Glupteba Botnet Evades Detection with Undocumented UEFI Bootkit
It has been discovered that the Glupteba botnet uses a previously unreported Unified Extensible Firmware Interface (UEFI) bootkit functionality, which gives the virus an extra degree of stealth and sophistication.
Researchers Lior Rochberger and Dan Yashnik of Palo Alto Networks Unit 42 wrote in a Monday analysis that "this bootkit can intervene and control the [operating system] boot process, enabling Glupteba to hide itself and create a stealthy persistence that can be extremely difficult to detect and remove."
Glupteba is a feature-rich backdoor and information stealer that can be used to install proxy components on compromised hosts and enable illegal bitcoin mining. To withstand takedown attempts, it is also known to use the Bitcoin blockchain read more Glupteba Botnet Evades D...

