Security

The Gentlemen Ransomware Now Deploys a Kernel Driver That Kills Nearly 180 Security Processes

The Storm-2697 group behind The Gentlemen expanded its victim list and is using a kernel-level driver that terminates security tools before encryption, researchers reported this week.

M
By Marcus Webb Tech Editor
July 31, 2026 / 5 min read

The ransomware group tracked as Storm-2697, operating under the name The Gentlemen, has expanded its victim list and upgraded its tradecraft: researchers this week documented the group deploying a kernel-level driver, anticheatG13.sys, that can terminate nearly 180 security-related processes before encryption begins, according to analysis published by Mallory and covered by Risky.biz. The group uses double extortion, threatening to leak stolen data if ransoms are not paid.

New Victims

The group's claims this week include attacks on Dutch ice arena Thialf, U.S. IT firm Promatrix, Indian companies Delkart Industries, Kontact Consortium India, and Indus Protech Solutions, and the UK's Angel Hotel. Thialf said its forensic investigation found minimal impact, a common rebuttal from victims that researchers caution does not always hold up.

Pressure on INC Ransom

Separately, Crime Stoppers International is offering a $22,000 bounty for information leading to the identification, arrest, or disruption of INC Ransom, citing its repeated attacks on hospitals and critical infrastructure. INC was the sixth most active ransomware group in June and Q2 2026. The bounty is a rare private-sector escalation against a specific criminal crew, reflecting growing frustration as healthcare-targeting groups operate with impunity.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.