Stealthy firmware bootkit leveraged by APT in targeted attacksHelp Net Security·Jan 21, 00:00 UTC · Jan 21, 2022Malware55
BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11The Hacker News·Jun 23, 08:42 UTC · Jun 23, 2023Malware in the wildCVE-2022-21894160
Diplomats Attacked with Firmware BootkitInfosecurity Magazine·Oct 5, 19:11 UTC · Oct 5, 2020Malware in the wild57
BlackLotus Malware Hijacks Windows Secure Boot ProcessSchneier on Security·Mar 15, 00:00 UTC · Mar 15, 2023Malware in the wildCVE-2022-2189460
Kaspersky Security Bulletin: Malware evolution 2008Kaspersky Securelist·Mar 2, 16:30 UTC · Mar 2, 2009Malware30
New FinSpy Malware Variant Infects Windows Systems With UEFI BootkitThe Hacker News·Sep 29, 18:08 UTC · Sep 29, 2021Malware42
Glupteba Botnet Evades Detection with Undocumented UEFI BootkitThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Malware42
Experts observed FinFisher infections involving usage of a UEFI bootkitSecurity Affairs·Sep 29, 05:20 UTC · Sep 29, 2021Malware30
TrickBot Malware Gets UEFI/BIOS Bootkit Feature to Remain UndetectedThe Hacker News·Dec 3, 12:13 UTC · Dec 3, 2020Malware42
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, ZeroThe Hacker News·Oct 14, 10:56 UTC · Oct 14, 2025Malware in the wildCVE-2025-2104360
MoonBounce: the dark side of UEFI firmwareKaspersky Securelist·Jan 20, 10:00 UTC · Jan 20, 2022Malware42
New 'MosaicRegressor' UEFI Bootkit Malware Found Active in the WildThe Hacker News·Oct 6, 08:33 UTC · Oct 6, 2020Malware30
MBRFilter — Open Source Tool to Protect Against 'Master Boot Record' MalwareThe Hacker News·Oct 20, 16:33 UTC · Oct 20, 2016Malware42
Kaspersky Security Bulletin 2008: Malware Evolution JanuaryKaspersky Securelist·Sep 24, 10:00 UTC · Sep 24, 2008Malware42
Bug in widely used bootloader opens Windows, Linux devices to persistent compromiseHelp Net Security·Aug 3, 11:37 UTC · Aug 3, 2020MalwareCVE-2020-1071347
Kaspersky Security Bulletin 2009. Malware Evolution 2009Kaspersky Securelist·Feb 17, 17:16 UTC · Feb 17, 2010Malware30
China-Linked SprySOCKS Backdoor Expands to Windows with DriverThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026MalwareCVE-2023-2493247
Microsoft Warns of StilachiRAT: A Stealthy RAT Targeting Credentials and Crypto WalletsThe Hacker News·Mar 18, 07:00 UTC · Mar 18, 2025Malware42
Sneaky malware BlackLotus can bypass important Windows boot functionsThe Record·Mar 10, 14:17 UTC · Mar 10, 2023Malware in the wild57
SprySOCKS Backdoor Expands From Linux to WindowsInfosecurity Magazine·Jun 16, 14:30 UTC · Jun 16, 2026Malware42
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
Sprout: Open-source bootloader built for speed and securityHelp Net Security·Nov 13, 00:00 UTC · Nov 13, 2025Malware55
RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell FeaturesThe Hacker News·Mar 31, 09:11 UTC · Mar 31, 2025MalwareCVE-2025-028260
CISA warns of RESURGE malware exploiting Ivanti flawSecurity Affairs·Mar 30, 23:13 UTC · Mar 30, 2025Malware in the wildCVE-2025-0282CVE-2025-028360
Code found online exploits LogoFAIL to install Bootkitty Linux backdoorArs Technica · Security·Nov 29, 21:37 UTC · Nov 29, 2024Malware42
NSA warns of ‘false sense of security’ against BlackLotus malwareThe Record·Jun 22, 17:31 UTC · Jun 22, 2023MalwareCVE-2022-21894135
Experts Uncover New 'CosmicStrand' UEFI Firmware Rootkit Used by Chinese HackersThe Hacker News·Aug 7, 04:15 UTC · Aug 7, 2022Malware42
Chinese Hackers Spotted Using New UEFI Firmware Implant in Targeted AttacksThe Hacker News·Jan 24, 06:26 UTC · Jan 24, 2022Malware42