{"id":16615,"date":"2012-06-07T11:08:36","date_gmt":"2012-06-07T18:08:36","guid":{"rendered":"http:\/\/blogs.mcafee.com\/?p=16615"},"modified":"2025-05-28T18:39:38","modified_gmt":"2025-05-29T01:39:38","slug":"bioskits-join-ranks-of-stealth-malware","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/","title":{"rendered":"&#8216;Bioskits&#8217; Join Ranks of Stealth Malware"},"content":{"rendered":"<p>We have seen many discussions of the MyBios &#8220;Bioskit&#8221; discovered at the end of 2011. MyBios was the first malware to successfully infect the Award BIOS and survive the reboot. It was first discovered by a Chinese security company; many other security vendors published detailed analyses after that.<\/p>\n<p>We have seen a lot of samples targeting the master boot record (MBR) to survive a reboot and reinfect a system. We found a sample in our collection that infected the MBR. Further investigation showed that the next variant of the malware was a Bioskit. The first variant of the malware was an executable that infected the MBR; the second was a DLL with the Bioskit component. We will discuss the second variant in this blog.<\/p>\n<h2><strong>DLL Analysis<\/strong><\/h2>\n<p>The malware&#8217;s main dropper is a DLL that is responsible for the MBR infection. It reads the original MBR from Sector 0 and writes it to Sector 15.<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=16747\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16747\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg\" alt=\"\" width=\"658\" height=\"405\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg 658w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1-300x184.jpg 300w\" sizes=\"auto, (max-width: 658px) 100vw, 658px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><em>MyBios code writes the malicious MBR.<\/em><\/p>\n<p>The malware overwrites the original MBR in sector 0 and writes the file to be dropped (the downloader) in hidden sectors. The DLL copies itself to the Recycle folder and deletes itself. The downloader is dropped and executed every time the system is started.<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=16748\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16748\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Malicious_MBR1.jpg\" alt=\"\" width=\"534\" height=\"515\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Malicious_MBR1.jpg 534w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Malicious_MBR1-300x289.jpg 300w\" sizes=\"auto, (max-width: 534px) 100vw, 534px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><em>The malicious MBR<\/em><\/p>\n<p>The next two screens show the malicious MBR code, which reads the original MBR from Sector 15 into memory at location 0000:7c00. Control passes to the original MBR at this location and the system boots in the normal way.<\/p>\n<p>Usually the boot sector is read to this memory location in a clean system after the power-on self-test and INT 19 jumps to location 0000:7c00.<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=16749\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16749\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Malicious_MBR_-at_7c00_before_interrupt1.jpg\" alt=\"\" width=\"682\" height=\"214\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Malicious_MBR_-at_7c00_before_interrupt1.jpg 682w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Malicious_MBR_-at_7c00_before_interrupt1-300x94.jpg 300w\" sizes=\"auto, (max-width: 682px) 100vw, 682px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><em>The malicious MBR at 7c00 before the interrupt<\/em><\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=16750\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16750\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Original_MBR_at_7c00_after_interrupt1.jpg\" alt=\"\" width=\"683\" height=\"218\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Original_MBR_at_7c00_after_interrupt1.jpg 683w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Original_MBR_at_7c00_after_interrupt1-300x95.jpg 300w\" sizes=\"auto, (max-width: 683px) 100vw, 683px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><em>The original MBR at 7c00 after the interrupt<\/em><\/p>\n<p>All the components dropped will be present in the DLL, including the utility cbrom.exe from the BIOS manufacturer, which the malware uses to flash the BIOS.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Dropped System File<\/strong><\/h2>\n<p>The sys file responsible for flashing the BIOS is similar to the one seen in MyBios. Unlike bios.sys, the code to check the BIOS manufacturer and the BIOS size is present in the DriverEntry. However, the functionality of both the drivers remains the same.<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=16751\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16751\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_to_check_Award_bios1.jpg\" alt=\"\" width=\"608\" height=\"382\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Code_to_check_Award_bios1.jpg 608w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Code_to_check_Award_bios1-300x188.jpg 300w\" sizes=\"auto, (max-width: 608px) 100vw, 608px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><em>Code to check for Award BIOS<\/em><\/p>\n<p>The rest of the code responsible for backing up and flashing the BIOS is present in the driver dispatch. A graph showing the code flow of both MyBios and the Niwa rootkit can be seen below.<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=16752\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16752\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Graph_of_MYBIOS_code_flow1.jpg\" alt=\"\" width=\"1258\" height=\"156\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Graph_of_MYBIOS_code_flow1.jpg 1258w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Graph_of_MYBIOS_code_flow1-300x37.jpg 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Graph_of_MYBIOS_code_flow1-1024x126.jpg 1024w\" sizes=\"auto, (max-width: 1258px) 100vw, 1258px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><em>MyBios code flow<\/em><\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=16753\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16753\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Graph_of_NIWA_code_flow1.jpg\" alt=\"\" width=\"1258\" height=\"156\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Graph_of_NIWA_code_flow1.jpg 1258w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Graph_of_NIWA_code_flow1-300x37.jpg 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Graph_of_NIWA_code_flow1-1024x126.jpg 1024w\" sizes=\"auto, (max-width: 1258px) 100vw, 1258px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><em>NIWA code flow<\/em><\/p>\n<p>What\u2019s interesting is that the strings observed in both malware are almost identical.<\/p>\n<p><strong>MyBios:<\/strong><br \/>\nThis is not an Aword BIOS!<\/p>\n<p><strong>NIWA:<\/strong><br \/>\nThis not an Aword BIOS!<\/p>\n<p><strong>Identical strings:<\/strong><br \/>\nFlash Aword BIOS form disk c bios.bin success.<br \/>\nSMI_AutoErase Aword Bios Failed.<br \/>\nExAllocatePool read file NonPagedPool failed.<br \/>\nBackup Aword BIOS to disk c bios.bin success.<br \/>\nMmMapIoSpace physics address:0x%x failed.<\/p>\n<p>It cannot be a coincidence that almost all of the strings are identical (including misspellings and bad grammar). This suggests the same individual or group is behind both of these BIOS-flashing malware.