The Latest in IT Security

Unencrypted Whistler Variant in the Wild

12
Feb
2013

Antimalware researchers Marius Tivadar and Cristian Istrate are back with a small update from the labs, this time about the Whistler bootkit family.

Another version of Whistler was recently found, with low detection rates. Known Whistler variants had their components stored after the last partition on disk; they were encrypted with their corresponding LBA as key. In this new version, the original MBR is also stored after the last partition, but is not encrypted as in the previous versions, rather simply XORed. The rest of the components are not encrypted at all, as you can see from the image:

whistler

As per usual, the new variant is detected by all Bitdefender software, including the recently released Rootkit Remover.

Leave a reply


Categories

FRIDAY, APRIL 26, 2024
WHITE PAPERS

Mission-Critical Broadband – Why Governments Should Partner with Commercial Operators:
Many governments embrace mobile network operator (MNO) networks as ...

ARA at Scale: How to Choose a Solution That Grows With Your Needs:
Application release automation (ARA) tools enable best practices in...

The Multi-Model Database:
Part of the “new normal” where data and cloud applications are ...

Featured

Archives

Latest Comments