Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Not very gentlemanly: Analyzing a zero-day exploit used to disable targets' EDRs

c277ae5a4dd62f51de5278790796cd2700de7f77ea17762e97729f27872d076b

TLP:CLEAR
Active

SHA-256 Hash

Description

The Gentlemen ransomware group, which emerged in July 2025, employed a zero-day vulnerability in a bring-your-own-vulnerable-driver (BYOVD) attack to disable endpoint detection and response systems. During an incident investigated in early April, the group leveraged an obscure third-party driver named ktapi.sys from Kontron to bypass security protections. The sophisticated exploit chains multiple advanced techniques to navigate Windows exploit mitigations, including bypassing Supervisor Mode Access Prevention and Supervisor Mode Execution Prevention. The toolkit enables the attackers to call privileged kernel mode functions from user mode processes, ultimately terminating EDR processes including Windows Defender, ESET, Palo Alto Cortex XDR, and SentinelOne. The vulnerability had no prior public documentation and was previously absent from vulnerable driver blocklists.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Not very gentlemanly: Analyzing a zero-day exploit used to disable targets' EDRs
Pattern Type
STIX
Confidence
75%
Valid From
Jul 5, 2026 15:12
Total Sightings
0
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of c277ae5a4dd62f51de5278790796cd2700de7f77ea17762e97729f27872d076b

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.