Running Malware Below the OS - The State of UEFI Firmware Exploitation
ID: f90f0396-a5c5-53b3-914f-6b74509ec65c
STIX ID: report--f90f0396-a5c5-53b3-914f-6b74509ec65c
Feed Name: Binary Defense Blog
Threat Score
This report reviews UEFI boot process security and categorizes modern bootkits by technique (ESP-only, DXE-only, DXE with SPI-based Secure Boot bypass, and MOK-based bypass), describing multiple real-world examples and their capabilities; it highlights firmware-level persistence, supply-chain risk, Secure Boot weaknesses (including CVE-2022-21894), and ties several bootkits to known APTs and criminal tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
