A malware analyst has deconstructed a highly advanced piece of crimeware believed to be the work of the notorious Russian Business Network. The step-by-step instructions for reverse engineering the stealthy ZeroAccess rootkit is a blow to its developers, who took great care to make sure it couldn't be forensically analyzed.. The tutorial means other malware researchers may also study the malware to close in on the people behind it and to better design products that can safeguard against it. The analysis was written by Giuseppe Bonfa, a malware researcher specializing in reverse engineering at InfoSec Institute, an information security services company. It documents a rootkit that's almost impossible to remove without damaging the host operating system and uses low-level programming calls to create hard disk volumes that are virtually impossible to detect using normal forensic techniques. Sophos's description of the rootkit, which is also known as Smiscer, is here. The link for this article located at The Register UK is no longer available. . Unlock the skills to reverse engineer the ZeroAccess rootkit with this guided tutorial, enhancing your malware analysis and defensive strategies against threats. ZeroAccess Rootkit, Crimeware Analysis, Malware Research, Cybersecurity Insights. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.