Killing Me Gently: Inside Gentlemen’s EDR Killer Framework

    Date: 06/19/2026

    Severity: Medium

    Summary

    Researchers analyzed the robust EDR-killing toolset of the prominent ransomware gang Gentlemen. Since early 2026, the group has become one of the most active threats in the ecosystem. They stand out by maintaining sophisticated tools designed to disrupt security software. Unlike peers, Gentlemen targets Southeast Asia, South America, and Western Europe over the US. While previous reports overlooked their EDR killers, Gained a deep, unique view into them. A May 2026 internal data leak further revealed the inner workings of the group's development.

    Indicators of Compromise (IOC) List

    Hash : 

    8AE6BD18B129061F63642531F1B684CF0383C75D

    BA914FE77B177B45799403B16DD14765C510A074

    D605994FC72A2BB59B5CFB1624A1B9170ECA73A2

    B0B912A3FD1C05D72080848EC4C92880004021A1

    5AA3124E5C4921E5EDFC60133B5D71DA21B07DA3

    7556AE58C215B8245A43F764F0676C7A8F0FDD1A

    331879F5EEC8892BBD896F90BDBB1BAD0BF63BD6

    F11AEBCCB9A86A7E2E653F90BAEC697F233C255F

    EF9CD06683159397F099CAA244E94E6EAAD96EBA

    711EF221526997039E804A18DB9647C91680BBE2

    68FEC379F2AE76C3D2CE913F7BE650CEA1D06990

    A11EE9CDC59E5CAA59AEFD27B30D104F3AD68E62

    96F0DBF52AED0AFD43E44500116B04B674F7358E

    2F86898528C6CAB3540C486A9BFAA0C029B73950

    9AD51AD97C01E97AB59214116740785E0F6320A8

    A19117175DBC9BA4D23B5DCE8415E299A2E32192

    12500F6C87CE62712A0ED6652C57468D15C14223

    D29670E684E40DDC89B47010C37CBC96737035B6

    56BEE9DF5833A637F5C54D5911DF98B0812FE643

    CF4D74DF17A91B4A36A2911B22AFEC5D8FA93A01

    EC296F9501AD71E430810CB5CDC38D954D4BA536

    7131B377E96016DC1911020C9F95B1B4D042D7B4

    82ED942A52CDCF120A8919730E00BA37619661A3

    F0537CBB773AE12100B36731E7C39F5A9D852B14

    1FA071303FB846308571E64727501FB98B1C2BE6

    A5CF917EC4A7DFBDFA43621398604805D860C718

    D4B19141102015D436321E6F26976E98183CFD27

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    sha1hash IN ("2F86898528C6CAB3540C486A9BFAA0C029B73950","BA914FE77B177B45799403B16DD14765C510A074","96F0DBF52AED0AFD43E44500116B04B674F7358E","B0B912A3FD1C05D72080848EC4C92880004021A1","56BEE9DF5833A637F5C54D5911DF98B0812FE643","68FEC379F2AE76C3D2CE913F7BE650CEA1D06990","12500F6C87CE62712A0ED6652C57468D15C14223","F0537CBB773AE12100B36731E7C39F5A9D852B14","EC296F9501AD71E430810CB5CDC38D954D4BA536","1FA071303FB846308571E64727501FB98B1C2BE6","A5CF917EC4A7DFBDFA43621398604805D860C718","D605994FC72A2BB59B5CFB1624A1B9170ECA73A2","82ED942A52CDCF120A8919730E00BA37619661A3","711EF221526997039E804A18DB9647C91680BBE2","9AD51AD97C01E97AB59214116740785E0F6320A8","7556AE58C215B8245A43F764F0676C7A8F0FDD1A","D4B19141102015D436321E6F26976E98183CFD27","8AE6BD18B129061F63642531F1B684CF0383C75D","5AA3124E5C4921E5EDFC60133B5D71DA21B07DA3","331879F5EEC8892BBD896F90BDBB1BAD0BF63BD6","F11AEBCCB9A86A7E2E653F90BAEC697F233C255F","EF9CD06683159397F099CAA244E94E6EAAD96EBA","A11EE9CDC59E5CAA59AEFD27B30D104F3AD68E62","A19117175DBC9BA4D23B5DCE8415E299A2E32192","D29670E684E40DDC89B47010C37CBC96737035B6","CF4D74DF17A91B4A36A2911B22AFEC5D8FA93A01","7131B377E96016DC1911020C9F95B1B4D042D7B4")

    Reference:    

    https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/   


    Tags

    Threat ActorRansomwareSoutheast AsiaEuropeUnited StatesSouth America

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags