logo

BootKitty UEFI malware exploits LogoFAIL to infect Linux systems

ID: 9944be49-e422-598a-96e3-cd3c545ede2b

STIX ID: report--9944be49-e422-598a-96e3-cd3c545ede2b

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-12-02

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Bootkitty is an in-development UEFI bootkit for Linux that abuses the LogoFAIL (CVE-2023-40238) image-parsing flaw to embed shellcode in BMP logos, bypass Secure Boot, and install a rogue bootloader; analysis shows device-specific targeting (Insyde/Lenovo firmware) and limited current impact, and the project authors later stated it was a student research/awareness exercise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.