BOOTRASH

S0114

Malware.View on attack.mitre.org

About this malware

BOOTRASH is a Bootkit that targets Windows operating systems. It has been used by threat actors that target the financial sector.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1542.003
Bootkit

BOOTRASH is a Volume Boot Record (VBR) bootkit that uses the VBR to maintain persistence.

T1564.005
Hidden File System

BOOTRASH has used unallocated disk space between partitions for a hidden file system that stores components of the Nemesis bootkit.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. FireEye BOOTRASH SANS Open source
    Glyer, C.. (2017, June 22). Boot What?. Retrieved November 17, 2024.
  2. FireEye Bootkits Open source
    Andonov, D., et al. (2015, December 7). Thriving Beyond The Operating System: Financial Threat Group Targets Volume Boot Record. Retrieved May 13, 2016.
  3. Mandiant M Trends 2016 Open source
    Mandiant. (2016, February 25). Mandiant M-Trends 2016. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.