July 29, 2026
- ESET is tracking 100+ EDR killers, with 60+ still relying on BYOVD against legitimate-but-vulnerable drivers. The team notes the Gentlemen gang runs a shared defense-evasion layer — in-house GentleKiller plus third-party and leaked tools — and can operationalize new BYOVD PoCs within days, a supply they expect to grow as actors weaponize thousands of vulnerable drivers with AI coding assistance (ESET).
· Threat Activity
in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route
June 20, 2026
- ESET dissected GentleKiller, the in-house EDR-killer at the core of the Gentlemen RaaS portfolio — eight variants, each impersonating a legitimate product, collectively targeting 400+ processes mapped to 48 security products, and combined with externally sourced HexKiller, ThrottleBlood, and HavocKiller. A leak of Gentlemen's own data also linked an affiliate to a stealer ESET named OxideHarvest; IoCs are published. The Hacker News, WeLiveSecurity
· Ransomware & Extortion
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
- ESET dissected the Gentlemen RaaS EDR-killer framework: in-house GentleKiller (8 variants, each impersonating a legit product, targeting 400+ processes) plus externally sourced HexKiller, ThrottleBlood and HavocKiller; a recent data leak confirmed the toolset and linked an affiliate to a stealer dubbed OxideHarvest. The gang focuses on Southeast Asia, South America and Western Europe (BleepingComputer, ESET/WeLiveSecurity).
· Ransomware
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk