Rombertik malware puts your MBR at risk.

In an email from Knowbe4 they presented information on the new Robertik attack. This malware travels as an email carrying an attachment that is saved as a .scr file. SCR files are screen saver files and are executed by the Operating System when the screen saver is loaded.

Robertik has two interesting features. First it has a component that spies on what you are doing and reports back to a collecting server.

It’s second feature is the more critical piece. It has the ability to recognize detection software and when it does it causes damage to the MBR of the hard drive.


Care and employee education is the best protection. Don’t automatically execute  a link just because it can be. Evaluate the content, sender and if it is even pertinent to what you are doing.

