Researchers detailed HDRoot, a stealthy Windows bootkit installer tied to Winnti activity that was disguised as Microsoft's net.exe, protected with VMProtect, and signed with a compromised certificate from Guangzhou YuanLuo Technology. The malware installs code into the MBR and subsequent boot sectors, then alters the startup chain so a malicious DLL is injected early in the boot process and a designated backdoor is launched with persistence.
HDRoot supports both FAT32 and NTFS systems and commonly hides its DLL in Windows paths such as %windir%\WMSysPr9.prx, while modifying ServiceDll registry values for legitimate services including wuauserv, LanManServer, schedule, and winmgmt. Some variants drop the payload as %windir%\temp\svchost.exe, while others execute it directly from memory to reduce forensic traces; despite its sophistication, the bootkit leaves detectable artifacts such as broken Windows services and persistent malicious ServiceDll paths.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers identified an observed HDD Rootkit/HDRoot sample carrying version number 1.2 dated 22 August 2006, providing the earliest explicit time anchor for the malware discussed. The sample was later analyzed as a bootkit installer linked to Winnti activity.
While analyzing Winnti group activity, researchers found a suspicious Win64 sample masquerading as Microsoft's net.exe, protected with VMProtect and signed with a compromised Guangzhou YuanLuo Technology certificate. Memory analysis and comparison with an unprotected sample confirmed it was an HDD Rootkit bootkit installer, which they named HDRoot.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.