UEFI rootkits are considered extremely dangerous tools, not only because they are difficult to detect, but also because they can “survive” radical security measures, such as reinstalling the operating system or even replacing the hard drive. 
Some UEFI rootkits have been presented as PoCs at security conferences, and some of them may be available to government agencies. However, to date, no UEFI rootkit has been detected in circulation. However, ESET has reportedly discovered a campaign by the Sednit APT group that successfully uses UEFI rootkits.
The discovery of the first UEFI rootkit is notable because it shows that malware is a real threat and is not just an attractive topic for a conference.
ESET’s analysis of the Sednit campaign using the UEFI rootkit was presented on September 27 at the Microsoft BlueHat 2018 conference and is described in detail in the white paper: “LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group”.
H om;ada Sednit has been operating since at least 2004 and has successfully carried out major attacks on high-profile targets in recent years. For example, the group is said to have carried out the attack on the US Department of Justice before the 2016 US elections. The group is also believed to be responsible for the attack on the global television network TV5Monde, among many others.
ESET’s research found that the group has succeeded in at least once installing a UEFI rootkit on a system’s SPI flash. The method is particularly invasive, as the malware can survive after reinstalling the operating system and replacing the hard drive.
The Sednit group used various components of the LoJax malware to target government organizations in the Balkans, Central and Eastern Europe.
You can read ESET’s full analysis at
https://www.welivesecurity.com
________________________
- Windows vs Linux you like it you don't like it
- Windows 10 October 2018 Update Installation and a First Look
