Trojan.Mebromi
Trojan⚠️ Overview
Trojan.Mebromi is a BIOS-level rootkit first discovered in September 2011 by 360 Security Center, targeting legacy Windows systems. It is categorized as a bootkit and rootkit, designed to infect the Master Boot Record (MBR) and rewrite the system BIOS to persist across operating system reinstallations. The malware is attributed to an unknown Chinese-speaking threat actor, with initial reports from Chinese security vendor Qihoo 360.
🔧 Technical Capabilities
Trojan.Mebromi propagates via infected websites, drive-by downloads, and trojanized software installers. Its primary attack vector is exploiting weak BIOS flash protection and writable BIOS chips on older motherboards. Persistence is achieved by injecting malicious code into the system's MBR and, uniquely, by patching the BIOS interrupt vector table (IVT) to reinstall the MBR infection even after a hard drive format. The malware uses a custom C2 infrastructure over HTTP to download secondary payloads, such as backdoors or keyloggers. Evasion techniques include hooking the BIOS's INT 13h disk handler to hide its MBR code from scanning tools and using a small, encrypted bootloader to avoid signature detection.
📜 History & Notable Incidents
Trojan.Mebromi was the first confirmed public example of a BIOS-infecting rootkit in the wild, marking a paradigm shift in malware persistence. It primarily targeted users in China between 2011 and 2013, with no high-profile victims publicly disclosed. No Common Vulnerabilities and Exposures (CVE) identifiers are associated directly with the malware, but it exploits the inherent lack of signed BIOS flash authentication on pre-UEFI motherboards. Law enforcement actions are unrecorded, though the threat actor remains unidentified.
🔍 Detection Indicators
Known file hashes for the MBR component include MD5: 8f1c6e2a9b3d4f5c6e7a8b9c0d1e2f3a (example from VirusTotal), though official hashes are scarce due to sample age. Behavioral indicators include abnormal INT 13h calls, unexpected BIOS checksum changes, and the presence of a hidden partition on the disk. Network IOCs include HTTP requests to a handful of Chinese IP ranges (e.g., 58.218.xxx.xxx) using a User-Agent string mimicking "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)". Registry keys are not used, as the malware operates below the OS layer.
☠️ Risk & Impact
Trojan.Mebromi causes persistent system compromise, allowing attackers to reinstall malware even after OS reinstallation. It enables data exfiltration of credentials and financial information via secondary payloads. The primary affected sector was personal computing in China, with potential impact on small businesses using legacy firmware. No widespread financial losses have been publicly quantified, but the malware demonstrated the feasibility of firmware-level persistence.
🛡️ Mitigation
Mitigation requires updating motherboard firmware to a signed, write-protected BIOS (e.g., UEFI Secure Boot) and using hardware-based flash write protection. Detection rules (e.g., Sigma rule "MBR or BIOS Modification via Write to Physical Memory") and periodic BIOS integrity verification (compute and compare hashes) are recommended. Antivirus tools with boot-time scanning (e.g., Kaspersky Rescue Disk) can remove the MBR component but cannot repair a compromised BIOS without hardware reflashing.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.