Glupteba is a long-running Windows malware family and botnet/backdoor known since at least 2011. The provided content describes it as advanced, modular, and multipurpose, historically associated with financially motivated cybercrime. Reported capabilities include backdoor/botnet functionality, spam bot activity, delivery of additional payloads, browser credential and cookie theft, theft of sensitive and credit card data, cryptocurrency theft/cryptomining, ad fraud, router exploitation, and UAC bypass. The content also notes command-and-control resilience features, including use of the Bitcoin blockchain as a backup C2 update mechanism; by 2019 it was cited as an early major example using Bitcoin OP_RETURN data to store encrypted backup C2 domains, and Google reportedly disrupted the botnet in 2021.
The malware has been distributed through multiple infection vectors in the cited material, including pay-per-install ecosystems, cracked/pirated software lures, SEO-poisoned fake software download sites, bundled installers, large-scale phishing, and multi-stage chains involving loaders such as PrivateLoader and SmokeLoader. One Sophos-described delivery ecosystem distributed Glupteba alongside Raccoon Stealer, CryptBot, cryptocurrency miners, click-fraud malware, and Conti/STOP ransomware via password-protected archives and fake cracked installers. Another analyzed case linked Glupteba-related components to a trojanized Adobe Illustrator CS6 crack and dropped files such as WinmonX.sys and windefender.exe.
A notable capability described in the content is a previously undocumented UEFI bootkit observed in a 2023 campaign. According to Unit 42, the bootkit installer was disguised as csrss.exe, mounted the EFI System Partition, renamed legitimate boot files, replaced Windows boot components, and dropped EfiGuardDxe.efi. The dropped components were assessed as modified/recompiled versions of the open-source EfiGuard bootkit, used to disable Windows PatchGuard and Driver Signature Enforcement at boot for stealthy persistence before Windows starts. The report explicitly states there was no evidence of a Secure Boot bypass in that activity. Separate content also states Peacock detected Glupteba as a real-world UEFI bootkit.
The content associates Glupteba with widespread global campaigns affecting multiple regions and industries, with impacted organizations reported in countries including Greece, Nepal, Bangladesh, Brazil, Korea, Algeria, Ukraine, Slovakia, Turkey, Italy, and Sweden. High-confidence indicators and artifacts directly mentioned in the content include use of Bitcoin-based backup C2, dropped/renamed EFI paths such as B:\EFI\Microsoft\Boot\bootmgfw.efi, B:\EFI\Microsoft\Boot\fw.efi, B:\EFI\Boot\bootx64.efi, B:\EFI\Boot\old.efi, and B:\EFI\Boot\EfiGuardDxe.efi, as well as sample names csrss.exe, WinmonX.sys, and windefender.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
"...it has increasingly become a target for advanced threats, including bootkits documented in real systems..." and "...detects multiple real-world UEFI bootkits, including Glupteba, BlackLotus, LoJax, and MosaicRegressor."
“The installer has a function main_writeEfiGuard that writes files in the ESP… bootmgfw.efi is renamed… embedded\bootmgfw.efi is written… embedded\EfiGuardDxe.efi is written…” | “We will focus on… a Unified Extensible Firmware Interface (UEFI) bootkit. This bootkit can intervene and control the OS boot process… create a stealthy persistence…”
“Another function… assigned newly allocated heap memory and then set with PAGE_EXECUTE_READWRITE… this heap memory is filled with some data… Further unpacking… allocating another RWX memory and jumping to it…”
After talking to a victim to clarify the infection method and origin of the malware I received a link to this pirated Version of Adobe Illustrator... A quick check confirmed my suspicion that every download on this site is "spiked" with malware.
“Another function… assigned newly allocated heap memory and then set with PAGE_EXECUTE_READWRITE… this heap memory is filled with some data… Further unpacking… allocating another RWX memory and jumping to it…”
"...it has increasingly become a target for advanced threats, including bootkits documented in real systems..." and "...detects multiple real-world UEFI bootkits, including Glupteba, BlackLotus, LoJax, and MosaicRegressor."
“The installer has a function main_writeEfiGuard that writes files in the ESP… bootmgfw.efi is renamed… embedded\bootmgfw.efi is written… embedded\EfiGuardDxe.efi is written…” | “We will focus on… a Unified Extensible Firmware Interface (UEFI) bootkit. This bootkit can intervene and control the OS boot process… create a stealthy persistence…”
This story includes detections for changes to 'ChannelAccess' and 'CustomSD' registry values, as well as the use of tools like 'sc.exe sdset', 'icacls' and 'subinacl' to modify securable objects (files, registry, services, etc) permissions.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet noted for using the Bitcoin blockchain OP_RETURN field to store encrypted backup C2 domains, enabling resilient command-and-control recovery after disruption.
Botnet noted for using the Bitcoin blockchain as a fallback/backup C2 channel to obtain the actual C2 server address, improving resilience against disruption.
Named as an example of a real-world UEFI-bootkit-detectable threat in the referenced Peacock framework evaluation; no further behavior described in this content.
Backdoor malware delivered through the same malicious cracked-software installer ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.