GentleKiller: Inside the Ransomware Framework Disabling 400+ EDR Security Products
ESET researchers have exposed GentleKiller, the in-house EDR-killing framework of the Gentlemen ransomware gang, capable of disabling over 400 security processes across 48 products using BYOVD kernel driver...
‘The Gentlemen’ Ransomware: Self-Propagating Go Encryptor Uses SYSTEM Scheduled Tasks to Lock Entire Networks
A new Go-based ransomware called The Gentlemen (tracked as Storm-2697 by Microsoft) spreads automatically across networks using eight simultaneous propagation methods, escalates to SYSTEM privileges via scheduled tasks,...
Inside The Gentlemen: The Fastest-Growing Ransomware-as-a-Service Operation of 2026 — 332 Victims, Leaked Playbook Exposed
The Gentlemen, a ransomware-as-a-service operation that emerged in mid-2025, has claimed approximately 332 victims in the first five months of 2026 alone by targeting Fortinet and Cisco edge...
VECT 2.0 Ransomware Permanently Destroys Files Over 128 KB Due to Encryption Flaw
A critical encryption bug in VECT 2.0 ransomware permanently destroys all files larger than 128 KB rather than encrypting them, making recovery impossible even after paying the ransom....
Qilin Ransomware Adopts Stealthy RDP History Enumeration to Map Victim Networks
The Qilin ransomware group, responsible for over 700 attacks in 2025, has been observed using a stealthy PowerShell technique to enumerate RDP authentication history on compromised servers —...
LockBit 5.0 Ransomware-as-a-Service Platform Claims 207 Victims After Criminal Relaunch
LockBit has relaunched with a new LockBit 5.0 Ransomware-as-a-Service platform, already claiming 207 victims across manufacturing, healthcare, government, and construction sectors. The upgrade demonstrates the resilience of RaaS...