Pitou, also known as Backboot, is a Windows bootkit and kernel-mode spambot active since at least 2014. It infects Master Boot Record-based systems to achieve execution before the operating system fully loads, allowing it to bypass kernel-mode code-signing protections and install a malicious driver on both 32-bit and 64-bit Windows systems, including versions from Windows XP through Windows 10. Its architecture spans multiple boot stages and, on 64-bit systems, extends through the Windows boot chain into the kernel before launching its payload.
The malware’s primary purpose is to send spam from infected victim machines. Its spam functionality operates from kernel mode, and Pitou also includes resilient command-and-control logic through a domain generation algorithm used as fallback communications infrastructure. That DGA is unusually sophisticated in that it executes in kernel mode inside a custom virtual machine, uses encrypted string tables, dynamically resolved APIs, and date-based seeding, and generates batches of pronounceable domains across multiple top-level domains.
Pitou employs extensive stealth and anti-analysis measures. It stores components in disk space outside normal partitions, hooks the boot process across real mode, protected mode, and kernel initialization, and intercepts disk operations to conceal MBR infection by returning benign data to user-mode inspection. Additional evasion includes heavy obfuscation, anti-virtualization checks, and NDIS hooking to obscure network communication. Reverse engineering has also shown that Pitou uses a rootkit component with dynamically resolved API calls and custom virtualization to protect critical logic.
Pitou has been associated with drive-by download infections from compromised websites and delivery by other malware. It targets legacy BIOS/MBR environments rather than UEFI systems. Its combination of bootkit persistence, kernel-mode stealth, anti-VM behavior, and spam-bot functionality made it one of the more sophisticated late-stage MBR bootkits observed in the wild.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
It uses the sophisticated technique of Bootkit to bypass the Microsoft Kernel-Mode Code Signing policy for load the own driver (kernel payload) on Windows. | When the dropper is executed, the malware infects the Master Boot Record of disk... It overwrites the last 1 MB with the loader of Pitou and the Driver in the unpartitioned space.
Stealth Pitou uses technique to be stealth , as other bootkits, it hooks the Miniport Device Object of disk to detect the request of read/write of sectors of disk... When an application in "user mode" send a request to read the MBR, this is intercepted by Pitou in kernel mode, that instead will read the original MBR at end of disk hiding the infection.
The driver is obfuscated... It contains a lot of random strings... A second level of obfuscation is the use of hashes of blocks of 16 byte of code/data to calculate the addresses of objects, structures, strings, data and etc.
Pitou is a rootkit with dynamically resolved API calls. Furthermore, Pitou uses NDIS hooking to obscure network communication.
Pitou checks if it is running under VM, Sandboxing or in emulated/virtualized environments... If it is running under VM or in emuIated/virtualized environments then it stops to work.
The entire domain generation algorithm, including seeding, is virtualized. Virtual machines are a particularly effective form of code protection and challenging to analyze, or at the very least incredibly time-consuming.
It uses the sophisticated technique of Bootkit to bypass the Microsoft Kernel-Mode Code Signing policy for load the own driver (kernel payload) on Windows. | When the dropper is executed, the malware infects the Master Boot Record of disk... It overwrites the last 1 MB with the loader of Pitou and the Driver in the unpartitioned space.
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kernel-mode rootkit malware with a heavily virtualized DGA, dynamically resolved APIs, and NDIS hooking to hide network communications. It drops 32-bit and 64-bit rootkit modules, generates 20 DGA domains per cycle, and uses encrypted strings for consonants, vowels, and TLDs.
An MBR-infecting bootkit/spambot that installs by overwriting disk sectors near the end of the disk, hooks the boot process across Windows XP through Windows 10, bypasses Microsoft Kernel-Mode Code Signing to load its kernel driver, hides its presence by intercepting disk read/write requests, performs anti-VM checks, contacts a C2 server or uses DGA fallback, and sends spam entirely from kernel mode.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.