Security researchers report that the Gentlemen ransomware-as-a-service (RaaS) operation is building and maintaining a suite of tools designed to impair endpoint detection and response (EDR) defenses before the ransomware encryptor is deployed. The tools are described as being provided to affiliates and are used during attacks to evade detection by disrupting monitoring and security processes on targeted systems.
Across the reporting, researchers identify a central component of this approach referred to as the “GentleKiller” framework. The framework is described as being used to target and disable security-related processes—reported as numbering around 400—rather than relying on a single technique. The coverage also notes that the toolkit can incorporate third-party elements alongside the operation’s own components.
The overall assessment from the sources is that Gentlemen demonstrates a structured, repeatable pre-encryption capability focused on disabling defenders. This suggests operational maturity in preparation for affiliate-led intrusions, where weakening endpoint protections is treated as a prerequisite step before the ransomware payload is executed.