Bootkitty: Analyzing the first UEFI bootkit for Linux
ID: 9e165763-c827-5f1d-a85c-ffa43238f8fd
STIX ID: report--9e165763-c827-5f1d-a85c-ffa43238f8fd
Feed Name: WeLiveSecurity (ESET Research)
ESET researchers analyzed Bootkitty, a UEFI bootkit uploaded to VirusTotal that targets certain Linux/Ubuntu configurations: it hooks UEFI authentication, patches GRUB and the Linux EFI stub, disables module signature checking (module_sig_check), and injects LD_PRELOAD to load further ELF stages; a possibly related unsigned kernel module (BCDropper) drops and runs an observer (BCObserver) that loads another kernel module. The report concludes Bootkitty appears to be a proof‑of‑concept with limited configuration support, not seen deployed in the wild, and provides IoCs and mitigation guidance (enable Secure Boot, keep firmware/OS updated, restore legitimate GRUB).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
