logo

Glupteba Botnet Evades Detection with Undocumented UEFI Bootkit

ID: b2157db0-46d4-54a4-9177-318d56a3d133

STIX ID: report--b2157db0-46d4-54a4-9177-318d56a3d133

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-02-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers report that the Glupteba botnet has incorporated an undocumented UEFI bootkit (based on a modified EfiGuard) to achieve stealthy persistence; Glupteba remains a modular information-stealing backdoor used for cryptocurrency mining, proxying, credential theft, and payload delivery, distributed via multi-stage infection chains (PrivateLoader/SmokeLoader/PPI) and employing the Bitcoin blockchain as a resilient backup C2, with widespread activity observed across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.