STONESTOP is a Windows user-mode malware component used to install and control the POORTRY malicious kernel driver. It functions as a loader and orchestrator for defense-impairment operations, directing the driver to terminate, suspend, resume, delete, or overwrite targeted security-related processes and files. In later observed variants, the toolset expanded from process killing into broader sabotage of endpoint protection, including deletion of critical EDR components from disk and coordination with kernel-level tampering performed by POORTRY.
STONESTOP has been associated with financially motivated intrusion activity and ransomware operations, including use by Scattered Spider/UNC3944 and reporting tying the broader toolset to Akira, ALPHV/BlackCat, Cuba, Hive, LockBit, Medusa, BlackCat, and RansomHub-linked activity. It has been used to disable antivirus and EDR products as a precursor to credential theft, SIM-swapping intrusions, extortion, and ransomware deployment. The malware has also appeared in campaigns targeting telecommunications, BPO, financial services, healthcare, MSSPs, entertainment, transportation, cryptocurrency-related organizations, and other enterprises.
The malware is notable for enabling kernel-assisted defense evasion on Windows by creating and loading a malicious or signed driver, including in bring-your-own-vulnerable-driver and signed-driver abuse scenarios. Public reporting describes STONESTOP as heavily obfuscated in some campaigns with commercial packers and used as part of a two-component toolkit in which the userland loader communicates with the driver through device control requests to specify actions against security software. Its primary role is to facilitate post-compromise defense evasion and preparation for follow-on attacker objectives rather than initial compromise itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Scattered Spider is known to exploit CVE-2015-2291 which is a vulnerability in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys) that allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges... Scattered Spider exploited CVE-2015-2291 to deploy a malicious kernel driver in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Scattered Spider uses POORTRY and STONESTOP to terminate security software and evade detection. STONESTOP is a Windows userland utility that attempts to terminate processes by creating and loading a malicious driver.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actors also leverage known system vulnerabilities using “Bring Your Own Vulnerable Driver” (BYOVD) techniques to gain administrative privileges and evade detection from endpoint security products.
Poortry has evolved into something akin to a rootkit that also has with finite controls over a number of different API calls used to control low-level operating system functionality.
Throughout 2022 and 2023, Poortry continued to evolve, optimizing its code and using obfuscation tools like VMProtect, Themida, and ASMGuard to pack the driver and its loader (Stonestop) for evasion.
Before reading from the file, STONESTOP verifies the file’s integrity against a predefined MD5 hash... reads process names from an external configuration file named, for example, poyuo.pdata.
Poortry now can also delete critical EDR components completely, instead of simply terminating their processes... The loader contains a list of hardcoded paths pointing at the location where EDR products are installed... and deletes files critical to the EDR agent, such as EXE files or DLL files.
The vulnerable drivers used by Scattered Spider are signed by stolen certificates from well-known authorities, such as Microsoft, NVIDIA, and Global Software LLC, which makes them appear legitimate.
111 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows userland utility that loads and orchestrates the POORTRY malicious driver to terminate processes, especially security tooling, as part of defense evasion.
A Windows userland utility that loads and orchestrates the POORTRY malicious driver to terminate processes and disable security tooling.
A loader often used together with the Poortry malicious driver.
User-mode loader paired with Poortry that locates and communicates with the malicious driver via DeviceIoControl, performs a handshake, sends IOCTLs to trigger driver capabilities, and helps terminate processes and delete EDR-related files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.