The Gentlemen ransomware operation is drawing attention for its aggressive effort to disable security software before locking files. Instead of relying only on fast encryption, the attackers attempt to remove the tools that could detect, block, or contain the attack. This approach raises the risk for businesses because antivirus and endpoint monitoring tools may be silenced when they are needed most. The campaign’s exact initial access method was not detailed, but the activity shows attackers preparing systems for encryption after obtaining a foothold. Catalyst analysts identified the malware component as anticheatG13.sys, a kernel-level driver with broad capabilities for manipulating processes, networking, files, and system...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!