Your computer is now stoned (...again!). The rise of MBR rootkits

Kimmo Kasslin F-Secure
Elia Florio Symantec

  download slides (PDF)

The war against invisible malware has been taken down to a new battleground, the lowest level seen so far in the wild: the Master Boot Record. The MBR rootkit, aka Mebroot, appeared in the wild in December 2007 and rapidly evolved from earlier beta versions to a full-working malware product. Mebroot rootkit uses techniques never before seen in modern threats and so it can be considered the next generation of stealth rootkit and kernel infector, written by professional malware developers clearly not for fun. The most notable characteristic of Mebroot is the fact that it replaces the system's Master Boot Record with malicious code that owns the machine completely from the boot, before the operating system itself gets loaded.

Years after Stoned and Michelangelo, Master Boot Record infection has been reborn with Mebroot on modern platforms. However, this technique is only the tip of the iceberg of a bigger cybercriminal project, since the final goal of Mebroot is to download and install additional bank trojan components on the infected machine. In this paper we present an extended view of MBR rootkit's features and its evolution - including a detailed look at its disk stealth, firewall bypassing, anti-analysis and anti-detection techniques.


Poll

Are you still running IE 6?
Yes, on my machine at work
Yes, on my home machine
Yes, on both work and home machines
No, I use a newer version of IE
No, I use a different browser

Leave a comment

Jobs Career Sidebar

Virus Bulletin

In this month's magazine:
  • Social networking meets social engineering
  • Flying solo
  • Geneva convention
  • 7th German Anti Spam Summit 2009
  • Anti-phishing landing page: turning a 404 into a teachable moment
  • An update on spamming botnets: are we losing the war?
  • Windows Server 2008 Standard Edition SP2 x86
Virus Bulletin 10 2009
Subscribe now!
Virus Bulletin currently has 187,817 registered users.