Whistler Bootkit Evolves to Evade AV Detection

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,379
Softpedia said:
One of the firstly discovered malicious pieces of software that could be considered a bootkit seems to have evolved, encapsulating new mechanisms that could allow it to slip unnoticed by anti-virus solutions.

According to Bitdefender researchers, in the past months the malware identified as Rootkit.MBR.Whistler.B has been seen infecting a lot of master boot records thanks to its new evasion techniques.

The bootkit keeps its data after the last partition on the disk, but if it doesn't find enough unpartitioned space it will shrink the partition until at least 400 sectors are available.

The first sector, which is responsible for defining the components of the Whistler, is encrypted differently than before with the aid of an additional key that is specific to the infected system, the key being hardcoded into the malware's code.

To make sure security products don't detect it as easily as before, the new variant comes with all its components encrypted, unlike the previous version which had only the malicious code encrypted, the rest being left in plain text. The encryption key consists of the absolute sector's LBA.

The analysis of this bootkit is highly difficult since after the dropper does its task infecting the MBR, it removes itself. The driver loaded while the machine boots up injects the payload into processes which will later make sure other malevolent components will land on the system.

Since it doesn't hide its MBR code like other such bootkits and because its payload is fairly well hidden, Whistler is much harder to detect by anti-virus programs. Another thing that helps it hide is the fact that it doesn't keep any files on the hard disk of the infected device.

via Softpedia
 
D

Deleted member 178

this one is exquisite, encrypted component, partition shrinking ability, self removal... i will give an award to the creator.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top