Suspicious Renamed GRUB Bootloader grubx64-real Creation via File System

PremiumReviewedSigma · High · v1
Product
linux
Category
file_event
Author
HuntRule
Published
2026-09-23
Updated
2026-09-23

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects creation of grubx64-real.efi under the EFI system partition, the artifact Bootkitty produces by displacing the genuine GRUB bootloader so its malicious bootloader can chainload the real one after patching the kernel. A grubx64-real.efi file indicates that the boot chain has been hijacked by a UEFI bootkit.

Related detections3 linkedT1542.003 — drag to rearrange
Suspicious Bootkitty Rootkit Component Drop under opt via File System
Malicious Boot Configuration Tampering via bcdedit (via process_creation)
Windows bcdedit.exe Tampering for MBR/Boot Persistence (Delete, Import, SafeBoot, Network)
Suspicious Renamed GRUB Bootloader grubx64-real Creation via File System
Pivot detection · T1542.003 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.