By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels
Tech News

Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels

By Viral Trending Content 3 Min Read
Share
SHARE

Nov 27, 2024Ravie LakshmananLinux / Malware

UEFI Linux Bootkit

Cybersecurity researchers have shed light on what has been described as the first Unified Extensible Firmware Interface (UEFI) bootkit designed for Linux systems.

Dubbed Bootkitty by its creators who go by the name BlackCat, the bootkit is assessed to be a proof-of-concept (PoC) and there is no evidence that it has been put to use in real-world attacks. Also tracked as IranuKit, it was uploaded to the VirusTotal platform on November 5, 2024.

“The bootkit’s main goal is to disable the kernel’s signature verification feature and to preload two as yet unknown ELF binaries via the Linux init process (which is the first process executed by the Linux kernel during system startup),” ESET researchers Martin Smolár and Peter Strýček said.

Cybersecurity

The development is significant as it heralds a shift in the cyber threat landscape where UEFI bootkits are no longer confined to Windows systems alone.

It’s worth noting that Bootkitty is signed by a self-signed certificate, and therefore cannot be executed on systems with UEFI Secure Boot enabled unless an attacker-controlled certificate has been already installed.

UEFI Linux Bootkit

Regardless of the UEFI Secure Boot status, the bootkit is mainly engineered to boot the Linux kernel and patch, in memory, the function’s response for integrity verification before GNU GRand Unified Bootloader (GRUB) is executed.

Specifically, it proceeds to hook two functions from the UEFI authentication protocols if Secure Boot is enabled in such a way that UEFI integrity checks are bypassed. Subsequently, it also patches three different functions in the legitimate GRUB boot loader to sidestep other integrity verifications.

Cybersecurity

The Slovakian cybersecurity company said its investigation into the bootkit also led to the discovery of a likely related unsigned kernel module that’s capable of deploying an ELF binary dubbed BCDropper that loads another as-yet-unknown kernel module after a system start.

The kernel module, also featuring BlackCat as the author’s name, implements other rootkit-related functionalities like hiding files, processes, and opening ports. There is no evidence to suggest a connection to the ALPHV/BlackCat ransomware group at this stage.

“Whether a proof-of-concept or not, Bootkitty marks an interesting move forward in the UEFI threat landscape, breaking the belief about modern UEFI bootkits being Windows-exclusive threats,” the researchers said, adding “it emphasizes the necessity of being prepared for potential future threats.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

How is Australia working to make data centres more sustainable?

Google Pixel 11 Design Leaked: Two key Changes

Are Biofuels Worse Than Fossil Fuels?

Critical Citrix NetScaler memory flaw actively exploited in attacks

Quantum computing company IQM to fuel R&D with €50m investment

TAGGED: BlackCat, Cyber Security, Cybersecurity, ESET, Internet, Linux, Malware, Rootkits, Secure Boot, Threat Intelligence, UEFI
Share This Article
Facebook Twitter Copy Link
Previous Article Trump promised mass deportations. Educators worry fear will keep immigrants’ kids from school.
Next Article Where’s The FOMO? Bitcoin Retail Crowd Yet To Jump In, Analyst Says
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

This airline is rolling out economy class rows that convert into beds for long-haul flights
Travel
How is Australia working to make data centres more sustainable?
Tech News
Nepal arrests former prime minister and home minister over deadly ‘Gen Z protests’ crackdown
World News
Prediction Markets Hit Record Highs As Bets Explode On Global Conflict
Crypto
Céline Dion’s Health Updates: What Is Stiff-Person Syndrome?
Celebrity
Nintendo’s Leaks Could Become “A Major Priority Going Forward,” Claims Former Senior PR Manager
Gaming News
Jerome Powell to Gen Z: don’t fear AI—master it
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?