A Chinese-speaking threat actor has been attributed to a new type of sophisticated UEFI firmware rootkit called CosmicStrand.
Chinese-speaking hackers have been using malware that lies virtually unnoticed in firmware images for certain motherboards since at least 2016, one of the most persistent threats commonly known as a UEFI rootkit.
Researchers at cybersecurity firm Kaspersky named it CosmicStrand, but an older variant of the threat was discovered by malware analysts at Qihoo360, who named it Spy Shadow Trojan.
It is unclear how the threat actor managed to insert the rootkit into the firmware images of the target machines, but researchers found the malware on machines with ASUS and Gigabyte motherboards .
Unified Extensible Firmware Interface (UEFI) software is what connects a computer's operating system to the firmware of the underlying hardware.
UEFI code is the first to run during a computer's boot sequence, before the operating system and available security solutions.
Malware planted in the UEFI firmware image is not only difficult to identify, but is also extremely persistent, as it cannot be removed by reinstalling the operating system or replacing the storage drive.

A report from Kaspersky today provides technical details about CosmicStrand, from the infected UEFI component to the deployment of a kernel-level implant on a Windows at every boot.
The whole process consists of creating a hook to modify the operating system loader and controlling the entire execution flow to launch the shellcode that retrieves the payload from the control server.
Mark Lechtik , a former Kaspersky engineer now at Mandiant who participated in the research, explains that the compromised firmware images came with a modified CSMCORE DXE driver , which allows for a legacy boot process.
See also: T-Mobile: Agrees to pay $350 million to customers for last year's data breach
"This driver was modified to interfere with the boot sequence and inject malicious logic into it," Lechtik noted in a tweet on Monday.
While the CosmicStrand variant discovered by Kaspersky is more recent, researchers at Qihoo360 revealed the first details about an early version of the malware in 2017.
Chinese researchers began analyzing the implant after a victim reported that his computer had created a new account and his antivirus software kept notifying him of a malware infection.
According to their report, the compromised system was running on a used ASUS that the owner had purchased from an online store.
Kaspersky was able to determine that the CosmicStrand UEFI rootkit was registered in firmware images of Gigabyte or ASUS motherboards that have common designs using the H81 chipset.

This refers to old material between 2013 and 2015 that has mostly been discontinued today.
It is unclear how the implant was placed on the infected computers, as the process would involve either physical access to the device or via a malware precursor capable of automatically repairing the firmware image.
The victims identified by Kaspersky also provide few clues about the threat actor and its target, as the infected systems identified belong to individuals in China, Iran, Vietnam, and Russia who could not be linked to an organization or industry.
See also: SonicWall warns of critical SQL injection flaw
However, researchers linked CosmicStrand to a Chinese-speaking actor based on code patterns also seen in the cryptomining botnet MyKings, where malware analysts at Sophos found artifacts in the Chinese language.
Kaspersky says the CosmicStrand UEFI firmware rootkit can remain on the system for the lifetime of the computer and has been used in operations for years, since late 2016 .
The first widespread report of a UEFI rootkit being found, LoJax, came in 2018 from ESET and was used in attacks by Russian hackers in the APT28 (also known as Sednit, Fancy Bear, Sofacy).

Almost four years later and UEFI malware attacks in everyday life have become more common, and it wasn't just advanced hackers exploring this option:
We learned about MosaicRegressor from Kaspersky in 2020, although it was used in attacks in 2019 against non-governmental organizations.
In late 2020, news broke that the developers of TrickBot had created TrickBoot, a new module that checked compromised machines for UEFI vulnerabilities.
Another UEFI rootkit was revealed in late 2021 to be developed by Gamma Group as part of the FinFisher.
That same year, details emerged from ESET about another bootkit called ESPecter, believed to be used primarily for espionage and dating back to 2012.
MoonBounce ,considered one of the most sophisticated UEFI firmware implants, was revealed in January this year to be used by Winnti, a Chinese-speaking hacker group (also known as APT41).
Source: bleepingcomputer.com
