s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.bootkitty

📛 Threat Title

Malware family: Bootkitty

Category: Bootkitty First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.bootkitty`. Printable name: Bootkitty.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.bootkitty VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bootkitty

IOC database

Type
domain
Value
elf.bootkitty
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.bootkitty

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bootkitty

References (1)

Remediations (10)

  • web:archive.codeblue.jp

    Bootkits & Rootkits An advanced malware that hijacks a boot process Takes control of the system before the operating system launches

  • web:bazaar.abuse.ch

    Malware samples associated with tag Bootkitty MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with Bootkitty . Database Entry

  • web:dl.acm.org

    Bootkits and rootkits are among the most elusive and persistent forms of malware , subverting system defenses by operating at the lowest levels of system architecture. Bootkits compromise the firmware or bootloader, allowing them to manipulate the boot sequence and gain control before security mechanisms initialize. Meanwhile, rootkits embed themselves within the OS kernel, stealthily conceal ...

  • web:github.com

    Indicators of Compromises (IOC) of our various investigations - eset/ malware -ioc

  • web:kevinkoo001.github.io

    27 • BOOTKITTY on windows •Windows boot process structure •Attack surfaces within the Windows boot process •Bootkit implementation strategy on Windows •OS-specific mitigation techniques and bypass methods •Rootkit deployment flow What We Have Not Talked About 28 Artifacts

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Bootkitty malware family including references, samples and yara signatures.

  • web:wpsites.ucalgary.ca

    Through their analysis, ESET determined that the application, titled Bootkitty , had likely been created as a proof-of-concept, and while the bootkit may not exfiltrate user information or drop malware onto infected computers, it has opened the flood gates as to the feasibility of bootkits on Linux (3).

  • web:www.researchgate.net

    Abstract—This paper presents a comprehensive analysis of BootKitty , a sophisticated proof-of-concept bootkit and rootkit that exemplifies the evolving landscape of firmware-level threats in ...

  • web:www.usenix.org

    In this paper, we introduce BOOTKITTY , a hybrid bootkit-rootkit capable of circumventing modern security features in multiple OS platforms, across Windows, Linux, and Android. We explore critical firmware and bootloader vulnerabilities that can lead to a low-level compromise, demonstrating tech-niques that bypass advanced security protections by breaking the chain of trust. Our study addresses ...

  • web:www.welivesecurity.com

    ESET's discovery of the first UEFI bootkit designed for Linux sendss an important message: UEFI bootkits are no longer confined to Windows systems alone.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.