DarkCloud Bootkit
ID: 59467bc3-65c4-5eb5-931b-c40f296be001
STIX ID: report--59467bc3-65c4-5eb5-931b-c40f296be001
Feed Name: Zscaler Security Research Blog
This report analyzes a sophisticated bootkit-based cryptominer: the installer infects the MBR (moving the clean MBR to sector 1 and writing malicious code to sector 0/2-53), hooks int 15h service 0xE820 to hide its presence, and employs OS loader and kernel patches (different techniques for Windows XP and 7) to load kernel shellcode that hides the MBR, patches storage drivers (atapi.sys IdePortStartIo) to serve clean sectors, kills many AV/security processes, injects user-mode shellcode into explorer.exe to download encrypted config and further stages, and ultimately deploys a downloader payload (conhost.exe) that registers as a service and fetches a cryptominer; Zscaler detection signatures and example config/IOC details are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
