The Glupteba botnet was found to embed a previously undocumented UEFI bootkit functionality into computing hardware, adding another layer of sophisticated technology and stealth to the malware.
See also: Increased botnet activity in the last month

The Glupteba botnet is a fully functional information-stealing malware that acts as a backdoor, capable of facilitating illegal cryptocurrency mining and installing additional middlemen on infected computers . It is also known to exploit Bitcoin blockchain technology as a backup command and control (C2) system, making it resistant to deterrence efforts.
Some of its other functions allow it to deliver additional payloads, steal credentials and credit card information, commit ad fraud, and even exploit routers to gain access to credentials and remote management.
Over the past ten years, modular malware has transformed into a sophisticated threat that uses complex, multi-stage infection chains to evade detection by security solutions.
A November 2023 campaign was observed by the cybersecurity firm and involves the use of pay-per-install (PPI) services such as Ruzki to distribute Glupteba. In September 2022, Sekoia linked Ruzki to activity groups, exploiting PrivateLoader as a distribution channel for the malware.
See also: KV-Botnet operators try to make a comeback after FBI actions
This takes the form of identity theft, where PrivateLoader is delivered under the guise of installation files for cracked software, which then loads SmokeLoader which, in turn, runs RedLine Stealer and Amadey, the latter ultimately depositing the Glupteba botnet.

In a sign that the malware is still active, the Glupteba botnet is equipped with a UEFI bootkit, incorporating a modified version of an open source program called EfiGuard, which is capable of disabling PatchGuard and Driver Signature Enforcement (DSE) at boot time.
It is worth mentioning that in previous versions of the malware, it was discovered that it “installs a driver kernel that is used by the bot as a rootkit and makes other changes that weaken the security of an infected computer.”
See also: Bigpanzi hackers: Their botnet targets Android TV boxes
What is the function of a botnet?
A botnet is a network of private computers that have been infected with malware and are controlled by a central administrator, known as a botmaster. Botnets are used for a variety of malicious activities, such as sending spam, performing distributed denial-of-service (DDoS) attacks, stealing personal information, and distributing malware.
A botnet can have hundreds or even millions of members, and computers may be completely unaware that they are part of it. Botmasters often exploit vulnerabilities in operating systems and software to infect computers and add them to their botnet. Detecting and removing a botnet can be very difficult, as botmasters often use complex techniques to hide their presence.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
