In May 2026, someone inside a ransomware crew got careless. An internal data leak from the gang known as Gentlemen spilled their chat logs into the open, and the logs told a story most defenders had only suspected. The gang’s leader was discussing a supply arrangement. Affiliates who rented the crew’s encryptors weren’t left to figure out how to disable endpoint protection on their own. They were handed a purpose-built tool to do it, maintained like any other product. That tool, tracked as GentleKiller, knows how to shut down more than 400 security processes across 48 separate products.

This is where a lot of cybersecurity programs quietly fall apart. The whole model assumes your detection layer keeps watching while an intrusion unfolds. GentleKiller is built on the premise that it won’t. And the gang behind it figured out that disabling your defenses is valuable enough to standardize, package, and ship to paying customers.

A laptop displaying a warning symbol, representing endpoint detection software being disabled by attackers
EDR killers are now maintained software, supplied to affiliates like any other product.

The defense everyone assumed was always on

Most ransomware-as-a-service operations leave the dirty work of killing endpoint security to the affiliate. That’s a meaningful detail. It means the skill of blinding an EDR used to be a bottleneck, something each operator had to solve on their own, often clumsily, often loudly enough to trip an alert. Gentlemen removed the bottleneck. Their operators develop and maintain the EDR-killer tooling centrally, then push it down to affiliates as part of the rental.

Think about what that does to the economics. The weakest, least technical affiliate in the program now arrives on your network with the same teardown capability as the gang’s best engineer. The 400-plus processes GentleKiller targets aren’t a random list. They map to the agents, services, and watchdog processes that real threat-protection suites rely on to stay alive. Kill the right handful and your console keeps showing green while encryption runs underneath it.

The uncomfortable part is how the tool gets on the box in the first place. It doesn’t kick the door in. It rides in behind valid access, the kind harvested from infostealer logs or carved out of an unpatched edge appliance. ShinyHunters spent the spring exploiting an Oracle PeopleSoft zero-day, CVE-2026-35273, against more than 100 organizations, with higher education taking the brunt of it. Once an attacker is inside with that level of access, an EDR killer is just the next step in a workflow, not a clever exploit.

Why “we have an EDR” stops being an answer

For years the honest answer to “are we covered” was “we deployed the agent.” GentleKiller turns that sentence into a liability. A control that can be switched off by a tool any affiliate now carries isn’t a guarantee. It’s a single point of failure dressed up as defense in depth.

The fix isn’t a better agent. It’s accepting that your detection layer is itself a target and building around that assumption. Defense in depth has always meant layering controls so no single failure is fatal. Apply that same logic to the security stack itself. The question you should be able to answer on demand: when my EDR goes quiet, who notices, how fast, and from where?

That “from where” matters more than people give it credit for. If the only place your endpoint telemetry lives is on the endpoint, an attacker who silences the agent has also silenced the evidence. Off-host logging changes the math. So does watching the agents themselves.

What to actually do this week

Start with the thing GentleKiller is designed to defeat, and make its absence loud. Configure alerts that fire when a security agent stops reporting, when its service is killed, or when tamper protection is disabled. The silence of a sensor should page someone the same way an alarm does. Too many shops only alert on what their EDR sees, never on the EDR going dark.

Get your telemetry off the host. Ship endpoint and authentication logs to a destination the local attacker can’t reach or wipe. If the agent dies but the last several minutes of behavior already left the building, you still have a thread to pull during incident response.

Turn on every tamper-protection feature your endpoint suite offers, then verify it from a second account rather than trusting the dashboard. Cut down local administrator rights, because most EDR-killer tooling needs elevation to touch protected processes. If standard users can’t elevate, the tool stalls before it starts.

Close the front door these affiliates lean on. The PeopleSoft and edge-appliance entry points are not exotic, they’re unpatched and exposed. Inventory your internet-facing systems, patch the known-exploited ones first, and put real brute-force controls and rate limiting on every authentication endpoint and management console. F5 just patched critical, unauthenticated NGINX flaws that can be driven to a crash or code execution; that class of bug is exactly the kind of foothold that precedes an EDR killer. Patch the edge before you worry about the encryptor.

Finally, rehearse the failure you’ve been avoiding. Run an incident response tabletop where the premise is that your EDR was disabled twenty minutes before you noticed. What detects the gap? What contains the host without the agent’s help? Who makes the call to isolate a segment using the firewall and network controls rather than the endpoint tool? Teams that have answered those questions on a quiet afternoon recover faster than teams meeting them for the first time at 2 a.m.

Frequently Asked Questions

Does tamper protection stop EDR killers like GentleKiller?
It raises the cost and stops the lazier tools, but it’s not absolute. Tools maintained as products evolve specifically to defeat current tamper defenses. Treat it as one layer, and pair it with off-host logging and alerts on agent silence so a bypass still leaves a trail.
If attackers can just turn off endpoint detection, is it worth deploying?
Yes. The point is that no single control should be load-bearing. Endpoint threat detection still catches the majority of intrusions that don’t bring a dedicated killer. The goal is to make its absence detectable, not to pretend it can’t be defeated.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.