FeedMalwareGentlemen ransomware uses multiple EDR killers to disable de...
MalwareBleeping Computer
8.5CRITICAL

Gentlemen ransomware uses multiple EDR killers to disable defenses

📅 18 June 2026 at 22:31 UTC📰 Bleeping ComputerView original source ↗
Gentlemen ransomware uses multiple EDR killers to disable defenses

The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Gentlemen ransomware-as-a-service is using multiple EDR killers to evade detection, targeting over 400 processes associated with approximately 48 security vendors/products.

⚙️Technical Details
Affected Systems
FortiGate endpoints
Attack Vectors
BYOVD techniqueElevating privileges and disabling security engines
💥Impact Assessment
Severity: high
Who Is at Risk
Corporate victims, particularly those with FortiGate endpoints
🛡️Recommended Actions
1Implement regular software updates for FortiGate endpoints
2Monitor system logs for suspicious activity and enable EDR rules
3Conduct breach and attack simulation tests to identify vulnerabilities in SIEM and EDR systems
📦Affected Products
FortiGate endpointsMicrosoft productsCrowdStrike productsSentinelOne productsPalo Alto productsSophos productsTrend Micro productsESET productsBitdefender productsMcAfee/Trellix productsKaspersky products

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed