logo

Bootkitty: Analyzing the first UEFI bootkit for Linux

ID: 9e165763-c827-5f1d-a85c-ffa43238f8fd

STIX ID: report--9e165763-c827-5f1d-a85c-ffa43238f8fd

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
35/100

Date Published: 2024-11-27

Date Updated: 2026-05-01

...
...

ESET researchers analyzed Bootkitty, a UEFI bootkit uploaded to VirusTotal that targets certain Linux/Ubuntu configurations: it hooks UEFI authentication, patches GRUB and the Linux EFI stub, disables module signature checking (module_sig_check), and injects LD_PRELOAD to load further ELF stages; a possibly related unsigned kernel module (BCDropper) drops and runs an observer (BCObserver) that loads another kernel module. The report concludes Bootkitty appears to be a proof‑of‑concept with limited configuration support, not seen deployed in the wild, and provides IoCs and mitigation guidance (enable Secure Boot, keep firmware/OS updated, restore legitimate GRUB).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.