PULSE NAME
Diving Into Glupteba's UEFI Bootkit
WHITE Glupteba AlienVault 2024-02-13 Modified: 2024-02-13
52
IOCs
HIGH VOLUME
This article describes the infection chain of a new Glupteba malware campaign that took place around November 2023. The analysis reveals Glupteba's use of an undocumented UEFI bootkit that can intervene and control the OS boot process, enabling Glupteba to hide itself and create stealthy persistence. The identification of this novel UEFI bypass technique underscores Glupteba's capacity for innovation and evasion, posing a significant detection challenge.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Glupteba PrivateLoader SmokeLoader
Indicators of Compromise (4 / 52 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 11963758b724ef55789b5a4e2407d4afbb43ee90 2024-02-13
FileHash-SHA1 65a84da42ff2c18fc72beff5b8e1fc3c0f09e17b 2024-02-13
FileHash-SHA1 a711d7874c8d3727ce2c7381a0b7c666b6c3b8f6 2024-02-13
FileHash-SHA1 d8dc6f85b5a0cffbcb20240988e29f3eb4504abc 2024-02-13