Gentlemen Ransomware Terminates 180 Security Processes Before Encryption
Key Takeaways The Gentlemen ransomware employs a kernel-level driver, anticheatG13.sys, to disable nearly 180 security processes before initiating file encryption. This tactic targets a wide range of...
Key Takeaways
- The Gentlemen ransomware employs a kernel-level driver,
anticheatG13.sys, to disable nearly 180 security processes before initiating file encryption. - This tactic targets a wide range of endpoint defenses, including antivirus, EDR, backup agents, and monitoring software, significantly hindering detection and response efforts.
- The driver exhibits advanced capabilities such as process termination, memory manipulation, network redirection, and driver blocking, underscoring a sophisticated approach to evasion.
- The campaign highlights a growing trend in ransomware operations to incapacitate security tools as a primary step, rather than merely attempting to evade them.
- Defenders must prioritize monitoring for unusual driver activity, restricting administrative access, and maintaining robust, off-network backups to mitigate this escalating threat.
The Gentlemen ransomware operation has surfaced with an alarming strategy: systematically disabling a comprehensive array of security software before proceeding with data encryption. This tactic represents a significant escalation in ransomware sophistication, moving beyond mere stealth to actively dismantle the very tools designed to detect and neutralize such threats.
Table Of Content
This aggressive pre-encryption phase dramatically elevates the risk for organizations. By neutralizing antivirus programs and endpoint monitoring solutions, the attackers ensure that critical alerts are suppressed, and automated defenses are rendered inoperative precisely when they are most needed.
Advanced Kernel-Level Driver at Play
While the initial compromise vector for this campaign remains undisclosed, forensic analysis indicates that attackers meticulously prepare systems for encryption once they gain a foothold. Cybersecurity researchers at Catalyst identified the core malicious component as anticheatG13.sys. This kernel-level driver possesses extensive capabilities, including the manipulation of processes, network configurations, files, and system memory. Catalyst said in a report that this driver builds upon features observed in a related component, G12drv.sys.
This discovery aligns with a broader trend in the ransomware landscape where threat actors increasingly focus on neutralizing defensive measures prior to deploying their encryptors. Recent reports on ransomware EDR killer tactics have shown a shift towards directly targeting endpoint security tools, rather than solely attempting to conceal malicious activity from them.
Nearly 180 Security Processes Targeted
The Gentlemen ransomware operation leverages its specialized driver to terminate approximately 180 security-related processes before initiating the encryption of files. This extensive list includes antivirus software, endpoint detection and response (EDR) solutions, backup agents, and system monitoring tools. Such a sweeping pre-emptive strike severely limits a victim’s ability to receive warnings, respond to the intrusion, or halt the attack.
The driver is designed to execute process terminations via a system worker, confirming that this process-killing capability is an integral and deliberate function. Furthermore, it supports destructive operations on process memory, providing attackers with an alternative method to disrupt applications even if direct termination attempts fail.
.webp)
Beyond process manipulation, the anticheatG13.sys component includes functions for system enumeration, file-operation control, minifilter management, and kernel-memory modification. These advanced capabilities grant attackers an unusually deep level of access and control once the driver is successfully loaded onto a system.
The ramifications of such actions are profound. Security tools often serve as the initial line of defense, providing crucial alerts and telemetry when ransomware begins to spread. When these processes are systematically eliminated, organizations lose vital alerts, forensic data, and the ability to initiate automated containment measures during the critical window before sensitive data becomes encrypted and inaccessible.
Driver Abuse Expands Risk
The capabilities of this malicious driver extend beyond merely ending processes. Catalyst’s analysis revealed support for Windows Filtering Platform (WFP) connection redirection, enabling address whitelisting, command-line rewriting, and staged transfer features. These functions could allow attackers to manipulate network traffic and obscure their activities, further undermining defensive visibility.
.webp)
The driver can also inspect and block other drivers from loading, adding another sophisticated layer of defense evasion. This behavior mirrors a growing trend of abusing trusted or vulnerable Windows drivers to disable endpoint protections, as seen in various reports detailing trusted drivers killing EDR solutions.

What You Should Do
- Monitor for Unusual Driver Activity: Implement robust monitoring for unexpected driver installations, particularly those immediately preceding the cessation of security services. Focus on detecting suspicious IOCTL requests, as attackers can easily rename or modify malicious tools.
- Restrict Administrative Privileges: Enforce the principle of least privilege across all systems to limit the impact of a compromised account.
- Maintain Up-to-Date Vulnerable Driver Blocklists: Ensure that your systems leverage current blocklists for known vulnerable drivers that could be exploited by attackers.
- Segment Critical Systems: Isolate critical network segments to contain potential ransomware spread and limit access to high-value assets.
- Implement Protected Backups: Regularly back up critical data and store these backups offline or in immutable storage locations, completely separate from the main network.
- Develop and Rehearse an Incident Response Plan: Have a well-defined and rehearsed ransomware incident response plan. This enables rapid isolation of affected devices, preservation of forensic evidence, and swift restoration of operations, reducing the pressure to pay a ransom.
The Gentlemen ransomware campaign underscores that ransomware defense must extend far beyond the moment encryption begins. Detecting the termination of security processes, investigating newly loaded kernel drivers, and safeguarding recovery systems are critical steps that can provide defenders with a vital opportunity to interrupt an attack before business-critical data becomes irretrievably locked.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| File name | anticheatG13.sys |
Kernel-level driver analyzed by Catalyst; associated with process termination, network redirection, command-line rewriting, and other system-control features. |
| File name | G12drv.sys |
Related driver referenced by Catalyst as sharing core capabilities with anticheatG13.sys. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.