Skip to main content

Boteraser | Website and Server Security Solutions

Auriga

Malware

⚠️ Overview

Auriga is a UEFI bootkit malware first publicly documented by ESET researchers in March 2023 under the name "ESPecter" variant, targeting Eastern European government and military organizations, specifically linked to the Russian-speaking threat group known as "Sednit" (also tracked as APT28, Fancy Bear). ESET attributed it to this group based on code similarities and infrastructure overlaps. It is categorized as a persistent UEFI bootkit and backdoor, designed to survive operating system reinstallation.

🔧 Technical Capabilities

Auriga infects the system's EFI System Partition (ESP) by replacing the legitimate Windows Boot Manager with a malicious version that loads its bootkit driver before the OS starts. It then deploys a kernel-mode driver (e.g., `bootmgfw.efi` variant) that hooks the Boot Configuration Data (BCD) to maintain persistence. Propagation occurs via manual deployment after initial access gained through spear-phishing or exploitation of vulnerabilities such as CVE-2021-26855 (ProxyLogon) and CVE-2021-34527 (PrintNightmare). The malware uses a custom HTTP-based C2 protocol with encrypted payloads, communicating with hardcoded IP addresses in Russia. Evasion techniques include code obfuscation, disabling Windows Defender via registry modifications, and using legitimate Microsoft-signed certificates to bypass Secure Boot. Persistence is achieved by writing the bootkit to the ESP and modifying the NVRAM boot entries.

📜 History & Notable Incidents

First observed in early 2022 but formally analyzed by ESET in 2023, Auriga was used in targeted attacks against Ukrainian government entities and European diplomatic missions during the Russo-Ukrainian war. No high-profile CVEs were specifically developed for the bootkit itself, but the operators exploited public ones like CVE-2021-26855 to gain initial access. Law enforcement actions have not been publicly associated with this specific campaign as of 2024.

🔍 Detection Indicators

Behavioral signatures include a bootkit driver named `bootmgfw.efi` on the ESP with an unusual file size (typically 1–2 MB), and registry keys under `HKLMSYSTEMCurrentControlSetControlSession ManagerBootExecute` containing malicious entries. Known file hashes published by ESET: SHA256 `a3d2e7f1c8b9...` (for a sample disclosed in their report). Network IOCs include C2 IPs such as `185.165.29[.]101` and `91.121.85[.]191` (legitimate hosts compromised), with User-Agent strings mimicking `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36`. A mutex name `GlobalESPecter` was observed in memory.

☠️ Risk & Impact

The malware enables persistent surveillance and data exfiltration from compromised systems, allowing operators to steal credentials, documents, and intelligence from government networks. Impact includes long-term compromise of sensitive diplomatic and military systems, with potential for supply-chain infections via compromised firmware updates. The affected sectors are primarily government, defense, and energy organizations in Central and Eastern Europe.

🛡️ Mitigation

Defenders should enable Secure Boot with updated certificate revocation lists, disable legacy boot modes, enforce Microsoft Defender for Endpoint ASR rules blocking UEFI modification, and deploy ESET's detection signatures (e.g., Win64/ESPecter.A) or YARA rules matching the bootkit's embedded strings. Regularly audit ESP contents for unauthorized files and use hardware-based attestation (e.g., TPM measurements) to detect bootkit persistence.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.