Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
DeepSeek-Powered Hermes Agent Autonomous Cyberattacks Target Exposed Servers
July 31, 2026
ShutterGap Flaw Exposes AWS Resources Between Security Scans
July 31, 2026
Critical SolarWinds Web Help Desk Flaw (CVE-2024-28925) Bypasses SAML Login
July 31, 2026
Home/CyberSecurity News/Gentlemen Ransomware Terminates 180 Security Processes Before Encryption
CyberSecurity News

Gentlemen Ransomware Terminates 180 Security Processes Before Encryption

Key Takeaways The Gentlemen ransomware employs a kernel-level driver, anticheatG13.sys, to disable nearly 180 security processes before initiating file encryption. This tactic targets a wide range of...

Jennifer sherman
Jennifer sherman
July 31, 2026 5 Min Read
3 0

Key Takeaways

  • The Gentlemen ransomware employs a kernel-level driver, anticheatG13.sys, to disable nearly 180 security processes before initiating file encryption.
  • This tactic targets a wide range of endpoint defenses, including antivirus, EDR, backup agents, and monitoring software, significantly hindering detection and response efforts.
  • The driver exhibits advanced capabilities such as process termination, memory manipulation, network redirection, and driver blocking, underscoring a sophisticated approach to evasion.
  • The campaign highlights a growing trend in ransomware operations to incapacitate security tools as a primary step, rather than merely attempting to evade them.
  • Defenders must prioritize monitoring for unusual driver activity, restricting administrative access, and maintaining robust, off-network backups to mitigate this escalating threat.

The Gentlemen ransomware operation has surfaced with an alarming strategy: systematically disabling a comprehensive array of security software before proceeding with data encryption. This tactic represents a significant escalation in ransomware sophistication, moving beyond mere stealth to actively dismantle the very tools designed to detect and neutralize such threats.

Table Of Content

  • Key Takeaways
  • Advanced Kernel-Level Driver at Play
  • Nearly 180 Security Processes Targeted
  • Driver Abuse Expands Risk
  • What You Should Do
  • Indicators of Compromise (IoCs)

This aggressive pre-encryption phase dramatically elevates the risk for organizations. By neutralizing antivirus programs and endpoint monitoring solutions, the attackers ensure that critical alerts are suppressed, and automated defenses are rendered inoperative precisely when they are most needed.

Advanced Kernel-Level Driver at Play

While the initial compromise vector for this campaign remains undisclosed, forensic analysis indicates that attackers meticulously prepare systems for encryption once they gain a foothold. Cybersecurity researchers at Catalyst identified the core malicious component as anticheatG13.sys. This kernel-level driver possesses extensive capabilities, including the manipulation of processes, network configurations, files, and system memory. Catalyst said in a report that this driver builds upon features observed in a related component, G12drv.sys.

This discovery aligns with a broader trend in the ransomware landscape where threat actors increasingly focus on neutralizing defensive measures prior to deploying their encryptors. Recent reports on ransomware EDR killer tactics have shown a shift towards directly targeting endpoint security tools, rather than solely attempting to conceal malicious activity from them.

Nearly 180 Security Processes Targeted

The Gentlemen ransomware operation leverages its specialized driver to terminate approximately 180 security-related processes before initiating the encryption of files. This extensive list includes antivirus software, endpoint detection and response (EDR) solutions, backup agents, and system monitoring tools. Such a sweeping pre-emptive strike severely limits a victim’s ability to receive warnings, respond to the intrusion, or halt the attack.

The driver is designed to execute process terminations via a system worker, confirming that this process-killing capability is an integral and deliberate function. Furthermore, it supports destructive operations on process memory, providing attackers with an alternative method to disrupt applications even if direct termination attempts fail.

Attack chain (Source - Catalyst)
Attack chain (Source – Catalyst)

Beyond process manipulation, the anticheatG13.sys component includes functions for system enumeration, file-operation control, minifilter management, and kernel-memory modification. These advanced capabilities grant attackers an unusually deep level of access and control once the driver is successfully loaded onto a system.

The ramifications of such actions are profound. Security tools often serve as the initial line of defense, providing crucial alerts and telemetry when ransomware begins to spread. When these processes are systematically eliminated, organizations lose vital alerts, forensic data, and the ability to initiate automated containment measures during the critical window before sensitive data becomes encrypted and inaccessible.

Driver Abuse Expands Risk

The capabilities of this malicious driver extend beyond merely ending processes. Catalyst’s analysis revealed support for Windows Filtering Platform (WFP) connection redirection, enabling address whitelisting, command-line rewriting, and staged transfer features. These functions could allow attackers to manipulate network traffic and obscure their activities, further undermining defensive visibility.

Affiliate Panel Login Page (Source - Catalyst)
Affiliate Panel Login Page (Source – Catalyst)

The driver can also inspect and block other drivers from loading, adding another sophisticated layer of defense evasion. This behavior mirrors a growing trend of abusing trusted or vulnerable Windows drivers to disable endpoint protections, as seen in various reports detailing trusted drivers killing EDR solutions.

Image-load inspection callback (Source - Catalyst)
Image-load inspection callback (Source – Catalyst)

What You Should Do

  • Monitor for Unusual Driver Activity: Implement robust monitoring for unexpected driver installations, particularly those immediately preceding the cessation of security services. Focus on detecting suspicious IOCTL requests, as attackers can easily rename or modify malicious tools.
  • Restrict Administrative Privileges: Enforce the principle of least privilege across all systems to limit the impact of a compromised account.
  • Maintain Up-to-Date Vulnerable Driver Blocklists: Ensure that your systems leverage current blocklists for known vulnerable drivers that could be exploited by attackers.
  • Segment Critical Systems: Isolate critical network segments to contain potential ransomware spread and limit access to high-value assets.
  • Implement Protected Backups: Regularly back up critical data and store these backups offline or in immutable storage locations, completely separate from the main network.
  • Develop and Rehearse an Incident Response Plan: Have a well-defined and rehearsed ransomware incident response plan. This enables rapid isolation of affected devices, preservation of forensic evidence, and swift restoration of operations, reducing the pressure to pay a ransom.

The Gentlemen ransomware campaign underscores that ransomware defense must extend far beyond the moment encryption begins. Detecting the termination of security processes, investigating newly loaded kernel drivers, and safeguarding recovery systems are critical steps that can provide defenders with a vital opportunity to interrupt an attack before business-critical data becomes irretrievably locked.

Indicators of Compromise (IoCs)

Type Indicator Description
File name anticheatG13.sys Kernel-level driver analyzed by Catalyst; associated with process termination, network redirection, command-line rewriting, and other system-control features.
File name G12drv.sys Related driver referenced by Catalyst as sharing core capabilities with anticheatG13.sys.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareransomwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

CMMC Phase 2 Paused, Contractors Must Still Meet Data Security Obligations

Next Post

PHP Patches Critical SQL Injection, Memory Corruption Flaws

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
PHP Patches Critical SQL Injection, Memory Corruption Flaws
July 31, 2026
Gentlemen Ransomware Terminates 180 Security Processes Before Encryption
July 31, 2026
CMMC Phase 2 Paused, Contractors Must Still Meet Data Security Obligations
July 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us