RockBoot is an MBR bootkit identified by Mandiant and referred to internally as RockBoot. According to the provided content, it targets Windows XP, Windows Server 2003, Windows 7, and Windows Server 2008/2012. It is a Windows persistence mechanism that modifies the Master Boot Record (MBR) so code executes before the operating system loads. The content places RockBoot in the context of evolving Windows persistence techniques observed by Mandiant in 2015. No specific infection vector, malware family association, threat actor attribution, industry targeting, or indicators of compromise are provided in the supplied content beyond its classification as an MBR bootkit and the listed supported Windows versions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MBR bootkit that hijacks the boot process to persist a specified backdoor across reboots; stores encoded payload both as a file and in unallocated disk sectors and uses staged loaders to execute before handing control back to the legitimate boot chain.
MBR bootkit that hijacks the boot process to persist a specified backdoor across reboots; stores encoded payload both as a file and in unallocated disk sectors and uses staged loaders to execute before handing control back to the legitimate boot chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.