Researchers analyzed an updated Rovnix bootkit framework variant, Rovnix.D, that continues the malware family’s use of NTFS VBR infection to load unsigned kernel-mode drivers on 64-bit Windows systems. The newer samples include BkSetup.dll version 2.4 and show revised polymorphic bootstrap code, modified malicious VBR storage, and updated driver decryption routines designed to make detection and analysis harder.
The refreshed framework also adds support for downloading multiple payloads from command-and-control infrastructure, with the payload communicating through a malicious driver and hidden storage before reaching out to rtttt-windows.com. Researchers assessed the changes as evolutionary rather than a full redesign, but said the updates appear aimed at improving antivirus evasion and keeping the bootkit viable for renewed criminal use, including possible botnet-for-rent operations.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
The analyzed newer sample contained the Rovnix bootkit's BkSetup.dll installer module with file version 2.4 and a compilation timestamp dated 24/06/2012. The article presents this as evidence of continued development of the Rovnix framework.
The author's team had been tracking the Rovnix bootkit family since April 2011. Rovnix was notable for using NTFS VBR infection to load unsigned kernel-mode drivers on x64 systems.
The Rovnix framework was sold to Carberp developers associated with the Hodprot/Origami botnet, and those developers used droppers incorporating the Rovnix bootkit framework until the end of 2011.
Early Rovnix samples that blocked internet access for Russian users and demanded payment by premium SMS stopped using the bootkit component during the summer of 2011.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.