Skip to content

UEFI / Firmware Malware

Risk Level

Firmware malware infects low-level software embedded in hardware — UEFI/BIOS, network cards, hard drive controllers, USB controllers. Because firmware executes before the OS loads and is typically not scanned by security software, firmware implants are extraordinarily persistent and difficult to detect or remove, surviving OS reinstallation and disk formatting.

MilestoneYearDetails
NSA ANT Catalogue~2001-2013IRATEMONK, DEITYBOUNCE, etc.
LoJax2018APT28; first confirmed UEFI rootkit
MosaicRegressor2020UEFI implant; journalists
BadUSB2014USB controller reprogramming
CosmicStrand2022UEFI bootkit; counterfeit hardware
MoonBounce2022SPI flash UEFI; SPI flash persistence
TargetDescriptionPersistence
UEFI/BIOSSystem firmware; executes firstOS reinstall survives
HDD/SSD FirmwareDrive controller; hidden data storeSurvives format/replace OS
NIC FirmwareNetwork card; traffic intercept/injectSurvives OS reinstall
USB ControllerBadUSB; emulate keyboard/HIDSurvives OS reinstall
TPMPlatform crypto processorPlatform integrity
BMC/IPMIServer managementOOB persistence
GPU/PeripheralOption ROMsDriver load
ImplantYearAttributionTarget
IRATEMONK~2001NSAHDD firmware
DEITYBOUNCE~2008NSAServer BIOS
LoJax2018APT28 (GRU)UEFI
MosaicRegressor2020UnknownUEFI
BadUSB2014ResearchersUSB controller
CosmicStrand2022UnknownUEFI bootkit
MoonBounce2022UnknownSPI flash UEFI
BlackLotus2023CriminalUEFI Secure Boot bypass
1. UEFI IMPLANT
└─ Flash malicious DXE driver into UEFI firmware
└─ Executes before OS loader; hooks Boot Services
2. HDD FIRMWARE
└─ Modify drive controller firmware
└─ Hidden sectors invisible to OS tools
└─ Persistent data store survives format
3. NIC IMPLANT
└─ Flash NIC option ROM / firmware
└─ Intercept/inject traffic at hardware level
4. USB CONTROLLER (BadUSB)
└─ Reprogram USB controller firmware
└─ Emulate keyboard, network, mass storage
5. SUPPLY CHAIN
└─ Introduced during manufacturing/distribution
└─ Counterfeit hardware with pre-installed implants
MethodTools
UEFI ScannerCHIPSEC, UEFI Scanner, Copernicus
SPI Flash Dumpflashrom, hardware programmer
UEFI Variable Dumpefivar, uefi-firmware-parser
Measured BootTPM PCR 0-7 verification
Hardware ProgrammerCH341A, Bus Pirate, Dediprog
UEFI Scanner (Windows)msinfo32, Get-SecureBootUEFI
  • Enable Secure Boot — Never disable
  • TPM 2.0 + Measured Boot — PCR 0-7 attestation
  • Firmware Updates — Vendor official channels only
  • Intel Boot Guard / AMD Platform Secure Boot — Hardware-rooted
  • Supply Chain — Trusted vendors, tamper-evident packaging
  • No Unknown USB — Hardware firewall, USBGuard
  • Physical Security — Tamper-evident seals, chassis intrusion
TechniqueIDDescription
BootkitT1542.003MBR/VBR/UEFI infection
Firmware CorruptionT1495UEFI/BIOS modification
System FirmwareT1542.001BIOS/UEFI modification