HomeSecurityChinese group uses UEFI bootkit to spread malware

Chinese group uses UEFI bootkit to spread malware

A Chinese hacking group has been observed using a UEFI bootkit to download and install additional malware on targeted computers.

UEFI firmware is a critical component for every computer. This critical firmware inside a flash memory is “screwed” into the motherboard and controls all of the computer’s hardware components and helps boot the actual operating system (like Windows, Linux, macOS, etc.).

UEFI malware

Attacks on the UEFI firmware are the target of every hacking group, as inserting malicious code here allows it to survive reinstallation of the operating system.

However, despite these benefits, attacks on UEFI firmware are rare because compromising this component is particularly difficult, as attackers either need physical access to the device or must compromise targets through complex supply chain attacks, where the UEFI firmware or tools that work with the UEFI firmware are modified to introduce malicious code.

In a talk at the SAS virtual security conference, Kaspersky security researchers said they had identified the second known case of a widespread attack leading to malicious code being implanted in UEFI.

The first, uncovered by ESET in 2018, was allegedly carried out by Fancy Bear, one of Russia's state-sponsored groups. The second is the work of Chinese hackers, Kaspersky says.

The company said it discovered these attacks after two computers were flagged by the company's Firmware Scanner module as suspicious.

In their talk today, Kaspersky researchers Mark Lechtik and Igor Kuznetsov said they investigated the flagged systems and found malicious code within the UEFI firmware. This code, they said, was designed to install a malicious application (as an autorun program) after each computer boot.

This initial autorun program acted as a downloader for other malware components, which Kaspersky named as the MosaicRegressor malware framework.

Kaspersky said it has not yet obtained and analyzed all of the MosaicRegressor components, but those they examined contained functionality to collect all documents from the “Recent Documents” folder and place them in a password-protected archive – likely preparing the files for exfiltration via another component.

The researchers said they found the UEFI bootkit on only two systems, but found MosaicRegressor components on many other computers.

However, all the targets of these attacks were carefully chosen. They were all diplomatic entities and NGOs in Africa, Asia , and Europe.

But Kaspersky made another important discovery while analyzing these attacks. The UEFI malicious code was not new. According to their analysis, the code was based on VectorEDK, which is a hacking utility for attacks on “UEFI firmware”, which was created by the Italian “HackingTeam”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS