BURNTCIGAR is a Windows kernel-level endpoint-security process-termination utility associated with Cuba ransomware operations, tracked by Mandiant as UNC2596. First observed in late 2021, it is used to disable endpoint protection and EDR processes before ransomware deployment, data theft, and encryption. Early variants implemented a bring-your-own-vulnerable-driver technique, installing a legitimate vulnerable Avast kernel driver and invoking an undocumented driver control function to terminate targeted processes in kernel mode. Later related activity used attacker-controlled signed kernel drivers and a loader to install and communicate with the driver, enabling termination of a large predefined set of security-product processes. BURNTCIGAR has been linked with Cuba ransomware intrusions involving exploitation of public-facing Microsoft Exchange vulnerabilities, as well as earlier phishing-enabled access operations. Its principal purpose is defense evasion rather than persistence or payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Cuba ransomware's arsenal includes unique tools like ‘BurntCigar’ malware and, more to the point, the BYOVD attack analyzed below.”
Burntcigar is a utility that can terminate processes at the kernel level by exploiting a flaw in an Avast driver, which is included with the tool for a “bring your own vulnerable driver” attack.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Because drivers pose a uniquely challenging risk to security... kernel-mode drivers can perform highly privileged operations that user-mode processes cannot leverage, potentially reducing the effectiveness of some antimalware, endpoint security, or EDR products.
Throughout 2022 and 2023, Poortry continued to evolve, optimizing its code and using obfuscation tools like VMProtect, Themida, and ASMGuard to pack the driver and its loader (Stonestop) for evasion.
The kit... first gained attention when its developers found ways to get their malicious drivers signed through Microsoft's attestation signing process... Sophos also notes that the latest Poortry variants employ signature timestamp manipulation to bypass security checks on Windows... The attackers were seen employing a tactic known as 'certificate roullete,' where they deploy multiple variants of the same payload signed with different certificates...
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
“Cuba ransomware's arsenal includes unique tools like ‘BurntCigar’ malware and, more to the point, the BYOVD attack analyzed below.”
Kernel-level process killer used by Cuba ransomware group to disable security and other processes.
Burntcigar is a custom tool used by the Cuba group to terminate security and EDR processes. It leverages the Bring Your Own Vulnerable Driver (BYOVD) technique, exploiting vulnerable drivers (such as Avast's aswarpot.sys) to gain kernel-level privileges and terminate protected processes.
An EDR-killer malware/driver family sold on criminal forums and used to disable endpoint security products. The article references it as prior Sophos research and notes abuse of WHCP-signed drivers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.