Netskope Threat Labs

Bootkitty

ATP Sandbox Adv. Heuristics

Bootkitty is a UEFI bootkit that researchers documented targeting Linux systems in late 2024, the first of its kind for that platform. It patches the boot process to disable kernel signature verification and load malicious modules, and its proof of concept quality suggests a testing stage rather than widespread operation.

First seen
November 2024
Last seen
October 2026
BootKitty
Alert Name
Win64.Trojan.Bootkitty
Win64.Trojan.BootKitty