A UEFI firmware bootkit in the wild by Ivan Kwiatkowski | Nullcon Goa 2022
Abstract : --------------- Despite the advanced capabilities they provide, low-level implants such as bootkits and rootkits are only deployed by the most sophisticated attackers due to the risk they pose to the victim system’s stability. In recent years, Kaspersky has however observed a number of new low-level malware, such as MosaicRegressor, MoonBounce, and the object of this talk, CosmicStrand. CosmicStrand is a UEFI firmware bootkit that hides in select Asus and Gigabyte motherboards in order to provide persistence so deep that it would survive a Windows reinstallation. CosmicStrand starts execution when the victim machine is powered on, and propagates a malicious component up to the Windows kernel, where it injects a shellcode tasked with downloading further malware from a C2 server. This talk presents the inner workings of the rootkit, but also delves into its mysterious history. The variants we discovered appeared between 2016 and 2020, with year-long gaps in the middle during which the corresponding infrastructure appears to have been inactive. We also study the interesting code similarities between CosmicStrand and the MyKings botnet, which is linked with the Chinese-speaking cybercrime ecosystem. #rootkit #bootkit #UEFI #Firmware #NullconGoa2022 #Nullcon ----------------------------------------------------------------------------------------------- Follow nullcon on Facebook: / nullcon Twitter: / nullcon LinkedIn: / nullcon Website: https://nullcon.net

When The Motherboard Comes With a Virus

BlackLotus - How UEFI Secure Boot Became a Gateway for Cyber Attacks

Exposing Bootkits with BIOS Emulation

There Might Be a Hidden Backdoor in Your Computer

Every Level of Reverse Engineering Explained

The UEFI Firmware Rootkits: Myths and Reality

Mastering UEFI: Your Essential Guide to Hardware-Firmware and Boot-Chain Security

Casey Muratori – The Big OOPs: Anatomy of a Thirty-five-year Mistake – BSC 2025

💀 Most Dangerous Computer Virus: BIOS Virus | Motherboard Virus | Lojax | UEFI Rootkit

BLACKLOTUS UEFI MALWARE | Forensics Guide

The Linux Boot Process (Linux+ Objective 1.1.2)

The New BIOS Hack That Bypasses Every Antivirus

Windows 11 Security — Our Hacker-in-Chief Runs Attacks and Shows Solutions

Something is jamming GPS over Europe. Here's what we found

Unauthenticated Pre Pairing Gatt Write Vulnerability In Smartwatch Ecosystems

BootKitty UEFI Bootkit Reverse Engineering: A Deep Dive into First UEFI Bootkit Targeting Linux

UEFI Malware - The Low Level Threat To Millions of PCs

How Computers BOOT: From Startup to Viruses

Bootloading 101

