Microsoft’s inaugural Security Signals report, for March 2021, shows that 80% of enterprises have experienced a firmware attack in the past two years. Yet, less than 1/3 of security budgets are dedicated to protecting firmware. Firmware attacks are difficult to combat.
The state-sponsored hacking group “APT28” (also known as Fancy Bear), was observed in 2018 using a UEFI (Unified Extensible Firmware Interface) rootkit to target Windows. Attacks based on hardware drivers have also been reported (e.g. RobbinHood, Uburos, Derusbi, Sauron, GrayFish, ThunderSpy).
Read also: APT28: Has been scanning the internet for vulnerable email servers for a year
Microsoft has released “Secure-core” PCs with greater protection against firmware attacks, as well as a UEFI scanner in Microsoft Defender ATP, to scan the firmware filesystem for the presence of malware.

However, enterprises are not taking firmware attacks seriously, according to a study commissioned by Microsoft to Hypothesis Group . Specifically, the study showed that current investments are being made for security updates, vulnerability scanning, and advanced threat protection solutions.
However, many organizations are concerned about malware gaining access to their systems, as well as the difficulty in detecting threats, which suggests that firmware is more difficult to monitor and control.
Additionally, the question arises as to whether and to what extent security teams are adequately addressing future threats. Microsoft believes they are not. The study found that 36% of enterprises are investing in hardware-based memory card data encryption and 46% are purchasing hardware-based kernel protections.
See also: Microsoft: Stops support for Cortana App on iOS and Android

The study also found that security teams are focused on safety and protection models, noting that only 39% of security teams' time is dedicated to prevention.
Suggestion: New Android malware appears as a system update!
It is worth noting that most of the 1,000 (82%) business decision-makers surveyed in the study said they do not have enough resources to handle high-impact security tasksbecause they are too busy patching, hardware upgrades, and mitigating any internal or external vulnerabilities.
Information source: zdnet.com
