Summary:
A recent campaign has unveiled a new facet of Glupteba, a longstanding and adaptable malware with origins dating back over a decade. This iteration of Glupteba introduces an undocumented Unified Extensible Firmware Interface (UEFI) bootkit, showcasing the malware's continuous evolution and sophistication. This bootkit infiltrates the system's boot process, providing Glupteba with stealthy persistence and heightened resilience against detection and removal efforts.[/subscribe_to_unlock_form]
Summary:
A recent campaign has unveiled a new facet of Glupteba, a longstanding and adaptable malware with origins dating back over a decade. This iteration of Glupteba introduces an undocumented Unified Extensible Firmware Interface (UEFI) bootkit, showcasing the malware's continuous evolution and sophistication. This bootkit infiltrates the system's boot process, providing Glupteba with stealthy persistence and heightened resilience against detection and removal efforts.[emaillocker id="1283"]
Glupteba, known for its modular design and multipurpose functionality, has evolved to incorporate various capabilities over the years. The recent campaign reveals its utilization of a Pay-per-install (PPI) ecosystem, demonstrating its adaptability to different distribution methods. However, the most significant revelation lies in the discovery of its UEFI bootkit, which intervenes in the OS boot process, enabling Glupteba to conceal itself effectively. Through a detailed analysis of the malware's installation process and code, it becomes evident that Glupteba leverages an open-source UEFI bootkit called EfiGuard. This bootkit allows Glupteba to disable security mechanisms like PatchGuard and driver signature enforcement (DSE), thereby granting it deeper access and control over the infected system. Additionally, Glupteba's authors have implemented multiple DSE bypass methods, including DSEFix, Universal PatchGuard and Driver Signature Enforcement Disable (UPGDSED), and now EfiGuard, showcasing their commitment to maintaining effectiveness in the face of evolving security measures.
The discovery of the undocumented UEFI bootkit within Glupteba highlights the malware's continuous evolution and adaptability to evade detection mechanisms. This novel technique underscores the need for cybersecurity professionals to remain vigilant and continuously enhance their defenses against emerging threats. Moreover, the integration of Glupteba into the pay-per-install (PPI) ecosystem emphasizes the collaborative and monetization strategies employed by cybercriminals. As such, a comprehensive cybersecurity strategy, including advanced threat prevention measures and multilayered security solutions, is imperative to mitigate the risks posed by Glupteba and similar advanced malware threats.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2024/02/glupteba-botnet-evades-detection-with.html
[/emaillocker]