Mebroot, also known in some reporting as Sinowal, is a Windows bootkit family first observed in the wild in 2007. It compromises the Master Boot Record to execute before Windows, providing persistent and stealthy control of the affected host. Mebroot variants use low-level disk-access interception, including malicious Int 13h handling, to access and load bootkit components. This pre-OS position can facilitate the loading of unsigned kernel-mode components and evasion of host-based security controls. Mebroot.FX deployed Win32/Theola malicious browser plugins for banking fraud; these plugins monitored browser activity, captured submitted banking credentials and payment-card data, and communicated with other malware components through named pipes. Theola also used legitimate browser-plugin interfaces rather than conventional user-mode network hooks, reducing the visibility of its web-activity manipulation. Mebroot has been associated with Windows-focused financial malware operations, including distribution of Torpig.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The first bootkits started to emerge on the malware scene as cybercriminals realized that bootkit development was a way in which they could increase the profitability of a kernel-mode rootkit by widening the range of its targets to include users of 64-bit machines.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named bootkit cited among early bootkit examples following initial proof-of-concept work.
A named bootkit referenced in the historical progression of bootkit malware.
A rootkit used to compromise systems and facilitate the spread of Torpig by infecting the Master Boot Record.
A bootkit family that installs Theola malicious browser plugins and uses typical MBR infection techniques, including a malicious int13 handler for hard drive access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.