BOOTKITTY: A Stealthy Bootkit-Rootkit Against Modern Operating Systems

Junho Lee, Mokpo National University; Jihoon Kwon, Korea University; HyunA Seo, Sungshin Women's University; Myeongyeol Lee, Chosun University; Hyungyu Seo, Keimyung University; Jinho Jung, Ministry of National Defense; Hyungjoon Koo, Sungkyunkwan University

Bootkits and rootkits are among the most elusive and persistent forms of malware, subverting system defenses by operating at the lowest levels of system architecture. Bootkits compromise the firmware or bootloader, allowing them to manipulate the boot sequence and gain control before security mechanisms initialize. Meanwhile, rootkits embed themselves within the OS kernel, stealthily conceal malicious activities, and maintain long-term persistence. Despite their critical implications for security, these threats remain underexplored due to the technical complexity involved in their study, the scarcity of real-world samples, and the challenges posed by defense-in-depth security in modern OSes.

In this paper, we introduce BOOTKITTY, a hybrid bootkit-rootkit capable of circumventing modern security features in multiple OS platforms, across Windows, Linux, and Android. We explore critical firmware and bootloader vulnerabilities that can lead to a low-level compromise, demonstrating techniques that bypass advanced security protections by breaking the chain of trust. Our study addresses technical challenges such as exploiting UEFI drivers, manipulating kernel memory, and evading advanced mitigations in the boot process, and provides actionable insights. Our systematic evaluations show that BOOTKITTY reveals critical weaknesses in contemporary security mechanisms, highlighting the need for better security design that offers holistic (low-level) protection.

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {309153,
author = {Junho Lee and Jihoon Kwon and HyunA Seo and Myeongyeol Lee and Hyungyu Seo and Jinho Jung and Hyungjoon Koo},
title = {{BOOTKITTY}: A Stealthy {Bootkit-Rootkit} Against Modern Operating Systems},
booktitle = {19th USENIX WOOT Conference on Offensive Technologies (WOOT 25)},
year = {2025},
isbn = {978-1-939133-50-2},
address = {Seattle, WA},
pages = {303--320},
url = {https://www.usenix.org/conference/woot25/presentation/lee},
publisher = {USENIX Association},
month = aug
}

Presentation Video