logo

ESET Unveils “Bootkitty”: The First UEFI Bootkit Targeting Linux Systems

ID: 3aba4b5a-46cf-5381-8aec-4b5490e1d73a

STIX ID: report--3aba4b5a-46cf-5381-8aec-4b5490e1d73a

Feed Name: securityonline.info

Threat Score
30/100

Date Published: 2024-11-27

Date Updated: 2026-04-22

Author: do son

...
...

ESET researchers disclosed Bootkitty, a proof-of-concept UEFI bootkit targeting Linux that disables kernel signature verification and patches the kernel during decompression to allow unsigned modules; its hardcoded patterns and lack of kernel-version checks limit reliability, and ESET published related IoCs and noted a possibly related unsigned module (BCDropper) on VirusTotal—users are advised to enable Secure Boot and keep firmware and revocation lists updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.