logo

DarkCloud Bootkit

ID: 59467bc3-65c4-5eb5-931b-c40f296be001

STIX ID: report--59467bc3-65c4-5eb5-931b-c40f296be001

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-09-01

Date Updated: 2026-05-01

...
...

This report analyzes a sophisticated bootkit-based cryptominer: the installer infects the MBR (moving the clean MBR to sector 1 and writing malicious code to sector 0/2-53), hooks int 15h service 0xE820 to hide its presence, and employs OS loader and kernel patches (different techniques for Windows XP and 7) to load kernel shellcode that hides the MBR, patches storage drivers (atapi.sys IdePortStartIo) to serve clean sectors, kills many AV/security processes, injects user-mode shellcode into explorer.exe to download encrypted config and further stages, and ultimately deploys a downloader payload (conhost.exe) that registers as a service and fetches a cryptominer; Zscaler detection signatures and example config/IOC details are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.