PoorTry Windows driver evolves into a full featured EDR wiper
A ransomware gang's tool for disabling Endpoint Detection and Response (EDR) solutions, the malicious PoorTry kernel-mode Windows driver, has developed into an EDR wiper that removes files essential to the functioning of security solutions and complicates restoration.
Sophos has now confirmed witnessing the EDR erasing assaults in the wild, despite Trend Micro's warning of this functionality enabled on Poortry since May 2023.
PoorTry's transformation from an EDR deactivator to an EDR wiper shows how aggressively ransomware perpetrators have changed their strategies, prioritizing a more disruptive preparation phase in order to achieve greater results during the encryption stage.
In 2021, 'BurntCigar,' another name for PoorTry, was created as a kernel-mode driver to deactivate EDR ...

