Mebroot
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence
2 techniques
Persistence
Windows bootkits gained notice in the early 2000s as proofs of concept developed by researchers of offensive security. BootRoot, a bootkit demonstrated at the 2005 Black Hat security conference, is likely the first such instance.
Secure Boot checks the digital signatures of all code that loads during system startup to ensure it originates from a trusted provider... Secure Boot is designed to thwart bootkits, a form of malware that alters the systems responsible for loading firmware and software during the initial boot sequence.
Stealth
3 techniques
Stealth
Windows bootkits gained notice in the early 2000s as proofs of concept developed by researchers of offensive security. BootRoot, a bootkit demonstrated at the 2005 Black Hat security conference, is likely the first such instance.
Secure Boot checks the digital signatures of all code that loads during system startup to ensure it originates from a trusted provider... Secure Boot is designed to thwart bootkits, a form of malware that alters the systems responsible for loading firmware and software during the initial boot sequence.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named bootkit cited among early bootkit examples following initial proof-of-concept work.
A named bootkit referenced in the historical progression of bootkit malware.
A rootkit used to compromise systems and facilitate the spread of Torpig by infecting the Master Boot Record.
2007 Alureon BlackEnergy Clampi Mebroot Storm ZeuS
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.