1. Executive summary
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and distributing a suite of endpoint detection and response (EDR) killer tools to its affiliates, with the primary tool — dubbed GentleKiller — available in at least eight variants that impersonate legitimate security products (Kaspersky, Valorant, Javelin, WatchDog). The framework leverages the "bring your own vulnerable driver" (BYOVD) technique to obtain kernel-level privileges and terminate more than 400 security processes spanning approximately 48 vendor products, including Microsoft Defender, CrowdStrike, SentinelOne, Palo Alto Cortex, Sophos, Trend Micro, ESET, Bitdefender, McAfee/Trellix, and Kaspersky. Three additional external EDR killers (HexKiller, ThrottleBlood, HavocKiller) and a Rust-based credential stealer (OxideHarvest) supplement the toolkit. Target selection is reportedly driven by FortiGate endpoint configuration, raising supply-chain and concentration-risk concerns for EMEA financial services firms operating Fortinet infrastructure. Attribution to a named actor is unconfirmed in the verified reference data; treat the "Gentlemen" branding as a campaign label pending further intelligence.
2. Regulatory framing
| Article | Trigger (fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17 | Ransomware incident response requires a defined ICT-related incident management process; Gentlemen's EDR-killer chain is a foreseeable incident scenario. | Financial entities must ensure incident response playbooks cover BYOVD-driven EDR tampering and credential theft (OxideHarvest). |
| DORA Art. 18 | The threat constitutes a classifiable ICT-related incident and cyber threat (ransomware + EDR killer + credential stealer). | Incidents must be classified against the entity's ICT-incident taxonomy and the competent authority's reporting thresholds. |
| DORA Art. 19 | A successful Gentlemen intrusion producing encryption or data exfiltration is a major ICT-related incident requiring competent-authority reporting. | Reporting timelines and content per competent-authority specifications must be observed. |
| DORA Art. 24 | EDR effectiveness must be tested; the framework specifically targets 48+ security products. | Digital operational resilience testing must validate EDR/AV resilience to BYOVD kernel attacks and process-killing logic. |
| DORA Art. 28 | FortiGate is an ICT third-party provider; OxideHarvest and external EDR killers introduce third-party tooling risk. | Third-party risk management must cover Fortinet appliances and any embedded third-party tooling in the security stack. |
| DORA Art. 29 | Target selection is reportedly driven by FortiGate endpoint configuration, indicating potential ICT concentration risk. | Entities must assess concentration risk on Fortinet/FortiGate and document mitigations. |
| DORA Art. 30 | FortiGate contractual provisions must address incident response cooperation and vulnerability disclosure. | Contracts must enable rapid forensic access and patch obligations for FortiGate devices. |
| NIS2 Art. 21(2)(d) | The FortiGate supply chain is implicated in target selection; FortiBleed credential exposure affects the supply chain. | In-scope entities must apply supply-chain security measures covering Fortinet devices and credential hygiene. |
| NIS2 Art. 23 | A successful ransomware incident triggers incident reporting obligations. | Early warning and incident notification timelines must be observed. |
| UK NIS 2018 | UK OES/RDSP duties apply where the entity is an operator of essential services or relevant digital service provider. | Incident reporting duties under UK NIS 2018 apply to qualifying incidents. |
3. Technical analysis & attack chain
- Target identification via FortiGate configuration. Gentlemen affiliates reportedly select targets based on the configuration of victim FortiGate endpoints. This is contextualised against the recent "FortiBleed" exposure of approximately 74,000 FortiGate VPN credentials, suggesting credential-driven targeting of Fortinet estates.
- Initial access (vector not specified in source). The source material does not confirm the initial access vector used by Gentlemen affiliates; treat this as unconfirmed.
- Deployment of EDR-killer framework. Affiliates deploy GentleKiller (primary tool, ≥8 variants) plus at least three external EDR killers — HexKiller (previously attributed to the Warlock gang), ThrottleBlood (linked to MesudaLocker and DragonForce), and HavocKiller — for redundancy or scenario-specific use.
- BYOVD privilege escalation. Each GentleKiller variant loads a different vulnerable kernel driver to obtain kernel-level execution. The framework is architected to allow driver swaps or weaponisation of newly disclosed flaws without major code changes.
