HomeSecurityFinFisher malware: Infects Windows Boot Manager with UEFI bootkit

FinFisher malware: Infects Windows Boot Manager with UEFI bootkit

FinFisher malware can now infect Windows devices using a UEFI bootkit that it integrates into the Windows Boot Manager.

FinFisher malware

See also: Microsoft: New FoggyWeb malware is a backdoor for hackers

FinFisher, also known as FinSpy or Wingbird, is a monitoring solution developed by Gamma Group that also comes with malware-like capabilities often found in spyware.

Its developer says it is sold exclusively to government agencies and law enforcement agencies around the world, but cybersecurity companies have also spotted it in phishing campaigns.

“ During our investigation, we found a UEFI bootkit that loaded FinSpy. All machines infected with the UEFI bootkit replaced the Windows Boot Manager (bootmgfw.efi) with a malicious one ,” Kaspersky researchers revealed to secnews

UEFI (Unified Extensible Firmware Interface) firmware allows for extremely persistent bootkit malware as it is installed on SPI flash storage, which is soldered to the computer's motherboard, making it impossible to get rid of by replacing the hard drive or even reinstalling the operating system.

See also: FlyTrap malware hacks thousands of Facebook accounts!

UEFI boot kit

Bootkits, like the one installed by the FinFisher malware, are malicious code that is installed in the firmware and is invisible to security solutions in the operating system, as they are designed to load before everything else, at the initial stage of a device's boot sequence.

They provide attackers with control over the operating system boot process and make it possible to sabotage defensive operating systems by bypassing the Secure Boot depending on the system's boot security mode.

“While in this case the attackers did not infect the UEFI firmware itself, but the next boot stage, the attack was notably undetectable, as the malicious module was installed in a separate partition and could control the boot process of the infected machine,” the researchers added.

The spyware's developers also used four layers of mitigation and analysis measures, designed to make the FinFisher malware one of the "most undetectable spyware to date.".

See also: iPhone 13: Apple not addressing spyware concerns

Their efforts were extremely effective, as the malware samples were able to evade almost every detection attempt and were nearly impossible to analyze.

Source: BleepingComputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS