Gentlemen Ransomware Disables Security Software Before Encrypting Files

The Gentlemen ransomware group has intensified its attacks by systematically disabling security software prior to encrypting files, significantly increasing the risk for targeted organizations. This method involves terminating nearly 180 security-related processes, including antivirus programs, endpoint detection systems, backup agents, and monitoring tools, leaving victims vulnerable and with limited options to halt the intrusion.

Central to this strategy is the deployment of a kernel-level driver named anticheatG13.sys. This driver possesses extensive capabilities, such as manipulating processes, network configurations, file operations, and system memory. By leveraging these functions, the ransomware effectively neutralizes security defenses, facilitating the subsequent encryption of files without detection or interruption.

The exact initial access methods employed by The Gentlemen remain unspecified. However, the observed activities indicate that once the attackers establish a foothold within a system, they prepare it for encryption by disabling security measures. This approach aligns with a broader trend among ransomware operators who prioritize neutralizing defensive tools before deploying their payloads.

Beyond terminating security processes, the anticheatG13.sys driver exhibits additional functionalities that enhance the attackers’ control over compromised systems. These include:

  • System enumeration to gather detailed information about the target environment.
  • File operation controls that allow manipulation or deletion of critical files.
  • Management of minifilter drivers to intercept and modify file system operations.
  • Kernel-memory modifications that can alter system behavior at a fundamental level.

Furthermore, the driver supports Windows Filtering Platform connection redirection, address whitelisting, command-line rewriting, and staged transfer features. These capabilities enable attackers to manipulate network traffic, evade detection, and maintain persistence within the network.

The implications of such sophisticated tactics are profound. By disabling security tools, attackers not only prevent immediate detection but also hinder forensic investigations and automated containment efforts. This leaves organizations blind to the ongoing attack and delays response times, thereby increasing the likelihood of successful data encryption and exfiltration.

To mitigate the risks associated with such advanced ransomware attacks, organizations should adopt a multi-faceted defense strategy:

  • Monitor for unexpected driver installations, especially those occurring just before security services become unresponsive.
  • Implement strict administrative access controls to limit the ability of attackers to install or execute malicious drivers.
  • Maintain up-to-date blocklists of vulnerable drivers to prevent their exploitation.
  • Segment critical systems to contain potential breaches and limit lateral movement within the network.
  • Ensure the availability of protected backups stored separately from the main network to facilitate recovery without succumbing to ransom demands.

Additionally, organizations should develop and regularly rehearse incident response plans that include procedures for isolating affected devices, preserving forensic evidence, and restoring operations efficiently. Proactive monitoring for unusual driver activity and suspicious input/output control (IOCTL) requests can also provide early indicators of compromise, enabling swift action to mitigate potential damage.

The emergence of The Gentlemen ransomware underscores the evolving sophistication of cyber threats. Attackers are increasingly focusing on disabling security defenses as a precursor to deploying ransomware, highlighting the need for organizations to enhance their detection and response capabilities. By adopting a proactive and layered security approach, businesses can better defend against such advanced threats and minimize the impact of potential attacks.