Daniel Roberson
  • Posts
  • About
  • Notes
  • Projects
  • Time
  • Posts
    About
    Notes
    Projects
    Time

bootkitty-vijayan2024

2025-04-17

‘Bootkitty’ First Bootloader to Take Aim at Linux

by Jai Vijayan

DarkReading

December 2, 2024

https://www.darkreading.com/cyber-risk/bootkitty-first-bootloader-target-linux-systems

Notes
Secure Boot
Linux Malware
Bootkitty
bootloader
malware
proof of concept
Korea
cybersecurity
LogoFAIL
UEFI
Binarly Research
persistence
https://www.welivesecurity.com/en/eset-research/bootkitty-analyzing-first-uefi-bootkit-linux/
BlackLotus
FinSpy
Windows
ELF
init process
preload
ESET
Martin Smolar, Peter Strycek
Binarly
CVE-2023-40238
shellcode
bitmap image (BMP)
Lenovo
Fujitsu
HP
Acer
https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux
bootloaders are often overlooked by defenders
CVE-2022-2189 – Baton Drop
CVE-2023-24932
CISA
Microsoft
PKI
GRUB
ASCII art
VirusTotal

Links to this note

  • Notes

Recent Posts

Linux Persistence: Modular Software

2025-04-17 DFIR CTF persistence linux persistence apache asterisk

Linux Persistence: Web Shells

2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP

Linux Persistence: Rootkits

2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking

Linux Persistence: Processes

2025-04-11 DFIR persistence processes linux persistence processes

Defanging Linux LKM Rootkits With cleanup_module()

2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit


Home

About

Notes

Projects

Time

© All rights reserved. Powered by Hugo and Erblog.