Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-security-bypassransomware-group-operationdefense-evasion-methodransomware-tooling-evolution

Poortry Driver Evolved Into an EDR-Wiping Tool Used in Ransomware Intrusions

Updated 8d agoFirst seen Jan 1, 20261 source

Sophos reported that new variants of the Poortry malicious kernel driver and its Stonestop loader have evolved into a more destructive tool used to disable security defenses during ransomware attacks. Previously known for terminating processes, the latest samples can patch kernel callbacks, interfere with filter drivers, kill security processes, and delete critical EDR files from disk, effectively shifting Poortry from an EDR killer to an EDR wiper. Researchers said the malware continues to develop even after Microsoft closed the attestation-signing loophole that earlier versions abused.

The toolset has been linked to major ransomware operations including CUBA, BlackCat, Medusa, LockBit, and RansomHub, where it is used to clear the way for encryption by impairing endpoint protection. Sophos observed attackers switching rapidly between differently signed Poortry variants during intrusions, suggesting access to multiple stolen or leaked certificates and an adaptive evasion strategy. In one RansomHub-related intrusion, Poortry and Stonestop were deployed before ransomware execution, reinforcing assessments that the driver now functions as a rootkit-like sabotage platform for pre-ransomware defense evasion.

Share:
Poortry Driver Evolved Into an EDR-Wiping Tool Used in Ransomware Intrusions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 1, 20266mo ago

Sophos observes Poortry file-deletion capability in active attacks

Analysis of the July 2024 RansomHub-related incident showed that the Poortry driver had gained file-deletion capabilities that Trend Micro had previously reported, and Sophos observed those capabilities in active use. Sophos said this marked an evolution from an EDR killer toward an EDR wiper.

Attack tool update impairs Windows computers | SOPHOS

RansomHub intrusion uses Poortry and Stonestop before ransomware deployment

In a July 2024 incident linked to RansomHub, Sophos observed attackers deploying the Poortry malicious driver and the Stonestop loader before ransomware execution. The case showed the toolset being used operationally to impair defenses during an intrusion.

Attack tool update impairs Windows computers | SOPHOS

Microsoft closes attestation-signing loophole abused by Poortry operators

Sophos reported that the Poortry and Stonestop toolset continued to evolve after Microsoft closed the attestation-signing loophole previously abused by its operators.

Attack tool update impairs Windows computers | SOPHOS
SOURCE COVERAGE

Sources

1 reference tracked. Mallory keeps watching after this page renders.

1 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.