logo

PoorTry Windows driver evolves into a full-featured EDR wiper

ID: 93a0e653-e5b3-5a84-bb74-8b579da09f06

STIX ID: report--93a0e653-e5b3-5a84-bb74-8b579da09f06

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-08-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report explains that the PoorTry (BurntCigar) kernel-mode driver—previously used to disable endpoint detection and response (EDR)—has been updated to act as an EDR wiper that deletes critical EXEs/DLLs and other security components to prevent recovery. Used by multiple ransomware groups (e.g., BlackCat, Cuba, LockBit) and observed in a July 2024 RansomHub incident, the tool employs kernel/user-mode components, hardcoded paths and file-type deletion, signing evasion tactics (timestamp manipulation and certificate roulette), and packing/obfuscation to increase success and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.