Skip to content

Malware

BOOSTWRITE

FireEye describes BOOSTWRITE as a loader crafted to be launched via abuse of the DLL search order of applications which load the legitimate ‘Dwrite.dll’ provided by the Microsoft DirectX Typography Se

BOOSTWRITE is a Windows malware family operated by Anunak.

Background

According to FireEye, BOOSTWRITE is a loader designed to run by abusing the DLL search order of applications that load the legitimate ‘Dwrite.dll’ from the Microsoft DirectX Typography Services. In this chain, the application loads the ‘gdi’ library, which in turn loads ‘gdiplus’, which finally loads ‘Dwrite’. Mandiant observed cases in which BOOSTWRITE was dropped on disk next to the RDFClient binary, causing the application to import DWriteCreateFactory from it instead of from the genuine DWrite.dll.


Source: Malpedia (Fraunhofer FKIE).