BootKitty UEFI malware exploits LogoFAIL to infect Linux systems
ID: 9944be49-e422-598a-96e3-cd3c545ede2b
STIX ID: report--9944be49-e422-598a-96e3-cd3c545ede2b
Feed Name: Bleeping Computer
Threat Score
Bootkitty is an in-development UEFI bootkit for Linux that abuses the LogoFAIL (CVE-2023-40238) image-parsing flaw to embed shellcode in BMP logos, bypass Secure Boot, and install a rogue bootloader; analysis shows device-specific targeting (Insyde/Lenovo firmware) and limited current impact, and the project authors later stated it was a student research/awareness exercise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
