'Bootkitty' First Bootloader to Take Aim at Linux
ID: d67a9f8b-b0c3-5c7f-845a-ad0e972cdcf4
STIX ID: report--d67a9f8b-b0c3-5c7f-845a-ad0e972cdcf4
Feed Name: Dark Reading
Threat Score
Researchers discovered 'Bootkitty,' a proof-of-concept UEFI bootkit for Linux that uses a LogoFAIL image-parsing exploit (CVE-2023-40238) to bypass Secure Boot, modify GRUB signature verification in memory, and preload ELF binaries; analyses by ESET and Binarly indicate it is functional but appears limited in scope and likely created by students for awareness rather than active campaign dissemination.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
