Home Malware Programs Rootkits Phase Bot

Phase Bot

Posted: January 13, 2015

Threat Metric

Threat Level: 8/10
Infected PCs: 5
First Seen: January 13, 2015
Last Seen: November 7, 2021
OS(es) Affected: Windows

Phase Bot is a rootkit that can be installed on a computer system without its own process and without leaving any files into the disk. Phase Bot targets Windows systems and can infect computers running Windows XP and subsequent versions. Phase Bot's relocatable code is concealed in the Registry and in order to execute it into memory, Phase Bot uses PowerShell (a standard feature installed in various Windows versions). If Phase Bot is targeting a computer that runs an older version of Windows that doesn't have PowerShell installed, Phase Bot has alternative installation methods. Phase Bot is able to bypass anti-malware programs with rootkit detection capability by using a new method which makes Phase Bot a highly stealth loader. Third parties can easily buy Phase Bot from its website and the asking price is 0.8 Bitcoin.

Loading...