Hackers operating primarily in Southeast Asia have developed a new bootkit trojan that masquerades as Microsoft’s built-in Net command to evade detection.
The threat was discovered by Russian security vendor Kaspersky Labs, which goes on to say that the bootkit appears to be an evolution of the HDD Rootkit, a similar tool first detected back in 2006.
This new version has been dubbed HDRoot due to its similarities to the original rootkit and has been developed by an advanced persistent threat (APT) known as the Winnti Group, which has been active since 2009.
Kaspersky claims that the bootkit is actively being exploited in the wild, and after it was first detected and blocked, Winnti hackers quickly made modifications to the original HDRoot source code in response.
Security researchers report that most HDRoot attacks have been observed in South Korea, but that the United Kingdom and Russia have also been affected.
How this particular bootkit works is by hiding inside a modified version of the Net command utility, net.exe. The functionality is not changed, so when users run net.exe they will not notice anything wrong.

This file is suspicious, however, mainly because it is signed with a certificate issued by the Chinese company Guangzhou YuanLuo Technology, which was reported as suspicious some time ago.
This is the entry point into infected systems, allowing it to compromise the target's MBR (Master Boot Record) hard drive and from there, download and launch any other malware.
In the HDRoot samples it was able to analyze, Kaspersky observed that the bootkit had two backdoors. To do this, it used two methods.
In the first method, it theoretically placed the backdoors using a suspicious Svchost.exe file, which was visible to AV products, while in the second it worked as a memory-hosted exploit, much harder to detect.
In addition to the preventive measures taken by the HDRoot creator to hide the bootkit in its initial stages of infection and more specifically not to prevent or delay the operating system from booting, Kaspersky researchers said that the bootkit paralyzes some other Windows services, such as Windows Update or the Task Scheduler, which stop working altogether.
Additionally, antivirus engines could detect the presence of HDRoot on a system using some other clues left behind by the bootkit, such as incorrect registry path names and variable names, and incorrectly replaced registry values.
Kaspersky said that antivirus product is able to detect HDRoot.
