ESET Unveils “Bootkitty”: The First UEFI Bootkit Targeting Linux Systems
ID: 3aba4b5a-46cf-5381-8aec-4b5490e1d73a
STIX ID: report--3aba4b5a-46cf-5381-8aec-4b5490e1d73a
Feed Name: securityonline.info
Threat Score
ESET researchers disclosed Bootkitty, a proof-of-concept UEFI bootkit targeting Linux that disables kernel signature verification and patches the kernel during decompression to allow unsigned modules; its hardcoded patterns and lack of kernel-version checks limit reliability, and ESET published related IoCs and noted a possibly related unsigned module (BCDropper) on VirusTotal—users are advised to enable Secure Boot and keep firmware and revocation lists updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
