s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.bcmpupnp_hunter

📛 Threat Title

Malware family: BCMPUPnP_Hunter

Category: BCMPUPnP_Hunter First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.bcmpupnp_hunter`. Printable name: BCMPUPnP_Hunter.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the BCMPUPnP_Hunter malware family including references, samples and yara signatures.

  • web:media.defense.gov

    BlackLotus is a recently publicized malware product garnering significant attention within tech media. Similar to 2020's BootHole (CVE-2020-10713), BlackLotus takes advantage of a boot loader flaw—specifically CVE-2022-21894 Secure Boot bypass known as "Baton Drop"—to take control of an endpoint from the earliest phase of software boot. Microsoft® issued patches for supported ...

  • web:notepad-plus-plus.org

    All remediation and security hardening was completed by the provider by December 2, 2025, successfully blocking further attacker activity. Note on timelines: The security expert's analysis indicates the attack ceased on November 10, 2025, while the hosting provider's statement shows potential attacker access until December 2, 2025.

  • web:www.bleepingcomputer.com

    The U.S. National Security Agency (NSA) released today guidance on how to defend against BlackLotus UEFI bootkit malware attacks.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.crowdstrike.com

    Remediate faster Execute built-in commands or custom scripts to easily carry out complex remediation actions on any managed endpoint remotely. Connect to and quickly isolate the impacted endpoint, then remove malicious files to immediately shut down the attack.

  • web:www.microsoft.com

    A guide to assess whether users have been targeted or compromised by threat actors exploiting CVE-2022-21894 via BlackLotus UEFI bootkit.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.securityweek.com

    The newly discovered " BCMPUPnP_Hunter " botnet appears to have been designed to send spam emails and has likely infected around 400,000 machines to date.

  • web:www.zyxel.com

    Zyxel security advisory for BCMUPnP_Hunter botnet Summary Zyxel has patched the vulnerability for years and urges users to install the latest firmware for your Zyxel devices for optimal protection. What's the vulnerability? According to a disclosure by Qihoo's Netlab 360 in November, an IoT botnet called "BCMUPnP_Hunter" was targeting routers running vulnerable versions of the Broadcom ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.