October 2023
Intermediate to advanced
312 pages
8h 26m
English
In 2012, adversaries launched the Zacinlo adware campaign, whose rootkit, a member of the Detrahere family, includes a number of self-protection features. One of the most interesting is its persistence mechanism.
Similar to the callback routines discussed in Chapters 3 through 5, drivers can register callback routines called shutdown handlers that let them perform some action when the system is shutting down. To ensure that their rootkit persisted on the system, the Zacinlo rootkit developers used a shutdown handler to rewrite the driver to disk under a new name and create new registry keys for a service ...
Read now
Unlock full access