Cybersecurity researchers from ESET identified the first-ever UEFI bootkit for Linux systems, known as Bootkitty. The bootkit targets the system’s signature verification feature, disabling it and preloading two unknown ELF binaries. Researchers suggest that Bootkitty is still a proof of concept, given various artifacts found in the binary. Even though the bootkit does not pose an immediate threat, the discovery serves as a reminder to ensure UEFI Secure Boot is enabled and system firmware and OS are updated.
Rapid7 Labs Identifies Malware Installer Targeting Chinese and Vietnamese Users
Rapid7 Labs has discovered a highly evasive malware installer called CleverSoar, which targets Chinese and Vietnamese-speaking users by deploying and protecting several malicious elements including