<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=16745\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16745\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/McAfee_detection_and_cleaning.jpg\" alt=\"\" width=\"525\" height=\"395\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/McAfee_detection_and_cleaning.jpg 525w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/McAfee_detection_and_cleaning-300x225.jpg 300w\" sizes=\"auto, (max-width: 525px) 100vw, 525px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><em>McAfee detection and cleaning<\/em><\/p>\n<p>McAfee detects this infection as &#8220;Niwa!mem&#8221; and successfully cleans the MBR infection and deletes all other malicious dropped components.<\/p>\n<h2><strong>Conclusion<\/strong><\/h2>\n<p>We have now seen two Bioskit malware in the wild within a couple of months. When the first Bioskit was identified, we did not know how soon we would see another. Now it appears we should expect to see more in near future. It\u2019s not hard to detect and clean the MBR, but cleaning BIOS infections will be a challenge for security vendors.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have seen many discussions of the MyBios &#8220;Bioskit&#8221; discovered at the end of 2011. MyBios was the first malware&#8230;<\/p>\n","protected":false},"author":674,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[442],"tags":[180],"coauthors":[3973],"class_list":["post-16615","post","type-post","status-publish","format-standard","hentry","category-mcafee-labs","tag-malware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>&#039;Bioskits&#039; Join Ranks of Stealth Malware | McAfee Blog<\/title>\n<meta name=\"description\" content=\"We have seen many discussions of the MyBios &quot;Bioskit&quot; discovered at the end of 2011. MyBios was the first malware to successfully infect the Award BIOS\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"&#039;Bioskits&#039; Join Ranks of Stealth Malware | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"We have seen many discussions of the MyBios &quot;Bioskit&quot; discovered at the end of 2011. MyBios was the first malware to successfully infect the Award BIOS\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2012-06-07T18:08:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-29T01:39:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"658\" \/>\n\t<meta property=\"og:image:height\" content=\"405\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"McAfee\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"McAfee\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/\"},\"author\":{\"name\":\"McAfee\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\"},\"headline\":\"&#8216;Bioskits&#8217; Join Ranks of Stealth Malware\",\"datePublished\":\"2012-06-07T18:08:36+00:00\",\"dateModified\":\"2025-05-29T01:39:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/\"},\"wordCount\":596,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg\",\"keywords\":[\"malware\"],\"articleSection\":[\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/\",\"name\":\"'Bioskits' Join Ranks of Stealth Malware | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg\",\"datePublished\":\"2012-06-07T18:08:36+00:00\",\"dateModified\":\"2025-05-29T01:39:38+00:00\",\"description\":\"We have seen many discussions of the MyBios \\\"Bioskit\\\" discovered at the end of 2011. MyBios was the first malware to successfully infect the Award BIOS\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#primaryimage\",\"url\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg\",\"contentUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"&#8216;Bioskits&#8217; Join Ranks of Stealth Malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\",\"name\":\"McAfee\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"caption\":\"McAfee\"},\"description\":\"We're here to make life online safe and enjoyable for everyone.\",\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/x.com\/McAfee\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"'Bioskits' Join Ranks of Stealth Malware | McAfee Blog","description":"We have seen many discussions of the MyBios \"Bioskit\" discovered at the end of 2011. MyBios was the first malware to successfully infect the Award BIOS","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"'Bioskits' Join Ranks of Stealth Malware | McAfee Blog","og_description":"We have seen many discussions of the MyBios \"Bioskit\" discovered at the end of 2011. MyBios was the first malware to successfully infect the Award BIOS","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_author":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2012-06-07T18:08:36+00:00","article_modified_time":"2025-05-29T01:39:38+00:00","og_image":[{"width":658,"height":405,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg","type":"image\/jpeg"}],"author":"McAfee","twitter_card":"summary_large_image","twitter_creator":"@McAfee","twitter_site":"@McAfee","twitter_misc":{"Written by":"McAfee","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/"},"author":{"name":"McAfee","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa"},"headline":"&#8216;Bioskits&#8217; Join Ranks of Stealth Malware","datePublished":"2012-06-07T18:08:36+00:00","dateModified":"2025-05-29T01:39:38+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/"},"wordCount":596,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg","keywords":["malware"],"articleSection":["McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/","name":"'Bioskits' Join Ranks of Stealth Malware | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg","datePublished":"2012-06-07T18:08:36+00:00","dateModified":"2025-05-29T01:39:38+00:00","description":"We have seen many discussions of the MyBios \"Bioskit\" discovered at the end of 2011. MyBios was the first malware to successfully infect the Award BIOS","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#primaryimage","url":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg","contentUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/06\/Code_-which_-writes_-malicious_-MBR1.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/bioskits-join-ranks-of-stealth-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"&#8216;Bioskits&#8217; Join Ranks of Stealth Malware"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa","name":"McAfee","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","caption":"McAfee"},"description":"We're here to make life online safe and enjoyable for everyone.","sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/x.com\/McAfee"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/16615","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/674"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=16615"}],"version-history":[{"count":2,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/16615\/revisions"}],"predecessor-version":[{"id":214656,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/16615\/revisions\/214656"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=16615"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=16615"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=16615"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=16615"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}