TF-MAL-elf.bcmpupnp_hunter
📛 Threat Title
Malware family: BCMPUPnP_Hunter
Description
ThreatFox malware family `elf.bcmpupnp_hunter`. Printable name: BCMPUPnP_Hunter.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the BCMPUPnP_Hunter malware family including references, samples and yara signatures.
-
web:media.defense.gov
BlackLotus is a recently publicized malware product garnering significant attention within tech media. Similar to 2020's BootHole (CVE-2020-10713), BlackLotus takes advantage of a boot loader flaw—specifically CVE-2022-21894 Secure Boot bypass known as "Baton Drop"—to take control of an endpoint from the earliest phase of software boot. Microsoft® issued patches for supported ...
-
web:notepad-plus-plus.org
All remediation and security hardening was completed by the provider by December 2, 2025, successfully blocking further attacker activity. Note on timelines: The security expert's analysis indicates the attack ceased on November 10, 2025, while the hosting provider's statement shows potential attacker access until December 2, 2025.
-
web:www.bleepingcomputer.com
The U.S. National Security Agency (NSA) released today guidance on how to defend against BlackLotus UEFI bootkit malware attacks.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.crowdstrike.com
Remediate faster Execute built-in commands or custom scripts to easily carry out complex remediation actions on any managed endpoint remotely. Connect to and quickly isolate the impacted endpoint, then remove malicious files to immediately shut down the attack.
-
web:www.microsoft.com
A guide to assess whether users have been targeted or compromised by threat actors exploiting CVE-2022-21894 via BlackLotus UEFI bootkit.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.securityweek.com
The newly discovered " BCMPUPnP_Hunter " botnet appears to have been designed to send spam emails and has likely infected around 400,000 machines to date.
-
web:www.zyxel.com
Zyxel security advisory for BCMUPnP_Hunter botnet Summary Zyxel has patched the vulnerability for years and urges users to install the latest firmware for your Zyxel devices for optimal protection. What's the vulnerability? According to a disclosure by Qihoo's Netlab 360 in November, an IoT botnet called "BCMUPnP_Hunter" was targeting routers running vulnerable versions of the Broadcom ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.