- EDR/AV termination. The driver is used to enumerate and terminate more than 400 processes associated with approximately 48 security vendors/products, including Microsoft, CrowdStrike, SentinelOne, Palo Alto, Sophos, Trend Micro, ESET, Bitdefender, McAfee/Trellix, and Kaspersky.
- Credential theft (OxideHarvest). A Rust-based credential stealer named OxideHarvest is deployed; the choice of Rust suggests external development rather than in-house tooling.
- Hands-on-keyboard activity. With EDR neutralised, affiliates proceed with data theft and encryption using the Gentlemen encryptor.
- Persistence / C2. The group has been linked to a SystemBC proxy malware botnet comprising over 1,570 hosts believed to be corporate victims, indicating proxy-based command-and-control infrastructure.
- Impact. Confirmed impact includes the compromise of the Romanian energy provider Oltenia. Encryption and data theft are the operational outcomes.
Technical specifics that matter to a defender
- Impersonation filenames: GentleKiller variants masquerade as Kaspersky, Valorant, Javelin, and WatchDog binaries.
- Packers: Binaries are protected by the commercial packers Enigma and Themida.
- Code signing: Threat actors use stolen digital signatures from legitimate software; signatures are invalid.
- Code reuse: All GentleKiller variants share common strings, identical obfuscation techniques, and similar process-killing logic and targeting scope — enabling family-level detection.
- Driver flexibility: The framework is modular; new vulnerable drivers can be swapped in without recompiling the process-killing logic.
- Tooling redundancy: Three external EDR killers (HexKiller, ThrottleBlood, HavocKiller) are bundled for redundancy, attribution complexity, or scenario-specific use.
- Credential theft: OxideHarvest is Rust-based; treat as externally developed and likely shared across multiple operations.
Unconfirmed / single-sourced claims: The FortiGate-driven targeting logic and the FortiBleed linkage are reported by a single research source and should be treated as unconfirmed pending corroboration. Attribution to a named actor "Gentlemen" is unconfirmed in the verified reference data; treat the brand as a campaign label.
4. Mitigation & containment
P1 — within 24 hours
- Enable HVCI / Kernel-mode Driver Block List on Windows endpoints to block known vulnerable drivers from loading. Apply via Group Policy:
Computer Configuration > Administrative Templates > System > Driver Installation > Code signing for drivers. - Enforce Microsoft Vulnerable Driver Block List (
HVCIandMicrosoft Vulnerable Driver Block Listpolicies) on all Windows 10/11 endpoints and Windows Server 2019+. - Block known EDR-killer driver hashes at EDR/AV gateway; prioritise any hashes provided by ESET or vendor partners.
- Audit FortiGate estate for indicators of compromise and rotate any credentials potentially exposed via FortiBleed; force MFA reset on FortiGate administrative accounts.
- Hunt for impersonation filenames (Kaspersky, Valorant, Javelin, WatchDog) in process trees and on disk; quarantine any unsigned or invalid-signature binaries matching these names.
P2 — within 72 hours
- Patch and harden FortiGate devices to the latest vendor-recommended firmware; review configuration against vendor hardening guides.
- Review EDR tamper-protection settings; ensure tamper protection is enabled and protected by a dedicated credential not stored on the endpoint.
- Restrict kernel driver loading via WDAC (Windows Defender Application Control) policies that allow only signed drivers from approved vendors.
- Credential rotation for any account that may have interacted with FortiGate management interfaces; force password resets and revoke active sessions.
- Threat hunt for OxideHarvest (Rust binary) and SystemBC proxy indicators across endpoints; review egress for known SystemBC C2 patterns.
P3 — within 7 days
- Tabletop exercise covering BYOVD-driven EDR tampering and post-EDR-kill response procedures.
- Validate EDR detection coverage against the 48 vendor products targeted; ensure alerting on process-killing logic and driver-load events.
- Third-party risk review of Fortinet under DORA Art. 28/29/30 obligations; document concentration risk and contractual incident-response clauses.
- Supply-chain security review under NIS2 Art. 21(2)(d) covering FortiGate supply chain and credential hygiene.
