Skip to content

Pitou

Pitou, also known as Backboot, is a Windows bootkit and kernel-mode spambot active since at least 2014.

Pitou

Family profile

Pitou, also known as Backboot, is a Windows bootkit and kernel-mode spambot active since at least 2014. It infects Master Boot Record-based systems to achieve execution before the operating system fully loads, allowing it to bypass kernel-mode code-signing protections and install a malicious driver on both 32-bit and 64-bit Windows systems, including versions from Windows XP through Windows 10. Its architecture spans multiple boot stages and, on 64-bit systems, extends through the Windows boot chain into the kernel before launching its payload.

The malware’s primary purpose is to send spam from infected victim machines. Its spam functionality operates from kernel mode, and Pitou also includes resilient command-and-control logic through a domain generation algorithm used as fallback communications infrastructure. That DGA is unusually sophisticated in that it executes in kernel mode inside a custom virtual machine, uses encrypted string tables, dynamically resolved APIs, and date-based seeding, and generates batches of pronounceable domains across multiple top-level domains.

Pitou employs extensive stealth and anti-analysis measures. It stores components in disk space outside normal partitions, hooks the boot process across real mode, protected mode, and kernel initialization, and intercepts disk operations to conceal MBR infection by returning benign data to user-mode inspection. Additional evasion includes heavy obfuscation, anti-virtualization checks, and NDIS hooking to obscure network communication. Reverse engineering has also shown that Pitou uses a rootkit component with dynamically resolved API calls and custom virtualization to protect critical logic.

Pitou has been associated with drive-by download infections from compromised websites and delivery by other malware. It targets legacy BIOS/MBR environments rather than UEFI systems. Its combination of bootkit persistence, kernel-mode stealth, anti-VM behavior, and spam-bot functionality made it one of the more sophisticated late-stage MBR bootkits observed in the wild.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence

Samples

Recent samples

44 sandbox samples in the Derp library, newest 24 shown

ea04dd6189f8017acf9c57c67d8ea5a9cb559fbfc667ec10c0f995c6271f8065
Analysed Oct 2, 2026Triage report
874aaeb0813eee02b317c0acf24ef612f223db2bcea3e1c2d23a246810771771
Analysed Oct 1, 2026Triage report
d9557c4b59b55d932b8b018ee8a6b668a24b8893f63c10fabd62c0c221186272
Analysed Oct 1, 2026Triage report
7f359a2477547d670d60c3b4a4cb4aed5453c826f8278f32d0ca5d4ae1d1b4dd
Analysed Oct 1, 2026Triage report
c0a192e5e86001e1dc6da4ee5b4dc61d07967c01f1c3aec1ab699cc3b021ee1e
Analysed Oct 1, 2026Triage report
517471b6c65e84cc120f692e6938a0eabe1e7e5b8e046bcf90a19d841dea6cc1
Analysed Sep 30, 2026Triage report
bb7c5aebcf99b26747717519bfa90f28431e75dd2a4a2b0cc05f541cd625a93e
Analysed Sep 30, 2026Triage report
a6ca229946ad2db5e2402e630cbd1c9f70459f958da603580e3f6dc4b6c508d4
Analysed Sep 30, 2026Triage report
eb77c178afe84fa6c202a6c381bc922996d9e47710124200c4387fe889b19f88
Analysed Sep 30, 2026Triage report
a71e0df14002731ac1e55e84634165507401c94f4e65e457c106a6c8cc2bd270
Analysed Sep 30, 2026Triage report
31b417066bb1e31a3a1e3531df95df5f6b75d6c75d5497b233c1904ba9c49329
Analysed Sep 30, 2026Triage report
4c819c3d0e2950cea891534bd6f0224ca35a975ee5ded83b69236246bbbdeca2
Analysed Sep 30, 2026Triage report
d317e1490bc0a53e49cc121b26a2479c9b9253c4aabeec1776d89faf08d15b74
Analysed Sep 30, 2026Triage report
b93842f1681ead3cabf883ada8c58d01f03f631e4d81fbab4e03e58216aa7468
Analysed Sep 30, 2026Triage report
4d0319a4cfc928ce456e503d8d10e0fe0c1c47e9c16f9a5837a887a24247e2a6
Analysed Sep 30, 2026Triage report
1cdba373b69dc3ec3d753cb099b24aebd468634f1388990fd56bdafb3210fa80
Analysed Sep 30, 2026Triage report
f4c5697ca489577251a6f7b3d36ecf5492077247ffc82c0e354df8a2c7e07a14
Analysed Sep 30, 2026Triage report
8d6a638a93022489ab3697ab011361e1a9e5d2ab4693d35d3af86a0f1466f931
Analysed Sep 30, 2026Triage report
99dcc9b2e7624b6dc544c87200c7c39055d54bd6de7a7021bb4f04de8ae79f1c
Analysed Sep 30, 2026Triage report
9553aa86a155c557aac2b69caa60d133d3715523a71560934223a07b8dcd4af4
Analysed Sep 30, 2026Triage report
7e85c05fde969452b6b2834407f7fd24def10e61fb7bc6c270ffb1c7e86221e3
Analysed Sep 30, 2026Triage report
a9c3af0fd9d5f91d132822eb9fd7ac153ef0e15a12c12ab408f0b4144463c33d
Analysed Sep 30, 2026Triage report
29cb810e1deb1a0368cc8482684e0cb097a43530b63cc58e26f730f6cba7564b
Analysed Sep 30, 2026Triage report
2f569167bdf00630675ff446068edae53225ab04f7f61ad2dc62d7e20656dfa2
Analysed Sep 30, 2026Triage report

MITRE ATT&CK

Pitou in ATT&CK

9 distinct techniques