MoonBounce: Internals of the 3rd publicly known UEFI firmware implant | Mark Lechtik | hardwear.io

Abstract: ---------------- During spring 2021, Kaspersky researchers were made aware of a novel threat against UEFI in the wild. Through careful inspection of firmware scanning logs, it was evident that attackers have modified and deeply embedded an implant within a benign UEFI firmware image. This was done in a way that allowed them to intercept the original execution flow of the machine’s boot sequence and introduce a sophisticated infection chain to run alongside it. We dubbed this discovered implant MoonBounce. In this talk, we will describe in detail how MoonBounce works, as well as outline the story of our investigation, including details that tie it with the activity of the infamous APT41 threat group. Speaker Bio: ---------------------- Mark Lechtik is a Senior Security Researcher at Kaspersky's GReAT (Global Research & Analysis Team), based in Israel. After having worked as a researcher and manager on Check Point’s malware research team, his primary focus is analysing malware of all shapes and forms, digging up their underlying stories and profiling the actors behind them. Today, he is tasked with providing intelligence reports on APT campaigns to Kaspersky customers, often focusing on the utilization of kernel mode rootkits and UEFI bootkits. Mark has previously presented his work at well-known security conferences such as REcon, CCC, CARO Workshop, AVAR and TheSASCon. #UEFI #embedded #firmware #hardwaresecurity #hardwear_io ------------------------------------------------------------------------------------------------ Website: https://hardwear.io Twitter:   / hardwear_io   Facebook:   / hardwear.io   LinkedIn:   / hardwear.io-hardwaresecurityconferenceandt...  

Cyber-physical system security: Exploiting the physics of sensors to undermine AI-based decisions
▶︎

Cyber-physical system security: Exploiting the physics of sensors to undermine AI-based decisions

Hardwear.io NL 2025 | RE Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security
▶︎

Hardwear.io NL 2025 | RE Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security

Decade of the RATs – Custom Chinese Linux Rootkits for Everyone
▶︎

Decade of the RATs – Custom Chinese Linux Rootkits for Everyone

Passkeys Explained: Are They Actually Better Than Passwords?
▶︎

Passkeys Explained: Are They Actually Better Than Passwords?

UEFI Malware - The Low Level Threat To Millions of PCs
▶︎

UEFI Malware - The Low Level Threat To Millions of PCs

Why Aliens Would NEVER Invade Africa
▶︎

Why Aliens Would NEVER Invade Africa

Knockin' on MediaTek aDSP’s Door | Slava Makkaveev | hardwear.io Webinar 2022
▶︎

Knockin' on MediaTek aDSP’s Door | Slava Makkaveev | hardwear.io Webinar 2022

When The Motherboard Comes With a Virus
▶︎

When The Motherboard Comes With a Virus

Hardwear.io NL 2025: [Keynote] Towards End-User Verifiable Silicon - Andrew 'Bunnie' Huang
▶︎

Hardwear.io NL 2025: [Keynote] Towards End-User Verifiable Silicon - Andrew 'Bunnie' Huang

We've Been Using The Wrong Science In Court For 50 years
▶︎

We've Been Using The Wrong Science In Court For 50 years

The Story of C++: The World's Most Consequential Programming Language | The Official Story
▶︎

The Story of C++: The World's Most Consequential Programming Language | The Official Story

Stop Prompting Claude. Use Karpathy's Method Instead.
▶︎

Stop Prompting Claude. Use Karpathy's Method Instead.

Hardwear.io NL 2025: Bypassing PQC Signature Verification w FaultInjection Dilithium, XMSS, SPHINCS+
▶︎

Hardwear.io NL 2025: Bypassing PQC Signature Verification w FaultInjection Dilithium, XMSS, SPHINCS+

The Database That Should Be Dead but Runs the Internet
▶︎

The Database That Should Be Dead but Runs the Internet

The FULL VIDEO of Trump they didn’t want released
▶︎

The FULL VIDEO of Trump they didn’t want released

Your Fancy DNS Tricks Won’t Give You Privacy
▶︎

Your Fancy DNS Tricks Won’t Give You Privacy

What is the Dark Web? A Guide to the Dark Side of the Internet
▶︎

What is the Dark Web? A Guide to the Dark Side of the Internet

Why Israel is the World's Top Hacking Nation | VICE: Cyberwar | Blueprint
▶︎

Why Israel is the World's Top Hacking Nation | VICE: Cyberwar | Blueprint

The Man Asked If I Was Still Looking for My Son—Then He Said, “I’m the Kid in..." - Calm Dad Stories
▶︎

The Man Asked If I Was Still Looking for My Son—Then He Said, “I’m the Kid in..." - Calm Dad Stories

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed
▶︎

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed