ISC StormCast for Tuesday, January 25th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 January 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, January 25th, 2020 edition of the Sands and the Storm Center's Stormcast. |
| 0:07.6 | My name is Johannes Ulrich. |
| 0:09.2 | And I'm recording from Jacksonville, Florida. |
| 0:13.7 | Gispersky has a write-up of what they call moonbounds, a new type of UEFI, a malware that malware that is well even more difficult to remove than |
| 0:24.3 | some of the malware that we have seen in the past. Now with UAFI you do have multiple components. |
| 0:32.4 | One is the SPI flash, that's the serial peripheral interface flash, a little bit of flash memory that sort of has |
| 0:38.6 | the basic firmware that's being used to boot the computer. But then you also do have a special |
| 0:46.7 | partition, an EFI system partition, that may contain things like parameters and such for UFI to boot. |
| 0:56.5 | Now the ESP, the EFI system partition, that's on your hard drive. |
| 1:02.2 | It's not on this flash memory. |
| 1:06.2 | Breyer Malware did mostly focus on the ESP. |
| 1:10.5 | So that meant if you swapped your hard drive, you were good. |
| 1:14.2 | You basically had a clean system. What Kasperski is now observing is Malver that actually makes |
| 1:21.2 | some subtle changes to the SPI flash. And with that, swapping your hard drive is no longer really going to clean |
| 1:30.0 | the system. So the usual repartition reinstall trick is not going to cut it here. And well, |
| 1:36.5 | what the Mallory does very briefly here, more details in Kasperski's report. It's not really possible to summarize it all here in the |
| 1:46.9 | podcast, but once you boot the system, components from SPI Flash are copied and injected |
| 1:53.6 | into the Windows loader in the Windows kernel, which then is used to essentially reinfect |
| 2:00.0 | the system if you had it cleaned up |
| 2:03.0 | before. |
| 2:04.5 | Kaspersky does speculate that this originates from a particular advanced persistent threat |
| 2:11.0 | group and was a targeted attack. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

