Security researchers have uncovered GentleKiller, an advanced Endpoint Detection and Response (EDR) disabling framework used by the Gentlemen Ransomware-as-a-Service (RaaS) group. Before deploying ransomware, the framework systematically terminates security products, significantly reducing an organization's ability to detect and respond to attacks. The research highlights a growing trend where ransomware operators provide affiliates with sophisticated defensive evasion tools, lowering the barrier for successful ransomware campaigns. GentleKiller is an in-house framework consisting of at least eight variants, each impersonating legitimate software while abusing a different vulnerable or malicious kernel-mode driver. The framework primarily leverages the Bring Your Own Vulnerable Driver (BYOVD) technique, enabling attackers to load signed but exploitable drivers that operate with kernel privileges. This allows the malware to bypass user-mode protections and forcibly terminate security software before ransomware execution. The framework continuously scans infected systems every few seconds and attempts to terminate processes associated with over 400 security processes across 48 endpoint security products, including Microsoft Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky, McAfee/Trellix, and others. Researchers also observed that the Gentlemen operators rapidly integrate newly published BYOVD proof-of-concept exploits into their toolkit, often within days of public disclosure. This operational model provides affiliates with centrally maintained EDR-killing capabilities, making ransomware deployments faster, more reliable, and harder to detect.
Tata Electronics has confirmed that it recently experienced a cybersecurity incident, affecting portions of its information technology environment. According to the company, the is...
Phishing attacks continue to evolve, incorporating advanced techniques such as multi-stage redirects, dynamically loaded content, embedded iframes, and browser-executed scripts. Th...
India based automotive manufacturer Bajaj Auto has disclosed a ransomware incident that impacted its corporate IT environment and the systems of its technology subsidiary, Bajaj Au...