Glupteba Botnet Adds UEFI Bootkit to Cyberattack Toolbox
ID: eb97cb7d-c131-5d14-9a75-5b1398b6b242
STIX ID: report--eb97cb7d-c131-5d14-9a75-5b1398b6b242
Feed Name: Dark Reading
Threat Score
Glupteba, a long-running modular botnet and malware family, has been observed using a UEFI bootkit implant that lives in the EFI System Partition to execute before Windows boots, disable driver signature enforcement and PatchGuard, and thereby achieve resilient persistence; the report details its multifaceted capabilities (backdoor, infostealer, loader, cryptominer, ad fraud), global distribution, and the tradecraft (EfiGuard and other tools) used in recent campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
