ATT&CKReferencesFireEye Bootkits

FireEye Bootkits

Andonov, D., et al. (2015, December 7). Thriving Beyond The Operating System: Financial Threat Group Targets Volume Boot Record. Retrieved May 13, 2016.

Open the source

Techniques1

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1542.003
Bootkit
MalwareBOOTRASH

BOOTRASH is a Volume Boot Record (VBR) bootkit that uses the VBR to maintain persistence.

T1542.003
Bootkit
MalwareROCKBOOT

ROCKBOOT is a Master Boot Record (MBR) bootkit that uses the MBR to establish persistence.

T1564.005
Hidden File System
MalwareBOOTRASH

BOOTRASH has used unallocated disk space between partitions for a hidden file system that stores components of the Nemesis bootkit.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.