Tag: UEFI Bootkit

Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels
News

Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels

Researchers studying cybersecurity have provided insight into what has been called the first Linux-based Unified Extensible Firmware Interface (UEFI) bootkit. The bootkit, known as Bootkitty by its developers, BlackCat, is deemed a proof-of-concept (PoC) and there is no proof that it has been used in actual attacks. It was posted to the VirusTotal website on November 5, 2024, and is also known as IranuKit. According to ESET researchers Martin Smolár and Peter Strýček, the bootkit's primary objective is to deactivate the kernel's signature verification mechanism and preload two unknown ELF files via the Linux init process, which is the first process the Linux kernel runs when the system boots up read more about Researchers Discover "Bootkitty" First UEFI Bootkit Targeting Linux Kerne...
Glupteba Botnet Evades Detection with Undocumented UEFI Bootkit
News

Glupteba Botnet Evades Detection with Undocumented UEFI Bootkit

It has been discovered that the Glupteba botnet uses a previously unreported Unified Extensible Firmware Interface (UEFI) bootkit functionality, which gives the virus an extra degree of stealth and sophistication. Researchers Lior Rochberger and Dan Yashnik of Palo Alto Networks Unit 42 wrote in a Monday analysis that "this bootkit can intervene and control the [operating system] boot process, enabling Glupteba to hide itself and create a stealthy persistence that can be extremely difficult to detect and remove." Glupteba is a feature-rich backdoor and information stealer that can be used to install proxy components on compromised hosts and enable illegal bitcoin mining. To withstand takedown attempts, it is also known to use the Bitcoin blockchain read more Glupteba Botnet Evades D...