The Gentlemen: New Ransomware Shuts Down Nearly 180 Security Processes Before Encrypting Data

6.8.2026 | Autor: Top privacy
5

The Gentlemen ransomware can shut down nearly 180 security processes before encrypting data. Find out how the attack works and how to protect yourself.

The Gentlemen: New Ransomware Shuts Down Nearly 180 Security Processes Before Encrypting Data

Security analysts at Catalyst have documented a new ransomware operation called The Gentlemen, which is characterized by an aggressive approach to disabling security software even before the actual encryption of files. The attackers do not rely solely on rapid encryption—they first systematically attempt to remove tools that could detect, block, or limit the attack.

The exact method of initial system access has not been disclosed, but the activity indicates that once the attackers have gained a foothold, they thoroughly prepare the system for the deployment of encryption.

How the Attack Worked

At the core of the operation is a kernel driver named anticheatG13.sys, which Catalyst identified as an extension of an older component, G12drv.sys. It is a highly privileged tool with deep access to processes, network communication, files, and system memory.

The driver is capable of independently terminating nearly 180 security processes—including antivirus tools, endpoint detection tools, backup agents, and monitoring software—even before the encryption process begins. Process termination occurs via a system worker that waits for the operation’s result, confirming that this is a targeted and deliberate function, not a side effect.

In addition, the driver supports:

  • destructive operations on process memory (disrupting applications even without successfully terminating them)
  • redirecting network communication through the Windows Filtering Platform
  • overwriting command lines and whitelisting addresses
  • controlling the loading of other drivers and selectively blocking them

This combination of features allows attackers not only to “turn off the alarm,” but also to actively limit the visibility of defensive tools and control network traffic throughout the entire attack.

Why This Is Dangerous

Security tools are often the first indication that ransomware is spreading across a network. When these processes disappear, defenders lose alerts, forensic records, and automated actions to stop the attack—precisely during the brief window while documents, databases, and shared files are still being encrypted.

The Gentlemen case fits into a broader trend where attackers target EDR and security processes directly, rather than simply hiding their code from them.

What to Do

We recommend that organizations:

  • Monitor for unusual driver installations, especially immediately before security services go down or stop responding
  • Monitor for suspicious IOCTL requests—relying solely on file signatures is not enough; attackers rename and modify their tools
  • Maintain an up-to-date blocklist of vulnerable/untrusted drivers
  • Restrict administrative access and segment critical systems
  • Keep backups secure and isolated from the main network
  • Have a prepared and tested incident response plan—rapidly isolating devices and preserving evidence is crucial before making any decision regarding a ransom payment

The Gentlemen case shows that defense against ransomware cannot begin only when encryption starts. Detecting missing security processes and investigating new kernel drivers can give defenders a real chance to stop the attack before data becomes inaccessible.


OUR SERVICES
Source: Cyber Security News / Catalyst


Top privacy

Top privacy

“High-quality content isn't created by copywriters, but by experts.”