T1542.003: T1542.003
Essential information
- MITRE technique ID
T1542.003- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:37
- Modified
- 27/03/2026 01:08
- Author / Source
- The MITRE Corporation
Aliases
Bootkit
Platforms
windows linux
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | defense-evasion |
| mitre-attack | persistence |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (10)
-
ZeroTrace Team usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:11 · Modified 21/12/2025 15:11
-
Andariel Group usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 09:40 · Modified 21/12/2025 09:40
-
Stealit usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 17:30 · Modified 21/12/2025 17:30
-
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
The MITRE Corporation Confidence 100
[Transparent Tribe](https://attack.mitre.org/groups/G0134) is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.(Citation: Proofpoint …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
BADBOX usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 09:16 · Modified 21/12/2025 09:16
-
TeamPCP usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/03/2026 22:18 · Modified 20/03/2026 22:18
-
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 08/04/2026 13:02 -
Keenadu usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 17/02/2026 17:07 · Modified 17/02/2026 17:07
Malware (25 / 33)
-
BADBOX usesFamilyPublished 17/02/2026 12:39 · Modified 17/02/2026 12:39
-
CanisterWorm usesFamilyPublished 22/04/2026 16:22 · Modified 22/04/2026 16:22
-
Spark stealer usesFamilyPublished 18/03/2026 10:42 · Modified 18/03/2026 10:42
-
ZinFoq usesFamilyPublished 10/12/2025 14:34 · Modified 10/12/2025 14:34
- Carberp
-
ModeLoader usesFamilyPublished 31/12/2024 16:26 · Modified 31/12/2024 16:26
-
SUPERNOVA - S0578 usesFamilyPublished 30/04/2026 14:20 · Modified 30/04/2026 14:20
-
Keenadu usesFamilyPublished 17/02/2026 12:39 · Modified 17/02/2026 12:39
-
Octalyn Stealer usesFamilyPublished 01/08/2025 11:48 · Modified 01/08/2025 11:48
-
Raven Stealer usesFamilyPublished 01/08/2025 11:48 · Modified 01/08/2025 11:48
-
Bootkitty usesFamilyPublished 27/11/2024 20:53 · Modified 27/11/2024 20:53
-
fast16.sys usesFamilyPublished 24/04/2026 05:05 · Modified 24/04/2026 05:05
-
Triada usesFamilyPublished 17/02/2026 12:39 · Modified 17/02/2026 12:39
-
BCObserver usesFamilyPublished 27/11/2024 20:53 · Modified 27/11/2024 20:53
-
WhisperGate usesFamilyPublished 09/09/2024 08:02 · Modified 09/09/2024 08:02
-
HybridPetya usesFamilyPublished 15/09/2025 14:12 · Modified 15/09/2025 14:12
-
PeerBlight usesFamilyPublished 28/01/2026 13:31 · Modified 28/01/2026 13:31
-
svcmgmt.exe usesFamilyPublished 24/04/2026 05:05 · Modified 24/04/2026 05:05
-
ClipBanker usesFamilyPublished 09/04/2026 09:57 · Modified 09/04/2026 09:57
-
NotPetya - S0368 usesFamilyPublished 15/09/2025 14:12 · Modified 15/09/2025 14:12
-
Vgod usesFamilyPublished 18/02/2025 06:02 · Modified 18/02/2025 06:02
- BOOTRASH
-
Totbrick usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
Stealit usesFamilyPublished 11/10/2025 02:50 · Modified 11/10/2025 02:50
-
Vo1d usesFamilyPublished 17/02/2026 12:39 · Modified 17/02/2026 12:39
Reports (11)
-
AlienVault Confidence 100 20 MITREs 3 Malwares 15 IOCs 15 ObservablesPublished 24/04/2026 07:05 · Modified 27/04/2026 14:38 · threat-report
-
AlienVault Confidence 100 19 MITREs 1 Malware 7 IOCs 7 Observables 1 APTPublished 24/03/2026 11:50 · Modified 27/03/2026 00:05 · threat-report
-
AlienVault Confidence 100 10 MITREs 4 IOCs 4 Observables 1 APTPublished 24/03/2026 09:49 · Modified 27/03/2026 00:05 · threat-report
-
11 MITREs 1 Malware 51 ObservablesPublished 18/03/2026 10:42 · Modified 18/03/2026 11:22
-
3 CVEs 20 MITREs 4 Malwares 36 ObservablesPublished 10/12/2025 14:34 · Modified 21/12/2025 18:57
-
20 MITREs 1 Malware 12 Observables 1 APTPublished 11/10/2025 02:50 · Modified 13/10/2025 10:15
-
5 MITREs 7 ObservablesPublished 17/03/2025 09:40 · Modified 17/03/2025 10:03
-
Vgod RANSOMWARE related30 MITREs 1 Malware 1 ObservablePublished 18/02/2025 06:02 · Modified 18/02/2025 08:54
-
15 MITREs 2 Malwares 5 Observables 1 APTPublished 31/12/2024 16:26 · Modified 31/12/2024 16:57
-
BADBOX Botnet Is Back related10 MITREs 2 Malwares 22 Observables 1 APTPublished 17/12/2024 21:59 · Modified 18/12/2024 12:10
-
8 MITREs 3 MalwaresPublished 27/11/2024 20:53 · Modified 28/11/2024 08:32
Vulnerabilities (CVE) (5)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
- Attack vector
- LOCAL
- Published
- 14/01/2025
- Modified
- 21/12/2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, which enables threat …
- Published
- 03/04/2025
- Modified
- 03/04/2025
Rejected reason: This CVE is a duplicate of CVE-2025-55182.
- Published
- 20/12/2025
- Modified
- 21/12/2025
The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 via deserialization of …
- Published
- 01/10/2024
- Modified
- 04/10/2024
Attack patterns (MITRE) (1)
-
Pre-OS Boot subtechnique-ofT1542
Course Of Action (2)
- Boot Integrity mitigates
- Privileged Account Management mitigates