Rovnix is a Windows malware family best known for its early bootkit architecture and later evolution into a data-stealing trojan and modular loader. It was one of the first known bootkits to infect the NTFS Volume Boot Record, allowing it to gain control during system startup and load unsigned kernel-mode components on 64-bit Windows systems before normal operating system protections fully applied. Its boot-stage components used stealth and anti-detection techniques including polymorphic bootstrap code, hidden storage on disk, and driver-assisted payload injection into user-mode processes.
The family evolved through multiple variants and modifications, including versions associated with a commercialized bootkit framework. Core functionality included persistence through boot-chain compromise, hidden storage management, encrypted or obfuscated components, and the ability to inject payloads into selected processes. Later variants supported downloading and executing additional modules, enabling operators to swap payloads and use the framework as a flexible delivery platform.
Rovnix has also been observed outside its classic bootkit form. More recent campaigns used updated loaders and privilege-bypass techniques, including UAC bypass and DLL hijacking, while retaining code lineage from leaked Rovnix source. In these operations, the malware installed boot components, deployed a kernel driver to inject a loader into running processes, and fetched additional payloads from command-and-control infrastructure. Related payloads functioned as backdoors capable of executing files, collecting system information, recording audio, and rebooting or shutting down infected systems.
Operationally, Rovnix has been used in financially motivated campaigns and has been described as a data-stealing trojan targeting Windows users, including theft of financial information such as payment-card data. It has been distributed through malicious email infection chains, sometimes via intermediary downloaders, and has also appeared in broader spam-driven malware ecosystems. The family was linked to criminal botnet infrastructure such as Avalanche for communications support. Leaked source code contributed to its reuse, adaptation, and incorporation into later criminal tooling, helping extend its lifespan and enabling modernization by other actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Rovnix was the first bootkit family to use VBR (Volume Boot Record) infection (NTFS bootstrap code) for loading unsigned kernel-mode drivers on x64 (64 bit) platforms.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware creates and runs a series of BAT files that start wusa.exe from the fake directory and then clean up the traces
Detect suspicious VBA keywords often used by malware ... detect_suspicious checks if VBA macro code contains specific keywords often used by malware to act on the system | olevba is a script to parse OLE and OpenXML files such as MS Office documents (e.g. Word, Excel), to detect VBA Macros, extract their source code in clear text...
With the aid of the Windows API, the malware creates the directory C:\Windows \System32
AutoOpen | Runs when the Word document is opened ... Auto_Open | Runs when the Excel Workbook is opened ... Workbook_Open | Runs when the Excel Workbook is opened
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
All bootkits aim to modify and subvert operating system components before the OS can be loaded. The most interesting target components are as follows: BIOS/UEFI, MBR (Master Boot Record) and the operating system boot loader.
KLoader is written to the disk; its purpose is to inject the payload into running processes.
This price is only for the bootkit package and excludes the cost of exploits for escalating privilege in order to get access allowing modifications deep into the system.
Most bootkit infections have used MBR-modification... The Rovnix family used other ways to infect with modification of the VBR
The first bootkits started to emerge on the malware scene as cybercriminals realized that bootkit development was a way in which they could increase the profitability of a kernel-mode rootkit by widening the range of its targets to include users of 64-bit machines.
This packet is XOR-encrypted with the single-byte key 0xF7
The file “on the new initiative of the World Bank in connection with the coronavirus pandemic.exe” is a self-extracting archive
KLoader is written to the disk; its purpose is to inject the payload into running processes.
clean up the traces by deleting the created directory and the easymule.exe dropper itself.
the malware ... copies there a legitimate signed executable file from C:\Windows\System32 ... (in this case, wusa.exe)
For synchronization reasons the payload generates the mutex: Global<Generated_string>.
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
All bootkits aim to modify and subvert operating system components before the OS can be loaded. The most interesting target components are as follows: BIOS/UEFI, MBR (Master Boot Record) and the operating system boot loader.
So as to store payload and configuration information secretly Win32/Gapz implements hidden storage.
The base functionality of BkSetup.dll is centred on the process of infection and setting up the hidden storage partition.
The IPL code is loaded and executed by the VBR: thus, by modifying value of the ‘Hidden Sectors’ field, the malware is able to intercept execution flow at boot time.
The payload module includes functionality for downloading and executing additional modules from the C&C server... The C&C domain is rtttt-windows.com
it then starts a C&C communication cycle, within which a data packet about the infected device is generated... and sent to C&C.
Avalanche used fast-flux DNS, a technique to hide the criminal servers, behind a constantly changing network of compromised systems acting as proxies.
It can steal user information and download a variety of other malicious software such as Zeus, Rovnix, Dyzap or Cutwail.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a complex threat that adopted TDL3’s hidden storage approach.
Mentioned as a name sometimes used in public reporting for ISFB-related activity.
Bootkit codebase referenced as a source of reused code within Downloader.Climax.A; the report does not claim full Rovnix deployment, but partial source reuse in the downloader implementation.
Named as one of the banking trojan strains tied to leaked Gozi source code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.