TF-MAL-elf.bootkitty
📛 Threat Title
Malware family: Bootkitty
Description
ThreatFox malware family `elf.bootkitty`. Printable name: Bootkitty.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.bootkitty
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bootkitty
IOC database
- Type
- domain
- Value
elf.bootkitty- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.bootkitty
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bootkitty
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:archive.codeblue.jp
Bootkits & Rootkits An advanced malware that hijacks a boot process Takes control of the system before the operating system launches
-
web:bazaar.abuse.ch
Malware samples associated with tag Bootkitty MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with Bootkitty . Database Entry
-
web:dl.acm.org
Bootkits and rootkits are among the most elusive and persistent forms of malware , subverting system defenses by operating at the lowest levels of system architecture. Bootkits compromise the firmware or bootloader, allowing them to manipulate the boot sequence and gain control before security mechanisms initialize. Meanwhile, rootkits embed themselves within the OS kernel, stealthily conceal ...
-
web:github.com
Indicators of Compromises (IOC) of our various investigations - eset/ malware -ioc
-
web:kevinkoo001.github.io
27 • BOOTKITTY on windows •Windows boot process structure •Attack surfaces within the Windows boot process •Bootkit implementation strategy on Windows •OS-specific mitigation techniques and bypass methods •Rootkit deployment flow What We Have Not Talked About 28 Artifacts
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Bootkitty malware family including references, samples and yara signatures.
-
web:wpsites.ucalgary.ca
Through their analysis, ESET determined that the application, titled Bootkitty , had likely been created as a proof-of-concept, and while the bootkit may not exfiltrate user information or drop malware onto infected computers, it has opened the flood gates as to the feasibility of bootkits on Linux (3).
-
web:www.researchgate.net
Abstract—This paper presents a comprehensive analysis of BootKitty , a sophisticated proof-of-concept bootkit and rootkit that exemplifies the evolving landscape of firmware-level threats in ...
-
web:www.usenix.org
In this paper, we introduce BOOTKITTY , a hybrid bootkit-rootkit capable of circumventing modern security features in multiple OS platforms, across Windows, Linux, and Android. We explore critical firmware and bootloader vulnerabilities that can lead to a low-level compromise, demonstrating tech-niques that bypass advanced security protections by breaking the chain of trust. Our study addresses ...
-
web:www.welivesecurity.com
ESET's discovery of the first UEFI bootkit designed for Linux sendss an important message: UEFI bootkits are no longer confined to Windows systems alone.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.