logo

Glupteba Botnet Adds UEFI Bootkit to Cyberattack Toolbox

ID: eb97cb7d-c131-5d14-9a75-5b1398b6b242

STIX ID: report--eb97cb7d-c131-5d14-9a75-5b1398b6b242

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-02-13

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Glupteba, a long-running modular botnet and malware family, has been observed using a UEFI bootkit implant that lives in the EFI System Partition to execute before Windows boots, disable driver signature enforcement and PatchGuard, and thereby achieve resilient persistence; the report details its multifaceted capabilities (backdoor, infostealer, loader, cryptominer, ad fraud), global distribution, and the tradecraft (EfiGuard and other tools) used in recent campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.