The Gentlemen ransomware operation is garnering increased scrutiny due to its sophisticated method of disabling security software before locking up files This article explores ransomware operation garnering. . This discovery aligns with broader ransomware trends where criminals focus on disabling defenses before deploying encryptors.
Recent incidents have shown attackers targeting endpoint tools directly, rather than just hiding malicious code from them, as previously covered in ransomware EDR killer tactics reports. When processes disappear during this brief window, defenders may lose alerts, forensic records, and automated containment actions, potentially allowing attackers to encrypt documents, databases, and shared files before defenses can react.
Driver Abuse Widens Threats Catalyst has revealed support for advanced features like Windows Filtering Platform connection redirection and address whitelisting, which could enable attackers to manipulate network traffic and obscure defensive visibility. Similar to how trusted or vulnerable Windows drivers are exploited by criminals to bypass endpoint protections, organizations should be vigilant about unexpected driver installations around the time security services cease functioning or become ineffective. A well-prepared response plan can help staff quickly isolate affected devices, preserve evidence, and swiftly restore operations without making rash decisions, as detailed in this guide for ransomware incident response planning.
Signatures of Compromise (IoCs): Type Indicator Description File name anticheatG13.sys Kernel-level driver analyzed by Catalyst; associated with process termination, network redirection, command-line rewriting, and other system-control features.












