Researchers detailed Pitou (also known as Backboot), a Windows bootkit and spambot that infects the Master Boot Record (MBR) to gain persistence before the operating system loads. The malware targeted Windows XP through Windows 10 on both 32-bit and 64-bit systems, stored its loader and encrypted driver in the last 1 MB of disk space, and hooked multiple stages of the boot chain to bypass Microsoft kernel-mode code-signing protections and launch a fully kernel-mode spam bot. Analysts also found anti-VM checks, heavy obfuscation, and stealth features that hid the MBR infection by intercepting disk read and write requests.
Further reverse engineering showed Pitou’s command-and-control design was built for resilience. The malware contacted a primary TCP server at 195.154.237.14:7384, but could also fall back to a domain generation algorithm (DGA) implemented inside a custom virtual machine in kernel mode. Researchers reconstructed the VM, extracted the DGA, and found it generated batches of 20 date-seeded domains using encrypted character tables and mostly 10-day windows, although coding bugs affected some date handling and domain output. The recovered algorithm matched previously observed Pitou infrastructure, underscoring the sophistication of one of the last notable MBR bootkits seen in the wild.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
The packed Pitou sample used in the DGA analysis had a compile timestamp of 31 October 2017 10:15:25 UTC.
The analyzed Pitou dropper sample was first submitted to VirusTotal on 23 September 2017 at 04:58:27, according to TG Soft.
TG Soft states that the analyzed Pitou dropper sample was found on 20 September 2017.
One analyzed Pitou dropper sample carried a compilation timestamp of 19 September 2017 20:55:31.
TG Soft reported analyzing new versions of Pitou that were observed in the wild from September to October 2017, indicating continued active development and deployment.
The Pitou unpacked executable analyzed in the DGA research had a compile timestamp of 22 August 2017 10:24:10 UTC.
The 64-bit Pitou rootkit module analyzed in the DGA research had a compile timestamp of 27 February 2017 06:13:41 UTC.
TG Soft's report states that the Pitou bootkit, also known as Backboot, was first released in April 2014.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 82 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.