Rovnix
Aliases: BkLoader, Cidox, Mayachok
- First seen
- 2011-03-01 00:00:00
- Malware type
- loader, rootkit
- Family
- Malware family
- Profile updated
- 2026-07-07 15:01:55
Targeted industries: financial-services technology-and-telecommunications
Targeted regions: country_code:us country_code:ru country_code:de
Context
Rovnix is a bootkit and consists of a driver loader (in the VBR) and the drivers (32bit, 64bit) themselves. It is part of the Carberp source code leak (https://github.com/nyx0/Rovnix). Rovnix has been used to protect Gozi ISFB, ReactorBot and Rerdom (at least).
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Rovnix_Auto (yara-rule)
Reports & references
- ptsecurity.com — Space Pirates Tools And Connections (report)
- 0xc0decafe.com — Malware Analysts Guide To Aplib Decompression (report)
- malwaredigger.com — Rovnix Dropper Analysis (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Rovnix (report)
- ESET — Rovnix Bootkit Framework Updated (report)
- kernelmode.info — Viewtopic (report)
- Kaspersky — 97365 (report)
- news.drweb.ru (report)
- Kaspersky — 29117 (report)
- virusbulletin.com — Vb2014 Rodionovmatrosov (report)
- Microsoft — The Evolution Of Rovnix New Virtual File System Vfs (report)
- malwaretech.com — Rovnix New Evolution (report)