GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes

A highly sophisticated EDR-killing framework, dubbed GentleKiller, was used by the Gentlemen ransomware-as-a-service (RaaS) gang to systematically disable endpoint security tools before deploying its ransomware payload. The findings by ESET, published on June 17, 2026, detail how Gentlemen, one of the most active ransomware gangs in Q1 2026, provides affiliates with a centralized, operator-maintained suite […]

The post GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: