logo

white-papers-defeating-x-64-modern-trends-of-kernel-mode-rootkits.pdf

ID: e762e544-b314-40b4-9dfd-99dce5a8c6a7

STIX ID: report--e762e544-b314-40b4-9dfd-99dce5a8c6a7

Threat Score

78/100

Uploaded: 2026-08-05

Published Date: 2026-08-05

Last Modified Date: 2026-08-05

Created by: gogogo

TLP:GREEN
...
...
This ESET technical presentation analyzes the evolution and modern techniques of x64 kernel-mode rootkits and bootkits (TDL4/Olmarik and Win64/Rovnix). It details installation flows, methods to subvert Windows kernel-mode code signing and PatchGuard (BCD manipulation, WinPE abuse, bootloader/MBR/VBR infection), hidden on-disk file systems, driver loading tricks, and debugging/forensic techniques (Bochs, WinDbg, HiddenFsReader). The paper includes code snippets, diagrams, and indicators (file names and MD5s) useful for detection and analysis.