Check out the results from our first round of ATT&CK Evaluations at attackevals.mitre.org!

ROCKBOOT

ROCKBOOT is a Bootkit that has been used by an unidentified, suspected China-based group. [1]

ID: S0112
Aliases: ROCKBOOT
Type: MALWARE
Platforms: Windows

Version: 1.0

Techniques Used

DomainIDNameUse
EnterpriseT1067BootkitROCKBOOT is a Master Boot Record (MBR) bootkit that uses the MBR to establish persistence.[1]

References