Executive Summary
In early 2024, the Gentlemen ransomware group executed a sophisticated attack leveraging a vulnerable version of the ThrottleStop.sys driver to disable antivirus and endpoint detection and response (EDR) systems. By exploiting this signed but flawed driver, the attackers were able to gain kernel-level privileges, terminate security defenses, and deploy ransomware effectively across targeted organizations. The impact resulted in rapid file encryption, significant operational disruption, and increased ransom demands as incident response capabilities were bypassed.
This incident highlights the growing trend of ransomware operators abusing trusted, vulnerable drivers to evade security controls. The ease with which attackers weaponize driver vulnerabilities underscores the urgent need for organizations to enhance driver and device control, patch management, and implement Zero Trust security strategies.
Why This Matters Now
Adversaries increasingly exploit vulnerable and legitimately signed drivers to neutralize modern security protections, making such attacks challenging to detect and block. Organizations must address these weaknesses proactively as ransomware groups like Gentlemen continue to innovate with new evasion techniques that quickly undermine traditional defenses.
Attack Path Analysis
Attackers initially compromised the environment using a vulnerable driver to disable security solutions. They escalated their privileges by leveraging the compromised host and deployed the ransomware payload. Using lateral movement techniques, attackers spread across internal systems, seeking additional workloads to encrypt. Command and control were maintained to orchestrate the attack and issue further instructions, likely leveraging allowed or covert channels. The adversary prepared to exfiltrate or encrypt data assets before triggering the ransomware. The impact culminated in the disabling of defenses and ransomware deployment, leading to operational disruption and potential data loss.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited a vulnerable ThrottleStop.sys driver to gain entry and initial execution, allowing them to disrupt EDR and antivirus protections.
Related CVEs
CVE-2025-7771
CVSS 8.7ThrottleStop.sys driver exposes IOCTL interfaces allowing arbitrary read/write access to physical memory, enabling local attackers to execute code in kernel context, leading to privilege escalation and potential disabling of security software.
Affected Products:
TechPowerUp ThrottleStop – 3.0.0.0 and possibly others
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Boot or Logon Autostart Execution: Driver Installation
Impair Defenses: Disable or Modify Tools
Exploitation for Privilege Escalation
Indirect Command Execution
Service Stop
Data Encrypted for Impact
Disk Wipe: Disk Content Wipe
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Render PAN Unreadable Anywhere It Is Stored
Control ID: 10.5.5
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Art. 9(1)
CISA ZTMM 2.0 – Continuous Security Monitoring
Control ID: Monitoring and Visibility.P3
NIS2 Directive – Incident Handling Capabilities
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Gentlemen ransomware targeting security drivers poses critical threat to financial institutions requiring robust endpoint protection for compliance and customer data protection.
Health Care / Life Sciences
Healthcare systems face severe risk as ransomware disabling EDR systems threatens patient data security and HIPAA compliance requirements for medical devices.
Information Technology/IT
IT sector extremely vulnerable as Gentlemen ransomware specifically targets security infrastructure, potentially compromising managed services and client protection capabilities.
Government Administration
Government agencies face heightened risk from driver-based ransomware attacks that bypass security controls, threatening critical infrastructure and sensitive citizen data.
Sources
- 'Gentlemen' Ransomware Abuses Vulnerable Driver to Kill Security Gearhttps://www.darkreading.com/vulnerabilities-threats/gentlemen-ransomware-vulnerable-driver-security-gearVerified
- NVD - CVE-2025-7771https://nvd.nist.gov/vuln/detail/CVE-2025-7771Verified
- AV Killer Malware Uses ThrottleStop.sys Vulnerabilityhttps://securelist.com/av-killer-exploiting-throttlestop-sys/117026/Verified
- TechPowerUp ThrottleStop Downloadhttps://www.techpowerup.com/download/techpowerup-throttlestop/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic controls, inline IPS, and policy-driven egress restrictions could have severely constrained the ransomware's ability to laterally move, establish command and control, or exfiltrate data—even if endpoint security was bypassed.
Control: Inline IPS (Suricata)
Mitigation: Malicious driver activity or exploit signatures would trigger detection or block at the network layer.
Control: Zero Trust Segmentation
Mitigation: Segmentation restricts scope of privilege escalation to the initially compromised resource.
Control: East-West Traffic Security
Mitigation: Lateral traffic between workloads is limited or blocked unless explicitly authorized.
Control: Cloud Firewall (ACF)
Mitigation: Outbound connections matching known command and control behavior are detected and denied.
Control: Egress Security & Policy Enforcement
Mitigation: Unapproved egress to external destinations is blocked and attempted exfiltration is detected.
Rapid detection and response to anomalous encryption activity and backup deletion attempts.
Impact at a Glance
Affected Business Functions
- IT Security
- Data Protection
- Compliance
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive corporate data due to disabled security defenses, leading to unauthorized access and data breaches.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation to strictly limit lateral movement and restrict workload communication to only what is necessary.
- • Deploy East-West Traffic Security and Inline IPS to continuously monitor for and block exploit and C2 traffic within and across cloud regions.
- • Apply robust Egress Policy Enforcement to detect and prevent unsanctioned outbound data flows and possible exfiltration.
- • Leverage Multicloud Visibility & Control to maintain real-time awareness of internal threats and accelerate response to anomalous or ransomware-related activity.
- • Continuously validate network security posture and automate incident detection through unified CNSF controls to minimize attack dwell time.



