Researchers reported that PoorTry—also tracked as BurntCigar—has evolved from a signed Windows kernel driver used to disable endpoint protections into a more destructive EDR wiper that deletes security software files before ransomware is deployed. Sophos observed the upgraded tool in a RansomHub intrusion, where attackers used a user-mode component to identify endpoint security files and a kernel-mode component to terminate protected processes and remove critical EXE, DLL, and related files, preventing security products from recovering before encryption began.
The newer variants show increasingly evasive tradecraft associated with signed malicious drivers in ransomware operations. Reporting indicates the malware uses hardcoded paths as well as deletion by filename or file type, while operators rotate among differently signed payloads and manipulate signature timestamps in a "certificate roulette" approach to improve execution success. The activity reflects a broader pattern seen in ransomware campaigns, including earlier use of signed kernel drivers by groups such as BlackCat/ALPHV, to neutralize defenses at the kernel level and give attackers a clearer path to encrypt victim systems.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
During a July 2024 RansomHub attack, attackers used PoorTry to delete critical EXE, DLL, and other files belonging to security software before ransomware encryption. Sophos said this prevented EDR products from being recovered or restarted during the attack.
In May 2023, Trend Micro warned that PoorTry had file-deletion functionality, marking an early public report of the malware's ability to go beyond process termination. This indicated the tool was expanding toward more destructive anti-security behavior.
During 2022 and 2023, PoorTry variants evolved through code optimization and obfuscation. Researchers also observed the malware and its loader Stonestop being packed with VMProtect, Themida, and ASMGuard for evasion.
PoorTry, also known as BurntCigar, was developed in 2021 as a malicious Windows kernel-mode driver designed to disable EDR and other security software. It later became associated with use by multiple ransomware groups.
Sophos published research describing how BurntCigar/PoorTry had evolved into a full-featured EDR wiper that terminates security processes and deletes critical files. The report also described newer variants using signature timestamp manipulation, borrowed software metadata, and multiple signed payloads in a 'certificate roulette' tactic.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 175 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcenews.sophos.com
Open sourcecloud.google.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.