You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
🏴☠️ Designing and Implementing UEFI Bootkits to Hijack the Boot Process and Subvert Kernel Integrity on Windows and Linux
Most public resources on UEFI bootkit development are incomplete, inaccurate, or written by people who have never shipped working code. BlackLotus gets reverse engineered but never truly explained. Bootkitty gets celebrated but never properly dissected at the implementation level. The ecosystem around UEFI malware development is full of high-level overviews, recycled slide decks, and blog posts that stop right before the part that actually matters.
This paper exists because we got tired of it. We built Abyss and Antarctic from scratch, two complete, functional UEFI bootkits targeting Windows and Linux respectively, and we documented the process at every layer. Boot flow hijacking. EFI application hooking. Secure Boot bypass strategies. Kernel integrity subversion. The full chain from firmware execution to post-boot persistence, done correctly.
If you have read everything else and still do not understand how any of this actually works, this is where you start.
A comprehensive open-source book dedicated to the research, design, and development of modern bootkits and kernel rootkits. Initially focused on Windows and the research publicly presented at DEF CON 33, the project documents every stage of the boot compromise chain, from UEFI firmware internals, boot managers, and kernel loading, to pre-OS persistence, kernel patching, and post-exploitation techniques. The book combines architectural explanations, reverse engineering, implementation details, proof-of-concepts, debugging methodologies, and practical code examples to provide a complete understanding of offensive development beneath the operating system.
Chronological reference of significant bootkit and rootkit families, from early MBR-era malware through modern UEFI threats, with technical annotations on their relevance to current development.
Minimal working PoCs and scaffolding for getting started with kernel rootkit development on both Windows and Linux.
🤝 Research & Collaboration
Working on something similar? Researching UEFI, Kernel security, exploitation, or another interesting security topic? If you need a hand developing an exploit, exploring a technique, or just want to exchange ideas, don't hesitate to reach out. I'm always open to discussing research, helping where I can, and collaborating on interesting projects. Feel free to contact me on LinkedIn.
About
Designing and implementing UEFI bootkits capable of hijacking the boot process and subverting kernel integrity on Windows and Linux.