ESET researchers analyze first UEFI bootkit for Linux systemsHelp Net Security·Nov 27, 00:00 UTC · Nov 27, 2024Exploit / PoC57
Source code of the BlackLotus UEFI Bootkit was leaked on GitHubSecurity Affairs·Jul 14, 21:31 UTC · Jul 14, 2023VulnerabilityCVE-2022-21894147
Security researchers find another UEFI bootkit used for cyberThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Vulnerability42
Researchers developed a new powerful BIOS bootkitSecurity Affairs·Mar 20, 12:08 UTC · Mar 20, 2015Vulnerability42
Researchers Discover "Bootkitty" – First UEFI Bootkit Targeting Linux KernelsThe Hacker News·Dec 2, 16:30 UTC · Dec 2, 2024RansomwareCVE-2023-4023860
Diplomats Attacked with Firmware BootkitInfosecurity Magazine·Oct 5, 19:11 UTC · Oct 5, 2020Malware in the wild57
New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024The Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Ransomware57
BlackLotus Malware Hijacks Windows Secure Boot ProcessSchneier on Security·Mar 15, 00:00 UTC · Mar 15, 2023Malware in the wildCVE-2022-2189460
New FinSpy Malware Variant Infects Windows Systems With UEFI BootkitThe Hacker News·Sep 29, 18:08 UTC · Sep 29, 2021Malware42
Glupteba Botnet Evades Detection with Undocumented UEFI BootkitThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Malware42
Researchers Discover UEFI Bootkit Targeting Windows Computers Since 2012The Hacker News·Oct 6, 06:33 UTC · Oct 6, 2021Vulnerability142
TrickBot Malware Gets UEFI/BIOS Bootkit Feature to Remain UndetectedThe Hacker News·Dec 3, 12:13 UTC · Dec 3, 2020Malware42
MosaicRegressor: Lurking in the Shadows of UEFIKaspersky Securelist·Oct 5, 10:00 UTC · Oct 5, 2020Vulnerability42
China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit HintsSecurity Affairs·Jun 17, 08:10 UTC · Jun 17, 2026VulnerabilityCVE-2023-2493247
HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetyaSecurity Affairs·Sep 13, 12:06 UTC · Sep 13, 2025Ransomware57
MoonBounce: the dark side of UEFI firmwareKaspersky Securelist·Jan 20, 10:00 UTC · Jan 20, 2022Malware42
Microsoft’s Secure Boot has been broken for a decade and no one noticed until nowArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2015-5381160
MBRFilter — Open Source Tool to Protect Against 'Master Boot Record' MalwareThe Hacker News·Oct 20, 16:33 UTC · Oct 20, 2016Malware42
Kaspersky Security Bulletin 2008: Malware Evolution JanuaryKaspersky Securelist·Sep 24, 10:00 UTC · Sep 24, 2008Malware42
200,000 Linux systems from Framework are shipped with signed UEFI components vulnerable to Secure Boot bypassSecurity Affairs·Oct 15, 14:22 UTC · Oct 15, 2025RansomwareCVE-2022-34302CVE-2023-48733CVE-2024-734460
HybridPetya Mimics NotPetya, Adds UEFI CompromiseInfosecurity Magazine·Sep 15, 16:45 UTC · Sep 15, 2025RansomwareCVE-2024-734460
MoonBounce UEFI implant spotted in a targeted APT41 attackSecurity Affairs·Jan 21, 11:59 UTC · Jan 21, 2022Threat actor57
TrickBoot feature allows TrickBot bot to run UEFI attacksSecurity Affairs·Dec 3, 14:32 UTC · Dec 3, 2020Ransomware in the wild60
Bug in widely used bootloader opens Windows, Linux devices to persistent compromiseHelp Net Security·Aug 3, 11:37 UTC · Aug 3, 2020MalwareCVE-2020-1071347
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure BootThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026VulnerabilityCVE-2026-8863CVE-2026-1079747
China-Linked SprySOCKS Backdoor Expands to Windows with DriverThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026MalwareCVE-2023-2493247
HybridPetya: (Proof-of-concept?) ransomware can bypass UEFI Secure BootHelp Net Security·Sep 12, 00:00 UTC · Sep 12, 2025RansomwareCVE-2024-734460
Microsoft Warns of StilachiRAT: A Stealthy RAT Targeting Credentials and Crypto WalletsThe Hacker News·Mar 18, 07:00 UTC · Mar 18, 2025Malware42
Sneaky malware BlackLotus can bypass important Windows boot functionsThe Record·Mar 10, 14:17 UTC · Mar 10, 2023Malware in the wild57
End of 2021 witnessed an explosion of RDP brute-force attacksHelp Net Security·Feb 9, 00:00 UTC · Feb 9, 2022VulnerabilityCVE-2017-1188247
SprySOCKS Backdoor Expands From Linux to WindowsInfosecurity Magazine·Jun 16, 14:30 UTC · Jun 16, 2026Malware42