MoonBounce: the dark side of UEFI firmwareKaspersky Securelist·Jan 20, 10:00 UTC · Jan 20, 2022Malware42
BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11The Hacker News·Jun 23, 08:42 UTC · Jun 23, 2023Malware in the wildCVE-2022-21894160
BlackLotus Malware Hijacks Windows Secure Boot ProcessSchneier on Security·Mar 15, 00:00 UTC · Mar 15, 2023Malware in the wildCVE-2022-2189460
Hacking Team Spyware uses a UEFI BIOS RootkitSecurity Affairs·Oct 5, 20:22 UTC · Oct 5, 2020Malware55
Russian Sednit APT used the first UEFI rootkit in attacks in the wildSecurity Affairs·Sep 27, 12:25 UTC · Sep 27, 2018Malware in the wild157
CosmicStrand: the discovery of a sophisticated UEFI firmware rootkitKaspersky Securelist·Jul 25, 10:00 UTC · Jul 25, 2022Malware42
Experts observed FinFisher infections involving usage of a UEFI bootkitSecurity Affairs·Sep 29, 05:20 UTC · Sep 29, 2021Malware30
New 'MosaicRegressor' UEFI Bootkit Malware Found Active in the WildThe Hacker News·Oct 6, 08:33 UTC · Oct 6, 2020Malware30
NSA publishes Guidance on UEFI Secure Boot customizationSecurity Affairs·Sep 16, 21:13 UTC · Sep 16, 2020Malware30
Chinese Hackers Spotted Using New UEFI Firmware Implant in Targeted AttacksThe Hacker News·Jan 24, 06:26 UTC · Jan 24, 2022Malware42
New FinSpy Malware Variant Infects Windows Systems With UEFI BootkitThe Hacker News·Sep 29, 18:08 UTC · Sep 29, 2021Malware42
LoJax: First-ever UEFI rootkit detected in a cyberattackHelp Net Security·Sep 27, 00:00 UTC · Sep 27, 2018Malware in the wild57
Researchers Uncover UEFI Secure Boot Bypass in 3 Microsoft Signed Boot LoadersThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2022MalwareCVE-2022-34301CVE-2022-3430247
Stealthy firmware bootkit leveraged by APT in targeted attacksHelp Net Security·Jan 21, 00:00 UTC · Jan 21, 2022Malware55
Experts Uncover New 'CosmicStrand' UEFI Firmware Rootkit Used by Chinese HackersThe Hacker News·Aug 7, 04:15 UTC · Aug 7, 2022Malware42
CosmicStrand, a sophisticated UEFI firmware rootkit linked to ChinaSecurity Affairs·Jul 31, 09:07 UTC · Jul 31, 2022Malware30
Glupteba Botnet Evades Detection with Undocumented UEFI BootkitThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Malware42
New UEFI rootkit Black Lotus offered for sale at $5,000Security Affairs·Oct 17, 15:01 UTC · Oct 17, 2022Malware42
Code found online exploits LogoFAIL to install Bootkitty Linux backdoorArs Technica · Security·Nov 29, 21:37 UTC · Nov 29, 2024Malware42
TrickBot Malware Gets UEFI/BIOS Bootkit Feature to Remain UndetectedThe Hacker News·Dec 3, 12:13 UTC · Dec 3, 2020Malware42
Critical GRUB2 Bootloader Bug Affects Billions of Linux and Windows SystemsThe Hacker News·Jul 29, 19:50 UTC · Jul 29, 2020MalwareCVE-2020-1071360
Diplomats Attacked with Firmware BootkitInfosecurity Magazine·Oct 5, 19:11 UTC · Oct 5, 2020Malware in the wild57
IGEL OS Workspace Edition version 11.03 offers advanced security features and signed OS partitionsHelp Net Security·Dec 13, 00:00 UTC · Dec 13, 2019Malware55
Russians' stealthy 'LoJax' malware can infect on the firmware levelCyberScoop·Sep 28, 13:48 UTC · Sep 28, 2018Malware in the wild60
Tails OS version 4.5 supports the Secure Boot .........Security Affairs·Apr 10, 07:52 UTC · Apr 10, 2020Malware30
IGEL integrates the AMD Secure Processor on IGEL UD7 endpointsHelp Net Security·Dec 5, 00:00 UTC · Dec 5, 2019Malware30
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News·Jun 29, 14:42 UTC · Jun 29, 2026Malware in the wildCVE-2026-43503CVE-2026-12569CVE-2026-47729+19 CVEs60
Bug in widely used bootloader opens Windows, Linux devices to persistent compromiseHelp Net Security·Aug 3, 11:37 UTC · Aug 3, 2020MalwareCVE-2020-1071347
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, ZeroThe Hacker News·Oct 14, 10:56 UTC · Oct 14, 2025Malware in the wildCVE-2025-2104360
GRUB2 boot loader maintainers fixed hundreds of flawsSecurity Affairs·Mar 4, 10:20 UTC · Mar 4, 2021MalwareCVE-2020-10713CVE-2020-14372CVE-2020-25632+7 CVEs35
BootHole issue allows installing a stealthy and persistent malwareSecurity Affairs·Jul 30, 05:49 UTC · Jul 30, 2020MalwareCVE-2020-1071335
Intel's CHIPSEC can detect CIA's OS X rootkitHelp Net Security·Jun 26, 21:23 UTC · Jun 26, 2018Malware30
China-Linked SprySOCKS Backdoor Expands to Windows with DriverThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026MalwareCVE-2023-2493247
Secure Boot-neutering PKfail debacle is more prevalent than anyone knewArs Technica · Security·Sep 15, 00:00 UTC · Sep 15, 2024Malware42