Glupteba Botnet Evades Detection with Undocumented UEFI Bootkit
ID: b2157db0-46d4-54a4-9177-318d56a3d133
STIX ID: report--b2157db0-46d4-54a4-9177-318d56a3d133
Feed Name: The Hacker News
Researchers report that the Glupteba botnet has incorporated an undocumented UEFI bootkit (based on a modified EfiGuard) to achieve stealthy persistence; Glupteba remains a modular information-stealing backdoor used for cryptocurrency mining, proxying, credential theft, and payload delivery, distributed via multi-stage infection chains (PrivateLoader/SmokeLoader/PPI) and employing the Bitcoin blockchain as a resilient backup C2, with widespread activity observed across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
