Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Not very gentlemanly: Analyzing a zero-day exploit used to disable targets' EDRs

9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046

TLP:CLEAR
Active

SHA-256 Hash

Description

The Gentlemen ransomware group, which emerged in July 2025, employed a zero-day vulnerability in a bring-your-own-vulnerable-driver (BYOVD) attack to disable endpoint detection and response systems. During an incident investigated in early April, the group leveraged an obscure third-party driver named ktapi.sys from Kontron to bypass security protections. The sophisticated exploit chains multiple advanced techniques to navigate Windows exploit mitigations, including bypassing Supervisor Mode Access Prevention and Supervisor Mode Execution Prevention. The toolkit enables the attackers to call privileged kernel mode functions from user mode processes, ultimately terminating EDR processes including Windows Defender, ESET, Palo Alto Cortex XDR, and SentinelOne. The vulnerability had no prior public documentation and was previously absent from vulnerable driver blocklists.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Not very gentlemanly: Analyzing a zero-day exploit used to disable targets' EDRs
Pattern Type
STIX
Confidence
75%
Valid From
Jul 5, 2026 15:12
Total Sightings
0
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.