started · updated
Gentlemen ransomware deploys driver to disable ~180 security processes
The Gentlemen ransomware campaign has been found to load a kernel‑level driver called anticheatG13.sys, which deliberately terminates nearly 180 security‑related processes—including antivirus, endpoint detection and response (EDR) tools, backup agents and monitoring software—before encrypting files. Disabling these defenses removes early warnings and containment options, raising the risk for affected organizations.
Analysts note that this tactic is part of a broader trend in ransomware operations, where “EDR killers” are used to neutralize protection mechanisms. Research from ESET highlights a variety of methods, from vulnerable drivers (BYOVD) to legitimate anti‑rootkit utilities and driver‑less approaches. The proliferation of such tools complicates attribution, as the same driver or script can appear in unrelated ransomware families, and commercial “EDR‑killer as a service” kits further blur responsibility.
The combined findings underscore a growing emphasis on defense evasion in ransomware, posing heightened challenges for cyber‑defense teams worldwide.
Entities
ESET · Endpoint Detection and Response (EDR) · Gentlemen ransomware · anticheatG13.sys driver · cybercriminal affiliates