5. Indicators of compromise
| Type | Value | Confidence | Source |
|---|---|---|---|
| tool | GentleKiller (≥8 variants impersonating Kaspersky, Valorant, Javelin, WatchDog) | High | ESET WeLiveSecurity |
| tool | HexKiller (external EDR killer, previously used by Warlock) | High | ESET WeLiveSecurity |
| tool | ThrottleBlood (external EDR killer, linked to MesudaLocker/DragonForce) | High | ESET WeLiveSecurity |
| tool | HavocKiller (external EDR killer) | High | ESET WeLiveSecurity |
| tool | OxideHarvest (Rust-based credential stealer) | High | ESET WeLiveSecurity |
| packer | Enigma | High | ESET WeLiveSecurity |
| packer | Themida | High | ESET WeLiveSecurity |
| technique | BYOVD (Bring Your Own Vulnerable Driver) | High | ESET WeLiveSecurity |
| botnet | SystemBC proxy botnet (1,570+ hosts) | Medium | ESET WeLiveSecurity |
| target | FortiGate endpoint configuration-driven selection | Low | ESET WeLiveSecurity (single-sourced) |
tool GentleKiller
tool HexKiller
tool ThrottleBlood
tool HavocKiller
tool OxideHarvest
packer Enigma
packer Themida
technique BYOVD
6. Detection
rule Gentlemen_EDRKiller_Strings
{
meta
{
author = "Adverse Trace"
date = "2026-06-19"
reference = "https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/"
description = "Detects Gentlemen EDR-killer family (GentleKiller, HexKiller, ThrottleBlood, HavocKiller) based on shared strings, packer artefacts and impersonation filenames"
}
strings:
$a1 = "GentleKiller" ascii wide
$a2 = "HexKiller" ascii wide
$a3 = "ThrottleBlood" ascii wide
$a4 = "HavocKiller" ascii wide
$a5 = "OxideHarvest" ascii wide
$b1 = "Enigma" ascii wide
$b2 = "Themida" ascii wide
$c1 = "Kaspersky" ascii wide
$c2 = "Valorant" ascii wide
$c3 = "Javelin" ascii wide
$c4 = "WatchDog" ascii wide
$d1 = "SystemBC" ascii wide
condition:
3 of ($a*, $b*, $c*, $d*)
}
title: 'Suspicious Process Killing Activity Targeting EDR/AV Products'
id: AT-2026-06-19-129-001
description: 'Detects process termination patterns consistent with Gentlemen EDR-killer framework targeting 400+ security processes across 48 vendors.'
status: experimental
author: Adverse Trace
date: 2026-06-19
references:
- https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/
logsource:
product: windows
category: process_termination
detection:
selection_process_names:
- 'Kaspersky*'
- 'Valorant*'
- 'Javelin*'
- 'WatchDog*'
selection_drivers:
DriverLoadEvents:
ImageLoaded: '*'
Signed: 'false'
condition: selection_process_names or selection_drivers
falsepositives:
- Legitimate uninstallers from named vendors
- Internal security testing tools
level: high
7. Sources
- BleepingComputer — Gentlemen ransomware uses multiple EDR killers to disable defenses (2026-06-18). https://www.bleepingcomputer.com/news/security/gentlemen-ransomware-uses-multiple-edr-killers-to-disable-defenses/
- Help Net Security — GentleKiller targets more than 400 security processes across 48 products (2026-06-18). https://www.helpnetsecurity.com/2026/06/18/eset-gentlemen-edr-killers/
- ESET WeLiveSecurity — Killing me gently: Inside Gentlemen's EDR killer framework (2026-06-18). https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/
8. Adverse Trace position
Severity: High. The Gentlemen framework combines a modular BYOVD EDR-killer (GentleKiller, ≥8 variants) with three external EDR killers and a Rust-based credential stealer (OxideHarvest), targeting 48+ security products and selecting victims based on FortiGate configuration. For EMEA financial services, the immediate risk is loss of endpoint visibility during the critical early phase of an attack, enabling encryption and data exfiltration. Client impact: Entities running Fortinet infrastructure should treat this as a credible threat to EDR effectiveness and FortiGate integrity; DORA/NIS2 obligations on incident management, classification, reporting, testing, third-party risk, concentration risk, contractual provisions, supply-chain security, and incident reporting are engaged as set out in Section 2. Next steps: Adverse Trace will (a) monitor for GentleKiller driver hashes and C2 indicators as ESET and partners publish them, (b) update detection content for the 48 targeted vendors, and (c) issue a follow-up advisory if FortiBleed credential exposure is confirmed to intersect with client FortiGate estates. Attribution to a named actor remains unconfirmed in the verified reference data; treat "Gentlemen" as a campaign label pending further intelligence.
Published via PulseTrace — Adverse Trace threat intelligence.