Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels
Researchers studying cybersecurity have provided insight into what has been called the first Linux-based Unified Extensible Firmware Interface (UEFI) bootkit.
The bootkit, known as Bootkitty by its developers, BlackCat, is deemed a proof-of-concept (PoC) and there is no proof that it has been used in actual attacks. It was posted to the VirusTotal website on November 5, 2024, and is also known as IranuKit.
According to ESET researchers Martin Smolár and Peter Strýček, the bootkit's primary objective is to deactivate the kernel's signature verification mechanism and preload two unknown ELF files via the Linux init process, which is the first process the Linux kernel runs when the system boots up read more about Researchers Discover "Bootkitty" First UEFI Bootkit Targeting Linux Kerne...

