ESPECTER-BOOTKIT

ESPECTER-BOOTKITESPecter bootkit

Description

ESET researchers have analyzed a previously undocumented, real-world UEFI bootkit that persists on the EFI System Partition (ESP). The bootkit, which we’ve named ESPecter, can bypass Windows Driver Signature Enforcement to load its own unsigned driver, which facilitates its espionage activities. Alongside Kaspersky’s recent discovery of the unrelated FinSpy bootkit, it is now safe to say that real-world UEFI threats are no longer limited to SPI flash implants, as used by Lojax.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
ExpBoot
Software
LoJax
Sub-technique
Bootkit
Software
EiTest
CVE
CVE-2026-45656
Software
Felipe
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.