ESPecter is a real-world Windows bootkit that evolved from earlier legacy BIOS infections into a UEFI-capable threat focused on long-term persistence and espionage. Its roots date back to at least 2012, with early variants persisting by modifying the Master Boot Record on BIOS systems. Later variants persist from the EFI System Partition by patching the Windows Boot Manager and related fallback boot components, allowing malicious code to execute before the operating system fully loads. This early execution position enables the malware to tamper with the boot chain and kernel initialization while remaining difficult to detect and remove with conventional operating-system-level tooling.
A defining feature of ESPecter is its ability to bypass Windows Driver Signature Enforcement by patching boot and kernel code in memory during startup. It modifies boot-manager logic to force integrity checks to succeed, then alters kernel code-integrity initialization so an unsigned kernel driver can be loaded. That driver provides the foundation for follow-on activity, including user-mode payload deployment and surveillance functions. Reported behavior includes injecting user-mode components into system processes, establishing command-and-control communications, executing downloaded payloads, collecting system information, taking screenshots, stealing documents, and operating a keylogger.
ESPecter has been assessed primarily as an espionage platform rather than a disruptive or destructive one. Observed components support persistent monitoring and staged data theft, with separate user-mode modules handling command execution, filesystem interaction, process and service control, screenshot capture, configuration updates, and exfiltration. The kernel component also supports keystroke interception, enabling credential and sensitive-information collection.
The malware targets Windows systems and has been reported across multiple Windows versions from Windows 7 through Windows 10. Its UEFI persistence method requires Secure Boot to be disabled or otherwise bypassed, although the exact mechanism used by operators to achieve that state on victim systems has not been conclusively established. Possible paths discussed in public reporting include preexisting insecure configuration, physical access, or exploitation of firmware weaknesses. Attribution to a specific threat actor remains unconfirmed; public analysis has noted only low-confidence indications suggesting a Chinese-speaking operator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
39 distinct techniques documented for this family, organized by ATT&CK tactic.
“DefaultConfig value in HKLM\SYSTEM\CurrentControlSet\Control registry… can be used… to store configuration.”
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Secure Boot is designed to thwart UEFI bootkits, a form of malware that alters the Unified Extensible Firmware Interface, the successor to the BIOS, both of which begin the initial boot sequence. Because these bootkits load before the OS and most other code, they can be difficult to detect.
Typical targets are like kernel structures, device drivers, MBR or boot sectors, which they do with techniques SSDT hooking, DKOM, file hiding, process hiding, and rootkit loaders in kernel space.
“WinSys.dll is an MPRESS-packed DLL embedded in the driver’s binary in an encrypted form.”
“installers… copy cmd.exe to con1866.exe to evade detection.”
“Execution of both WinSys.dll and Client.dll libraries is achieved by injecting them into svchost.exe and winlogon.exe… NotifyRoutine hooks the entry point… responsible for loading and executing the appropriate payload DLL.”
“ESPecter uses single-byte XOR with subtraction to decrypt user-mode payloads… configuration… one-byte XOR key… Base64 decodes… XORs…”
В процессе своей работы ESPecter патчит менеджер загрузки, чтобы заменить легитимный драйвер (либо beep.sys, либо winsys.dll) на вредоносный.
“can be configured to postpone C&C communication after execution or to communicate… only in a specified time range.”
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Secure Boot is designed to thwart UEFI bootkits, a form of malware that alters the Unified Extensible Firmware Interface, the successor to the BIOS, both of which begin the initial boot sequence. Because these bootkits load before the OS and most other code, they can be difficult to detect.
Bootkits usually targeted MBR/ESP in the early 2010s, but as the cost of firmware attack decreased rapidly, the modern bootkits started to target DXE or even PEI.
“DefaultConfig value in HKLM\SYSTEM\CurrentControlSet\Control registry… can be used… to store configuration.”
FinSpy ... патчит код, ответственный за проверку цифровых подписей ... ESPecter отключает проверку цифровой подписи драйверов, чтобы загрузить в систему подменный beep.sys или winsys.dll.
“reports foreground window names along with keylogger information to provide application context.”
“check for installed software under… HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall.”
“Client.dll component can list running processes and their loaded modules.”
“Upload various system info (CPU name, OS version, memory size, ethernet MAC address, list of installed software, etc.).”
“Client.dll component can list file information for specific directories.”
“can collect files with specified extension from removable drives.”
“Interception of keystrokes is done by setting up CompletionRoutine for IRP_MJ_READ requests for the keyboard driver object \Device\KeyboardClass0… Client… register its logging function by sending IOCTL 0x22C004.”
“WinSys.dll communicates with its C&C using HTTPS… https://<ip>/Heart.aspx?…”
“For communication with the C&C, it uses the TCP protocol…”
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bootkit/tool cité comme source d’inspiration pour RedLotus.
A named UEFI bootkit identified as part of newer bootkit discoveries.
A UEFI firmware bootkit mentioned as an in-the-wild example of stealthy malware operating beneath the operating system.
A real UEFI bootkit discovered in the wild in 2021, cited as part of the progression of publicly known UEFI bootkits targeting Windows systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.