The Gentlemen ransomware operation is drawing attention for its aggressive effort to disable security software before locking files. Instead of relying only on fast encryption, the attackers attempt to remove the tools that could detect, block, or contain the attack.
This approach raises the risk for businesses because antivirus and endpoint monitoring tools may be silenced when they are needed most.
The campaign’s exact initial access method was not detailed, but the activity shows attackers preparing systems for encryption after obtaining a foothold.
Catalyst analysts identified the malware component as anticheatG13.sys, a kernel-level driver with broad capabilities for manipulating processes, networking, files, and system memory.
Catalyst said in a report shared with Cyber Security News (CSN) that the driver expands on features found in a related component named G12drv.sys.
The discovery fits a broader ransomware trend in which criminals focus on disabling defenses before deploying the encryptor.
Recent incidents have shown that attackers increasingly target endpoint tools directly rather than trying only to hide malicious code from them, as covered in reports on ransomware EDR killer tactics.
Nearly 180 Security Processes Targeted
The Gentlemen ransomware operation reportedly uses the driver to terminate nearly 180 security-related processes before file encryption begins.
This tactic can remove antivirus, endpoint detection, backup agents, and monitoring software, leaving a victim with fewer warnings and fewer options to stop the intrusion.
The driver can run process termination through a system worker and wait for the result, indicating that process killing is a deliberate part of its design.
It also supports destructive process-memory operations, which may allow attackers to disrupt selected applications even when a direct termination attempt does not succeed.

The component also includes system enumeration, file-operation controls, minifilter management, and kernel-memory modification functions, giving attackers unusually deep access once the driver is loaded.
The impact can be severe because security tools often provide the first signal that ransomware is spreading.
When those processes disappear, defenders may lose alerts, forensic records, and automated containment actions during the short window before documents, databases, and shared files are encrypted.
Driver Abuse Expands Risk
The driver’s functions go beyond ending processes. Catalyst documented support for Windows Filtering Platform connection redirection, address whitelisting, command-line rewriting, and staged transfer features, which could help an attacker control network traffic and interfere with defensive visibility.

It can also inspect driver loads and block selected drivers, adding another layer of defense evasion.
This behavior resembles the wider abuse of trusted or vulnerable Windows drivers, where criminals use highly privileged code to disable endpoint protections, as explained in coverage of trusted drivers killing EDR.
Organizations should watch for unexpected driver installations, especially immediately before security services stop or become unresponsive.
Monitoring unusual driver activity and suspicious IOCTL requests can be more useful than relying only on file signatures, because attackers can rename, modify, or replace their tools.

Teams should also restrict administrative access, keep vulnerable-driver blocklists current, segment critical systems, and retain protected backups outside the main network.
A rehearsed response plan can help staff isolate affected devices quickly, preserve evidence, and restore operations without rushing into a ransom decision, as outlined in this guide to ransomware incident response planning.
The Gentlemen case shows why ransomware defense cannot begin only when encryption starts.
Detecting the disappearance of security processes, investigating new kernel drivers, and protecting recovery systems can give defenders a meaningful chance to interrupt an attack before business data becomes inaccessible.
Indocators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.