Jan 5th

MBR Rootkit: follow up

Posted by: Marco Giuliani

Bookmark Now

I add a short follow up to the previous blog post about MBR Rootkit.

Most of the websites we have been monitoring that spread the MBR rootkit are using iframe code in compromised webpages, a widely known attack vector that has become widespread over the last few years.

Dropper iframe

We've seen that one of the most widely exposed countries to this attack is Italy, where these malicious pages are already seen on compromised web sites.

Leave a reply








Monthly Archives

Yearly Archives

Stay Updated

YouTube Channel

Find us on Facebook