By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels
Tech News

Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels

By Viral Trending Content 3 Min Read
Share
SHARE

Nov 27, 2024Ravie LakshmananLinux / Malware

UEFI Linux Bootkit

Cybersecurity researchers have shed light on what has been described as the first Unified Extensible Firmware Interface (UEFI) bootkit designed for Linux systems.

Dubbed Bootkitty by its creators who go by the name BlackCat, the bootkit is assessed to be a proof-of-concept (PoC) and there is no evidence that it has been put to use in real-world attacks. Also tracked as IranuKit, it was uploaded to the VirusTotal platform on November 5, 2024.

“The bootkit’s main goal is to disable the kernel’s signature verification feature and to preload two as yet unknown ELF binaries via the Linux init process (which is the first process executed by the Linux kernel during system startup),” ESET researchers Martin Smolár and Peter Strýček said.

Cybersecurity

The development is significant as it heralds a shift in the cyber threat landscape where UEFI bootkits are no longer confined to Windows systems alone.

It’s worth noting that Bootkitty is signed by a self-signed certificate, and therefore cannot be executed on systems with UEFI Secure Boot enabled unless an attacker-controlled certificate has been already installed.

UEFI Linux Bootkit

Regardless of the UEFI Secure Boot status, the bootkit is mainly engineered to boot the Linux kernel and patch, in memory, the function’s response for integrity verification before GNU GRand Unified Bootloader (GRUB) is executed.

Specifically, it proceeds to hook two functions from the UEFI authentication protocols if Secure Boot is enabled in such a way that UEFI integrity checks are bypassed. Subsequently, it also patches three different functions in the legitimate GRUB boot loader to sidestep other integrity verifications.

Cybersecurity

The Slovakian cybersecurity company said its investigation into the bootkit also led to the discovery of a likely related unsigned kernel module that’s capable of deploying an ELF binary dubbed BCDropper that loads another as-yet-unknown kernel module after a system start.

The kernel module, also featuring BlackCat as the author’s name, implements other rootkit-related functionalities like hiding files, processes, and opening ports. There is no evidence to suggest a connection to the ALPHV/BlackCat ransomware group at this stage.

“Whether a proof-of-concept or not, Bootkitty marks an interesting move forward in the UEFI threat landscape, breaking the belief about modern UEFI bootkits being Windows-exclusive threats,” the researchers said, adding “it emphasizes the necessity of being prepared for potential future threats.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Our Favorite Amazon Streaming Stick Is Almost Half Off

How is Australia working to make data centres more sustainable?

Google Pixel 11 Design Leaked: Two key Changes

Are Biofuels Worse Than Fossil Fuels?

Critical Citrix NetScaler memory flaw actively exploited in attacks

TAGGED: BlackCat, Cyber Security, Cybersecurity, ESET, Internet, Linux, Malware, Rootkits, Secure Boot, Threat Intelligence, UEFI
Share This Article
Facebook Twitter Copy Link
Previous Article Trump promised mass deportations. Educators worry fear will keep immigrants’ kids from school.
Next Article Where’s The FOMO? Bitcoin Retail Crowd Yet To Jump In, Analyst Says
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Our Favorite Amazon Streaming Stick Is Almost Half Off
Tech News
Leafs Score Today: Latest Toronto Maple Leafs Game Result and Key Stats
Sports
US Stocks: S&P, Nasdaq end lower as investors weigh Middle East conflict outlook
Business
Sky price outlook as project diversifies revenue streams and yield strategies
Crypto
How much do you need in a Stocks and Shares ISA for a £10,000 second income?
Business
DNC Playbook Offers Self-Critique of Party’s Organizing Failures Ahead of 2026 Midterms
Politics
Midnight brings a new level of faction cooperation to WoW
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?