Researchers documented multiple espionage malware families using vulnerable but legitimately signed Oracle VirtualBox drivers to defeat Windows kernel protections and load unsigned code. Uroburos, a rootkit associated with Turla, was reported to disable Driver Signature Enforcement by installing VBoxDrv.sys and exploiting flaws in the driver, while also using stealth features such as hidden kernel modules, overwritten in-memory PE headers, RWX mappings, covert HTTP header command parsing, and direct responses to specially crafted network requests before traffic reached userland. Analysts said the technique exposed a broader weakness in code-signing and certificate revocation because old signed drivers can remain trusted long after release.
A separate toolkit, AcidBox, used a similar exploit chain against a newer signed VirtualBox driver, VBoxDrv.sys version 2.2.0, to load an unsigned kernel payload during targeted intrusions against Russian organizations. Unit 42 reported that AcidBox persisted through the Security Support Provider mechanism to load into lsass.exe, decrypted worker modules from the Windows registry, and concealed payloads in encrypted, compressed data appended to icon resources. Other Turla-linked research in the same body of reporting described increasingly advanced kernel and firmware tradecraft, including the MoonBounce UEFI implant and a Turla-attributed keylogger, underscoring a sustained focus on stealthy boot- and kernel-level persistence in high-end espionage operations.

TTPs, infrastructure, and targeting history in one profile.
18 events from the most recent confirmed update back to the earliest known activity.
EpicTurla published analysis noting apparent code overlap between an ACIDBOX DLL and a Turla Nautilus payload, initially suggesting the shared crypto implementation warranted further attention.
Unit 42 published a report describing AcidBox as a rare modular malware toolkit used in targeted attacks in 2017, detailing its reuse of a Turla-associated VirtualBox exploit chain and its SSP-based persistence in lsass.exe.
0ffset published static analysis of a 64-bit DLL keylogger attributed to Turla, documenting its XOR-based string decryption and recovered strings including "msimm.dat" and "KSL0T Ver = 21.0."
Unit 42 says it discovered an AcidBox sample on VirusTotal in February 2019 containing a string associated with Turla's VirtualBox exploit, leading researchers to assess it as a previously unknown malware family.
EpicTurla notes that the Turla Nautilus sample used for later code-overlap comparison had been reported by NCSC in November 2017.
Unit 42 says Kaspersky found an additional AcidBox sample in its databases that appeared in June 2017, supporting the campaign timeframe.
Unit 42 reports that all known AcidBox samples shared compilation timestamps of May 9, 2017, indicating the toolkit was built for the 2017 activity cluster.
ExaTrack analyzed a 2017 Uroburos/Turla rootkit sample that targeted servers, retained the Null-driver and VirtualBox exploit traits from 2014, and changed its network protocol while dropping the earlier PatchGuard bypass.
Unit 42 reports that an unknown actor used AcidBox with VBoxDrv.sys v2.2.0 to target at least two Russian organizations in 2017, and Dr.Web linked it to a targeted attack on an unspecified Russian entity that year.
Kaspersky's MoonBounce analysis says the patched rogue CORE_DXE firmware component carried a reported link time of 2014-07-18 03:29:55 UTC.
Unit 42 says that in 2014 Turla's kernel-mode malware was publicly described as the first case of abusing a third-party signed device driver, VBoxDrv.sys v1.6.2, to disable Windows Driver Signature Enforcement and load unsigned payloads.
ExaTrack says Uroburos was originally detected in 2014 and was notable for using a 64-bit Windows rootkit driver.
Unit 42 states that Core Security found CVE-2008-3431 in 2008, affecting VBoxDrv.sys versions less than or equal to 1.6.2.
G Data published analysis describing how Uroburos used a legitimately signed Oracle VirtualBox driver and a vulnerability in it to disable Driver Signature Enforcement, alongside a Kernel Patch Protection bypass, calling it the first observed in-the-wild combination of those techniques.
Kaspersky published technical details on MoonBounce, describing a UEFI firmware implant in a rogue CORE_DXE component that hooks boot services, tampers with the Windows loader and kernel, and injects a user-mode stager into svchost.exe.
EpicTurla updated the ACIDBOX post on 2020-06-29 to say the observed overlap was not unique and was actually Mbed TLS compiled with Visual Studio, explicitly retracting the earlier implication of a meaningful Turla link.
EpicTurla says Palo Alto Unit 42 researchers Dominik Reichel and Esmid Idrizovic disclosed ACIDBOX, also known as KL: MagicScroll, as a new activity set and described it as reminiscent of Remsec while stopping short of firm attribution.
Unit 42 reports that Oracle fixed CVE-2008-3431 in VBoxDrv.sys version 1.6.4 by changing how VBoxDrvNtDeviceControl handled the UserBuffer pointer.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
epicturla.com
Open sourceunit42.paloaltonetworks.com
Open source0ffset.net
Open sourcegdatasoftware.com
Open sourcesecurelist.com
Open sourcemedia.kasperskycontenthub.com
Open sourceexatrack.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.