ESET Research discovers the first UEFI bootkit for Linux

ESET Research has discovered the first UEFI bootkit designed for Linux systems, which has been named Bootkitty by its creators. In November 2024, a previously unknown application, named bootkit.efi, was uploaded to VirusTotal. Upon inspection, ESET Research discovered it to be a UEFI application. Further analysis confirmed that it is a UEFI bootkit, named Bootkitty … More ESET Research discovers the first UEFI bootkit for Linux

ESET Research Podcast: Finding the mythical BlackLotus bootkit

A story of how analysis of a supposed game cheat turned into a discovery of a powerful UEFI threat. Towards the end of 2022 an unknown threat actor boasted on an underground forum that they’d created a new and powerful UEFI bootkit called BlackLotus. Its most distinctive feature? It could bypass UEFI Secure Boot – a … More ESET Research Podcast: Finding the mythical BlackLotus bootkit

What does $5,000 buy you on a hacking forum?

For a mere $5,000, you can buy a UEFI bootkit called BlackLotus that can run even on fully up-to-date Windows 11 systems with UEFI Secure Boot enabled. This week, ESET researchers published their analysis of BlackLotus that caused them to conclude that the bootkit they had discovered in the wild is indeed the BlackLotus bootkit … More What does $5,000 buy you on a hacking forum?

ESET Research analyzes BlackLotus: A UEFI bootkit that can bypass UEFI Secure Boot on fully patched systems

ESET researchers are the first to publish an analysis of BlackLotus, the first in-the-wild UEFI bootkit that is capable of bypassing an essential platform security feature — UEFI Secure Boot. This UEFI bootkit has been sold on hacking forums for USD$5,000 since at least October 2022 and can run even on fully up-to-date Windows 11 … More ESET Research analyzes BlackLotus: A UEFI bootkit that can bypass UEFI Secure Boot on fully patched systems