Bootkitty is a Linux-targeting UEFI bootkit and the first publicly described UEFI bootkit built for Linux, with observed focus on several Ubuntu versions. It operates in the pre-OS boot chain, where it can replace the boot loader, patch the Linux kernel before execution, disable kernel signature verification, and modify integrity-checking routines in memory. It is also designed to preload additional ELF payloads during startup, giving an attacker control before the operating system fully initializes.
Bootkitty has been assessed as a proof of concept rather than a mature in-the-wild threat. Researchers reported development artifacts, limited platform compatibility, and no confirmed real-world deployment at the time of analysis. The known sample was self-signed, which means it cannot execute on systems where UEFI Secure Boot is properly enforced through trusted signing and current revocation controls.
The malware is associated with UEFI-level persistence and early-boot compromise rather than conventional user-space infection. Reporting also links Bootkitty conceptually to Secure Boot bypass chains involving vulnerable or outdated trusted boot components, including exploitation paths based on LogoFAIL and legacy Microsoft-signed shim abuse, both of which can enable deployment of UEFI bootkits on systems that would otherwise trust only signed boot code. In that context, Bootkitty illustrates the expansion of bootkit tradecraft beyond Windows into Linux environments.
A potentially related component known as BCDropper has been described as an unsigned kernel module that deploys an ELF program used to load another kernel module, suggesting a broader experimental toolset around the same development effort. Bootkitty has also been tracked under the name IranuKit in some reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Bootkitty, exploited LogoFAIL (CVE-2023-40238) ... Vulnerability Target ... LogoFAIL (CVE-2023-40238) UEFI | Bootkitty, exploited LogoFAIL (CVE-2023-40238) ... Bootkitty 2024 2024 ESP Linux N/A
Two CVE IDs, CVE-2026-8863 and CVE-2026-10797, cover the reported shims, and Microsoft revoked the vulnerable binaries in the dbx update shipped with its June 9 Patch Tuesday.
Two CVE IDs, CVE-2026-8863 and CVE-2026-10797, cover the reported shims, and Microsoft revoked the vulnerable binaries in the dbx update shipped with its June 9 Patch Tuesday.
Через такой вектор можно развернуть полноценные UEFI-буткиты - BlackLotus или Bootkitty - даже при включённом Secure Boot. | CVE-2024-7344, обнаруженная исследователем ESET Martin Smolár, затрагивает UEFI-приложение Reloader - компонент нескольких утилит восстановления: Howyar SysReturn, Greenware GreenGuard, Radix SmartRecovery, Sanfong EZ-back System, CES NeoImpact. По данным ESET, также затронуты WASAY eRecoveryRX и SignalComputer HDD King.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Attackers could bypass UEFI Secure Boot on a wide range of systems thanks to 11 Microsoft-signed UEFI shim bootloaders carrying vulnerabilities that have remained buried for more than a decade... Exploitation allows untrusted code to run during boot, opening the door to UEFI bootkits ... even with Secure Boot switched on.
Bootkits usually targeted MBR/ESP in the early 2010s, but as the cost of firmware attack decreased rapidly, the modern bootkits started to target DXE or even PEI.
It’ll then try to preload two unknown executables during the system startup process.
This rogue MokList enables the bootkit to be trusted by the system’s Secure Boot components, allowing it to load during the early boot process.
The bootkit’s main goal is to disable the kernel’s signature verification feature... Another way to tell whether the bootkit is present on the system with UEFI Secure Boot enabled is by attempting to load an unsigned dummy kernel module during runtime. If it’s present, the module will be loaded.
If security protections are set properly, malicious firmware might achieve the persistent by utilizing exploits (e.g. CVE-2014-8273).
The bootkit is an advanced rootkit that is capable of replacing the boot loader and of patching the kernel ahead of its execution.
the shellcode restores the original instructions, hiding the exploit activity and effectively clearing all traces of the bootkit.
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Attackers could bypass UEFI Secure Boot on a wide range of systems thanks to 11 Microsoft-signed UEFI shim bootloaders carrying vulnerabilities that have remained buried for more than a decade... Exploitation allows untrusted code to run during boot, opening the door to UEFI bootkits ... even with Secure Boot switched on.
The exploit uses embedded shellcode within a BMP image to bypass Secure Boot protections by injecting rogue certificates into the MokList variable.
По MITRE ATT&CK это одновременно Bootkit (T1542.003) для persistence и Code Signing Policy Modification (T1553.006) для defense evasion - Secure Boot формально включён, но фактически удалось его обойти.
The bootkit’s main goal is to disable the kernel’s signature verification feature... Another way to tell whether the bootkit is present on the system with UEFI Secure Boot enabled is by attempting to load an unsigned dummy kernel module during runtime. If it’s present, the module will be loaded.
The bootkit’s main goal is to disable the kernel’s signature verification feature... Another way to tell whether the bootkit is present on the system with UEFI Secure Boot enabled is by attempting to load an unsigned dummy kernel module during runtime. If it’s present, the module will be loaded.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named UEFI bootkit cited as malware that could be enabled by Secure Boot bypass via vulnerable Microsoft-signed shim bootloaders.
A malicious UEFI bootkit that could be deployed after bypassing Secure Boot via vulnerable Microsoft-signed shim bootloaders.
A malicious UEFI bootkit cited as an example of malware that could be deployed after bypassing UEFI Secure Boot.
A named UEFI bootkit cited as malware that could be deployed after abusing vulnerable Microsoft-signed shim bootloaders to bypass Secure Boot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.