YoVDO

A UEFI Firmware Bootkit in the Wild

Offered By: nullcon via YouTube

Tags

nullcon Courses Cybersecurity Courses Malware Analysis Courses

Course Description

Overview

Explore the intricacies of CosmicStrand, a sophisticated UEFI firmware bootkit, in this 46-minute conference talk from Nullcon Goa 2022. Delve into the inner workings of this low-level implant that targets specific Asus and Gigabyte motherboards, providing persistence that survives even Windows reinstallation. Discover how CosmicStrand operates from system power-on, propagating malicious components to the Windows kernel and injecting shellcode for further malware downloads. Examine its mysterious history, including variants from 2016 to 2020, and explore code similarities with the MyKings botnet. Gain insights into the bootkit's prevalence, functionality, and potential attack scenarios. Learn about the EFI driver, attacker code, boot manager modifications, and the process of transferring to the kernel. Understand the implications for victims, identify potential threat actors, and discover methods for disinfection in this comprehensive analysis of advanced firmware-level malware.

Syllabus

Introduction
Definitions
Past examples
Prevalence
How it works
EFI driver
Attacker code
Modifying the boot manager
OSL Arc Transfer to Kernel
ZW Create section
Patch Guard
Shell Code Loader
User Mode Components
C2 Servers
Timeline
Possible attack scenario
Victims
Threat actors
How to disinfect
Conclusion


Taught by

nullcon

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network