BOOTRASH is a Volume Boot Record (VBR) bootkit identified by Mandiant. Mandiant refers to the bootkit as BOOTRASH. It was reported as being used by targeted financial threat actors and as part of evolving Windows persistence techniques. BOOTRASH modifies the boot process to execute before the operating system loads, providing early-stage persistence. Reported target platforms include Windows XP, Windows Server 2003, Windows 7, and Windows Server 2008/2012. The provided content does not include specific infection vectors, industries targeted beyond the association with financial threat actors, or concrete indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Minor Software changes: ... BOOTRASH
VBR bootkit used by targeted financial threat actors; hijacks the VBR to load backdoor components from a virtual file system (VFS) created in free space between partitions, then continues the normal boot process via a stored copy of the legitimate VBR.
VBR bootkit used by targeted financial threat actors; hijacks the VBR to load backdoor components from a virtual file system (VFS) created in free space between partitions, then continues the normal boot process via a stored copy of the legitimate VBR.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.