[ROCKBOOT](https://attack.mitre.org/software/S0112) is a [Bootkit](https://attack.mitre.org/techniques/T1542/003) that has been used by an unidentified, suspected China-based group. (Citation: FireEye Bootkits)
Actors that use this
0 tracked actors
No tracked actor uses this yet
Not linked to any of our tracked MENA actors in actor_software — still browsable via the ATT&CK dictionary above.