Mebromi BIOS Rootkit
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Mebromi infects systems via a dropper, but at the time of publication it is not known how the dropper is spread. This is likely to be via spam campaigns or malicious downloads.
The dropper checks if the system is running certain security software. It then loads a kernel mode driver to gain access to the BIOS. It checks whether the BIOS can be overwritten and makes a copy of it. Control is then passed back to the user mode component, which runs a legitimate BIOS flash tool and overwrites the BIOS with the infected version.
Whether or not the BIOS infection succeeds, the dropper then stores a copy of the partition table before infecting the MBR. This infection injects malicious code into Windows components during system startup, which will result in additional malware being downloaded. Mebromi uses a kernel mode rootkit to hide the MBR infection from the user, and this infection is restored at every system startup if the BIOS was successfully compromised.
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
Last edited: 17 February 2020 12:48 pm