Firmware malware infects low-level software embedded in hardware — UEFI/BIOS, network cards, hard drive controllers, USB controllers. Because firmware executes before the OS loads and is typically not scanned by security software , firmware implants are extraordinarily persistent and difficult to detect or remove , surviving OS reinstallation and disk formatting.
Milestone Year Details NSA ANT Catalogue ~2001-2013 IRATEMONK, DEITYBOUNCE, etc. LoJax 2018 APT28; first confirmed UEFI rootkit MosaicRegressor 2020 UEFI implant; journalists BadUSB 2014 USB controller reprogramming CosmicStrand 2022 UEFI bootkit; counterfeit hardware MoonBounce 2022 SPI flash UEFI; SPI flash persistence
Target Description Persistence UEFI/BIOS System firmware; executes first OS reinstall survives HDD/SSD Firmware Drive controller; hidden data store Survives format/replace OS NIC Firmware Network card; traffic intercept/inject Survives OS reinstall USB Controller BadUSB; emulate keyboard/HID Survives OS reinstall TPM Platform crypto processor Platform integrity BMC/IPMI Server management OOB persistence GPU/Peripheral Option ROMs Driver load
Implant Year Attribution Target IRATEMONK ~2001 NSA HDD firmware DEITYBOUNCE ~2008 NSA Server BIOS LoJax 2018 APT28 (GRU) UEFI MosaicRegressor 2020 Unknown UEFI BadUSB 2014 Researchers USB controller CosmicStrand 2022 Unknown UEFI bootkit MoonBounce 2022 Unknown SPI flash UEFI BlackLotus 2023 Criminal UEFI Secure Boot bypass
└─ Flash malicious DXE driver into UEFI firmware
└─ Executes before OS loader; hooks Boot Services
└─ Modify drive controller firmware
└─ Hidden sectors invisible to OS tools
└─ Persistent data store survives format
└─ Flash NIC option ROM / firmware
└─ Intercept/inject traffic at hardware level
4. USB CONTROLLER (BadUSB)
└─ Reprogram USB controller firmware
└─ Emulate keyboard, network, mass storage
└─ Introduced during manufacturing/distribution
└─ Counterfeit hardware with pre-installed implants
Method Tools UEFI Scanner CHIPSEC, UEFI Scanner, Copernicus SPI Flash Dump flashrom, hardware programmerUEFI Variable Dump efivar, uefi-firmware-parserMeasured Boot TPM PCR 0-7 verification Hardware Programmer CH341A, Bus Pirate, Dediprog UEFI Scanner (Windows) msinfo32, Get-SecureBootUEFI
✅ Enable Secure Boot — Never disable
✅ TPM 2.0 + Measured Boot — PCR 0-7 attestation
✅ Firmware Updates — Vendor official channels only
✅ Intel Boot Guard / AMD Platform Secure Boot — Hardware-rooted
✅ Supply Chain — Trusted vendors, tamper-evident packaging
✅ No Unknown USB — Hardware firewall, USBGuard
✅ Physical Security — Tamper-evident seals, chassis intrusion
Technique ID Description Bootkit T1542.003 MBR/VBR/UEFI infection Firmware Corruption T1495 UEFI/BIOS modification System Firmware T1542.001 BIOS/UEFI modification