Skip to main content

Posts

Showing posts with the label UEFI Firmware

MoonBounce - UEFI-Malware that can withstand OS reinstallations

MoonBounce is the UEFI firmware's dark side. Report Link - Click here Malware that can withstand OS reinstallations strikes again, most likely for cyberespionage. Kasper Firmware Scanner logs revealed a UEFI firmware-level compromise, which has been integrated into Kaspersky products since the beginning of 2019. Further investigation by Kasper Lab revealed that attackers modified a single component within the inspected firmware's image, allowing them to intercept the original execution flow of the machine's boot sequence and introduce a sophisticated infection chain. As per the study, the attackers could be pointing out a target belongs to an organisation which is in charge of various transportation-related businesses.   A very critical segment as it can bring down the entire transport system and creating chaos across the globe After obtaining a foothold in the network, Kasper Lab identified some of the attackers' orders, which lateral movement and data exfiltration fro...