Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le août 19, 2019, 15:00:04

Titre: [Trend]Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response
Posté par: igor51 le août 19, 2019, 15:00:04
Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response

When we first investigated MyKings in 2017, we focused on how the cryptominer-dropping botnet malware used WMI for persistence. Like Mirai, MyKings seems to be constantly undergoing changes to its infection routine. The variant we analyzed for this incident did not just have a single method of retaining persistence but multiple ones, as discussed in the previous section. In addition to WMI, it also used the registry, the task scheduler, and a bootkit — the most interesting of which is the bootkit.


The post Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response appeared first on .


Source: Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/0asMPHan37w/)