MoonBounce

MoonBounce
Malware details
TypeBootkit
ClassificationRootkit
AuthorAPT41
Technical details
PlatformMicrosoft Windows

MoonBounce is a UEFI firmware-based rootkit. It is linked to the Chinese APT41 hacker group. MoonBounce was discovered by the researchers at Kaspersky in 2021.[1] It can disable Windows security tools and bypass User Account Control.[2]

Data shows that the attacks are highly targeted.[3] The malware is a landmark in UEFI rootkit evolution.[4] It is the third known malware UEFI bootkit found.[citation needed]

Infection

Kaspersky has detected the firmware rootkit in only one case so little was discovered in regards to the way the rootkit is supposed to spread. It is believed that it had been installed remotely.[5]

The SPI flash memory on the motherboard is the implanting location. CORE_DXE is the firmware laced component which is used during the first phases of the UEFI boot sequence. It hooks EFI Boot Services functions and inject more malware into a svchost.exe process during boot.[6]

It resides on a low level portion of the motherboard's SPI flash. It operates in memory only which makes it undetectable on the HDD.[7]

References

  1. ^ "New MoonBounce UEFI malware used by APT41 in targeted attacks". BleepingComputer. Archived from the original on 2023-01-17. Retrieved 2024-03-21.
  2. ^ Yusaf, Mansoor (2023-09-18). "MoonBounce UEFI Bootkit Malware". Propelex. Archived from the original on 2023-09-25. Retrieved 2024-03-21.
  3. ^ CG (2022-02-06). 電腦1週: PCStation Issue 1109 (in Chinese). Creative Games Limited.
  4. ^ Olyniychuk, Daryna (2023-03-14). "BlackLotus UEFI Bootkit Detection: Exploits CVE-2022-21894 to Bypass UEFI Secure Boot and Disables OS Security Mechanisms". SOC Prime. Archived from the original on 2023-03-31. Retrieved 2024-03-21.
  5. ^ Paulina, Adam (2023-11-14). "Running Malware Below the OS - The State of UEFI Firmware Exploitation". Binary Defense. Archived from the original on 2023-12-09. Retrieved 2024-03-21.
  6. ^ "MoonBounce: the dark side of UEFI firmware". securelist.com. 2022-01-20. Archived from the original on 2024-02-01. Retrieved 2024-03-21.
  7. ^ Yurchenko, Alla (2022-01-25). "The Most Refined UEFI Firmware Implant: MoonBounce Detection". SOC Prime. Archived from the original on 2023-06-03. Retrieved 2024-03-21.

Content Disclaimer

Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.

  1. The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
  2. There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
  3. It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
  4. Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
  5. Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.