PoorTry Windows driver evolves into a full-featured EDR wiper
ID: 93a0e653-e5b3-5a84-bb74-8b579da09f06
STIX ID: report--93a0e653-e5b3-5a84-bb74-8b579da09f06
Feed Name: Bleeping Computer
The report explains that the PoorTry (BurntCigar) kernel-mode driver—previously used to disable endpoint detection and response (EDR)—has been updated to act as an EDR wiper that deletes critical EXEs/DLLs and other security components to prevent recovery. Used by multiple ransomware groups (e.g., BlackCat, Cuba, LockBit) and observed in a July 2024 RansomHub incident, the tool employs kernel/user-mode components, hardcoded paths and file-type deletion, signing evasion tactics (timestamp manipulation and certificate roulette), and packing/obfuscation to increase success and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
