BURNTCIGAR is a Windows defense-evasion utility and driver loader used in ransomware intrusions, most notably activity attributed to UNC2596/Cuba ransomware operators. First observed in late 2021, it disables endpoint protections by causing kernel-mode drivers to terminate processes associated with antivirus, EDR, and other security products. Early variants implemented a bring-your-own-vulnerable-driver technique by installing a legitimate vulnerable Avast driver and invoking an undocumented driver control interface that ultimately terminates a chosen process at kernel level. Later related activity used attacker-controlled drivers signed with legitimate, including Microsoft hardware-program, certificates to kill security processes. BURNTCIGAR is deployed before ransomware execution and data theft to reduce defensive visibility and prevent security tools from interfering with post-compromise activity. It has been associated with Cuba ransomware intrusions affecting organizations, particularly in the United States and Canada, where operators also exploited public-facing Microsoft Exchange vulnerabilities or used phishing-derived access. The utility requires sufficient local privileges to install and load its kernel driver.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Cuba ransomware's arsenal includes unique tools like ‘BurntCigar’ malware and, more to the point, the BYOVD attack analyzed below.”
Burntcigar is a utility that can terminate processes at the kernel level by exploiting a flaw in an Avast driver, which is included with the tool for a “bring your own vulnerable driver” attack.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Because drivers pose a uniquely challenging risk to security... kernel-mode drivers can perform highly privileged operations that user-mode processes cannot leverage, potentially reducing the effectiveness of some antimalware, endpoint security, or EDR products.
Throughout 2022 and 2023, Poortry continued to evolve, optimizing its code and using obfuscation tools like VMProtect, Themida, and ASMGuard to pack the driver and its loader (Stonestop) for evasion.
The kit... first gained attention when its developers found ways to get their malicious drivers signed through Microsoft's attestation signing process... Sophos also notes that the latest Poortry variants employ signature timestamp manipulation to bypass security checks on Windows... The attackers were seen employing a tactic known as 'certificate roullete,' where they deploy multiple variants of the same payload signed with different certificates...
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
“Cuba ransomware's arsenal includes unique tools like ‘BurntCigar’ malware and, more to the point, the BYOVD attack analyzed below.”
Malicious signed driver referenced solely as comparative background on code-signing abuse.
Kernel-level process killer used by Cuba ransomware group to disable security and other processes.
Burntcigar is a custom tool used by the Cuba group to terminate security and EDR processes. It leverages the Bring Your Own Vulnerable Driver (BYOVD) technique, exploiting vulnerable drivers (such as Avast's aswarpot.sys) to gain kernel-level privileges and terminate protected processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.