Rovnix

Aliases: BkLoader, Cidox, Mayachok

First seen
2011-03-01 00:00:00
Malware type
loader, rootkit
Family
Malware family
Profile updated
2026-07-07 15:01:55

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:de

Context

Rovnix is a bootkit and consists of a driver loader (in the VBR) and the drivers (32bit, 64bit) themselves. It is part of the Carberp source code leak (https://github.com/nyx0/Rovnix). Rovnix has been used to protect Gozi ISFB, ReactorBot and Rerdom (at least).

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Rovnix_Auto (yara-rule)

Reports & references

  • ptsecurity.com — Space Pirates Tools And Connections (report)
  • 0xc0decafe.com — Malware Analysts Guide To Aplib Decompression (report)
  • malwaredigger.com — Rovnix Dropper Analysis (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Rovnix (report)
  • ESET — Rovnix Bootkit Framework Updated (report)
  • kernelmode.info — Viewtopic (report)
  • Kaspersky — 97365 (report)
  • news.drweb.ru (report)
  • Kaspersky — 29117 (report)
  • virusbulletin.com — Vb2014 Rodionovmatrosov (report)
  • Microsoft — The Evolution Of Rovnix New Virtual File System Vfs (report)
  • malwaretech.com — Rovnix New Evolution (report)

External references