Gapz, also known as Win32/Gapz, is a Windows bootkit that compromises the boot process to establish persistent, stealthy execution before the operating system fully loads. A documented variant used a sophisticated Volume Boot Record infection method that altered the NTFS Hidden Sectors field to redirect boot execution to malicious code stored outside the normal partition area. Its kernel-mode component comprises position-independent modules for API functionality, cryptography, hooking, hidden storage, payload management, and networking. Gapz encrypts concealed storage and has used custom kernel-mode networking through the NDIS miniport layer to reduce visibility to personal firewalls and traffic-monitoring tools; it communicates with command-and-control infrastructure using encrypted HTTP messages. Gapz has also been associated with Extra Window Memory Injection, a process-injection technique targeting Explorer window memory, and was documented using a novel injection method capable of bypassing host-based intrusion-prevention systems. The family is notable among bootkits active against legacy BIOS/MBR and VBR-based Windows boot chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The first bootkits started to emerge on the malware scene as cybercriminals realized that bootkit development was a way in which they could increase the profitability of a kernel-mode rootkit by widening the range of its targets to include users of 64-bit machines.
To keep the information stored within the hidden storage secret, its content is encrypted. The malware utilizes AES with key length 256 bits in CBC (Cipher Block Chaining) mode to encrypt/decrypt each sector of the hidden storage.
Most antiviruses don’t treat all processes the same... the goal of malware is to inject code into one of these “trusted” processes... In the case of PowerLoader, the trusted process targeted is explorer.
All bootkits aim to modify and subvert operating system components before the OS can be loaded. The most interesting target components are as follows: BIOS/UEFI, MBR (Master Boot Record) and the operating system boot loader.
So as to store payload and configuration information secretly Win32/Gapz implements hidden storage.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a complex threat that adopted TDL3’s hidden storage approach.
Malware noted here for using a novel code injection technique to bypass host-based intrusion prevention systems; also described as first using the PowerLoader technique.
Mentioned as a historical example of earlier bootkits during the peak bootkit era.
Malware family mentioned as using extra window memory injection via SetWindowLong.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.