Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Not very gentlemanly: Analyzing a zero-day exploit used to disable targets' EDRs

7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237

TLP:CLEAR
Active

SHA-256 Hash

Description

The Gentlemen ransomware group, which emerged in July 2025, employed a zero-day vulnerability in a bring-your-own-vulnerable-driver (BYOVD) attack to disable endpoint detection and response systems. During an incident investigated in early April, the group leveraged an obscure third-party driver named ktapi.sys from Kontron to bypass security protections. The sophisticated exploit chains multiple advanced techniques to navigate Windows exploit mitigations, including bypassing Supervisor Mode Access Prevention and Supervisor Mode Execution Prevention. The toolkit enables the attackers to call privileged kernel mode functions from user mode processes, ultimately terminating EDR processes including Windows Defender, ESET, Palo Alto Cortex XDR, and SentinelOne. The vulnerability had no prior public documentation and was previously absent from vulnerable driver blocklists.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Not very gentlemanly: Analyzing a zero-day exploit used to disable targets' EDRs
Pattern Type
STIX
Confidence
75%
Valid From
Jul 5, 2026 15:12
Total Sightings
0
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.