ROCKBOOT

S0112

Malware.View on attack.mitre.org

About this malware

ROCKBOOT is a Bootkit that has been used by an unidentified, suspected China-based group.

Techniques used1

Procedure examples1

TechniqueProcedure example
T1542.003
Bootkit

ROCKBOOT is a Master Boot Record (MBR) bootkit that uses the MBR to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye Bootkits Open source
    Andonov, D., et al. (2015, December 7). Thriving Beyond The Operating System: Financial Threat Group Targets Volume Boot Record. Retrieved May 13, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.