A ransomware operation known as The Gentlemen, tracked by Microsoft under the name Storm-2697, is drawing fresh attention from security researchers for a specific and worrying capability: the ability to disable endpoint detection and response (EDR) tools before launching an attack. A new advisory breaks down how this group blinds the very defenses organizations rely on to spot intrusions, and what defenders can do to close the gap.
The Gentlemen operates as a ransomware-as-a-service (RaaS) platform, meaning the core group builds and maintains the malware while a network of affiliates carries out the actual break-ins and negotiations. This model has become the dominant structure behind large-scale ransomware campaigns because it lets the operators scale quickly, spreading their tools to more attackers without doing the hands-on intrusion work themselves. Researchers describe The Gentlemen as financially motivated, with a Russian-speaking origin and rapid growth in a relatively short window, a pattern that mirrors other RaaS groups that have expanded aggressively once their affiliate model matured.
How The Gentlemen Ransomware Blinds EDR Defenses
EDR software is designed to be the last line of defense on a compromised device: it watches for suspicious process behavior, flags unusual file activity, and can isolate a machine before ransomware finishes encrypting files. The Gentlemen's approach specifically targets this layer. Rather than trying to sneak past EDR tools, the group's toolkit is built to disable, uninstall, or otherwise neutralize them outright, effectively removing the alarm system before the break-in is even noticed.
This kind of EDR-killer capability has become a recurring feature in modern ransomware toolkits, and it changes the calculus for defenders. A network that assumes its EDR agent will always report back is vulnerable if an attacker's first move is to silence that agent. Once the security tooling goes dark, the ransomware operators can move laterally, harvest credentials, and stage data for exfiltration with far less risk of early detection. This mirrors a broader trend seen across ransomware families: threat actors increasingly prioritize disabling security tools as a first step, not an afterthought, because it buys them the time needed to complete a full-network encryption and extortion campaign.
Why This Matters Beyond the Ransom Note
The privacy implications of EDR blinding go beyond the immediate disruption of a ransomware attack. Most modern ransomware operations, including double-extortion groups, steal data before encrypting it. If EDR tools are disabled early in the intrusion, organizations lose visibility into exactly what was accessed, copied, or exfiltrated during the window the attackers controlled the network. That uncertainty complicates breach notification, regulatory reporting, and any effort to tell affected customers or patients what data may have been exposed.
This is a familiar pattern across the ransomware landscape. Advisories covering other active groups, such as the joint warnings issued around Gunra ransomware targeting healthcare organizations, have repeatedly flagged how attackers exploit blind spots in monitoring to maximize the damage before anyone notices. The healthcare sector in particular has been a recurring target, as detailed in advisories on Gunra's growing threat to hospitals, because sensitive patient data combined with operational urgency makes organizations more likely to pay quickly. The Gentlemen's EDR-blinding approach fits this same playbook: disable the watchers, then take your time.
What This Means For You
If you run IT or security operations for a business, this advisory is a reminder that EDR software alone is not a guarantee of protection. Attackers are actively building tools designed to defeat it, and a single disabled agent on one machine can be the difference between a contained incident and a network-wide breach. Layered defenses, including network-level monitoring that doesn't depend solely on endpoint agents reporting in, are increasingly necessary to catch an intrusion when the EDR signal goes silent.
For everyday users and consumers, the takeaway is less about direct action and more about awareness. Ransomware groups like The Gentlemen ultimately target organizations that hold your data, from employers to healthcare providers to service companies. When those organizations lose visibility into an attack, the resulting breach notifications can be delayed or incomplete, which is why staying alert to breach disclosures and acting quickly on password changes or credit monitoring offers matters more than ever.
Staying Ahead of EDR-Evading Ransomware
Defending against The Gentlemen and similar groups requires treating EDR as one layer among several rather than a single point of failure. Security teams should monitor for unauthorized attempts to uninstall or disable security agents, since that behavior itself is a strong early warning sign of an active intrusion. Keeping systems patched matters too, since attackers frequently rely on known vulnerabilities to gain the initial foothold needed to reach and disable security tooling, a dynamic also seen in recent patch guidance like the Windows zero-day advisory for CVE-2026-68820.
Ultimately, the rise of The Gentlemen ransomware EDR evasion tactics underscores a shift in how ransomware groups operate: the fight now starts before encryption, at the moment attackers try to blind your defenses. Organizations that build redundancy into their monitoring, segment networks to limit lateral movement, and train staff to recognize the early signs of tampering with security software will be far better positioned than those relying on EDR as a single safety net.
Actionable takeaways:
- Audit whether your EDR or antivirus software has tamper protection enabled and cannot be disabled without additional authentication.
- Set up alerts specifically for EDR agent uninstalls, disables, or service stoppages, since this behavior is a red flag on its own.
- Layer network-based monitoring alongside endpoint tools so visibility doesn't disappear if one agent goes dark.
- Patch known vulnerabilities promptly, as unpatched systems remain the easiest entry point for RaaS affiliates.
- If you're a consumer, watch for breach notifications from organizations you interact with and act quickly on any recommended password or account security changes.




