Auteur Sujet: [Trend]Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response  (Lu 2485 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response

When we first investigated MyKings in 2017, we focused on how the cryptominer-dropping botnet malware used WMI for persistence. Like Mirai, MyKings seems to be constantly undergoing changes to its infection routine. The variant we analyzed for this incident did not just have a single method of retaining persistence but multiple ones, as discussed in the previous section. In addition to WMI, it also used the registry, the task scheduler, and a bootkit — the most interesting of which is the bootkit.


The post Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response appeared first on .


Source: Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response

Tags: