerable signed UEFI applications — admins should update DBX and monitor driver trust.
Why it matters: centralized EDR neutralization lowers the entry bar for affiliates and raises the risk of widespread attacks.
What steps do you consider priority to defend against BYOVD attacks?
#cybersecurity #ransomware #EDR #BYOVD

