/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Amid a shift in malware targeting UEFI firmware, Kaspersky details new MoonBounce UEFI bootkit that can survive even after swapping the infected PC's hard drive

Catalin Cimpanu / The Record :

The Record Catalin Cimpanu

Context & Ripple Effects

MoonBounce extends a lineage Kaspersky has been documenting for years: Hacking Team's UEFI rootkit showed firmware persistence was possible back in 2015, and Kaspersky itself later found malware implanted in the UEFI firmware of motherboards belonging to diplomats focused on North Korea. The new detail here is degree of persistence — MoonBounce lives at the UEFI level and survives even swapping the infected machine's hard drive.

The report also lands mid-arc in a broader escalation: Kaspersky subsequently tracked a malicious UEFI-based rootkit used in the wild since 2016, and by 2023 the technique had reached the criminal market with BlackLotus, a $5K bootkit sold since October 2022 that bypasses UEFI Secure Boot.

First-order effects

  • Organizations cleaning MoonBounce infections can no longer treat a drive swap or OS reinstall as remediation — the implant persists in firmware, so responders must reflash or replace the motherboard's SPI flash to be sure the machine is clean.
  • Kaspersky's disclosure hands incident-response teams a detection target while tipping off the operators behind MoonBounce that their toolchain is burned.

Second-order effects

  • Endpoint security vendors face pressure to add firmware-layer visibility, since traditional on-disk antivirus cannot see a bootkit that loads before the OS.
  • Once a state-grade technique like this is publicly documented, it becomes a template for commercial tooling — the path that led to BlackLotus being sold as a ready-made bootkit within about a year.

Third-order effects

  • If firmware implants keep spreading down the sophistication curve, PC trust models built on assuming the bootloader is clean break down, pushing vendors toward hardware-rooted verification and aggressive Secure Boot binary revocation — a mechanism Microsoft's slow use of already left patched systems exposed to BlackLotus.
  • The battleground expanding beyond Windows — ESET's discovery of the first Linux-targeting UEFI bootkit suggests firmware persistence is becoming platform-agnostic rather than a Windows-specific threat.

The trend: Malware persistence is migrating from the operating system into UEFI firmware, moving from rare state-actor implants toward commoditized bootkits across platforms.

Discussion

  • @therecord_media @therecord_media on x
    Security researchers from Kaspersky said on Thursday that they had discovered a novel bootkit that can infect a computer's UEFI firmware https://therecord.media/...
  • @bitburner @bitburner on x
    MoonBounce Malware Hides In Your BIOS Chip, Persists After Drive Formats. It can be installed remotely, too. https://www.tomshardware.com/ ...