Get a Pentest and security assessment of your IT network.

News

Analysis of FinFisher Bootkit

Malware makes a copy of the original master boot record (MBR) and stores it elsewhere on the hard drive. Malware uses Logical Block Addressing (LBA) to find a physical location of the malicious data. The address of the first sector containing this data is hard-coded into the bootstrap code. The kernel mode driver reads and writes raw data from/onto a hard drive. This data is later copied by the malicious Bootstrap code. The approximation of the technique used by the driver can be found in this article.”]

Source: https://securityintelligence.com/analysis-of-finfisher-bootkit/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2