ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

A UEFI firmware bootkit in the wild by Ivan Kwiatkowski | Nullcon Goa 2022

Автор: nullcon

Загружено: 2022-10-12

Просмотров: 3651

Описание: Abstract :
---------------
Despite the advanced capabilities they provide, low-level implants such as bootkits and rootkits are only deployed by the most sophisticated attackers due to the risk they pose to the victim system’s stability. In recent years, Kaspersky has however observed a number of new low-level malware, such as MosaicRegressor, MoonBounce, and the object of this talk, CosmicStrand. CosmicStrand is a UEFI firmware bootkit that hides in select Asus and Gigabyte motherboards in order to provide persistence so deep that it would survive a Windows reinstallation. CosmicStrand starts execution when the victim machine is powered on, and propagates a malicious component up to the Windows kernel, where it injects a shellcode tasked with downloading further malware from a C2 server.

This talk presents the inner workings of the rootkit, but also delves into its mysterious history. The variants we discovered appeared between 2016 and 2020, with year-long gaps in the middle during which the corresponding infrastructure appears to have been inactive. We also study the interesting code similarities between CosmicStrand and the MyKings botnet, which is linked with the Chinese-speaking cybercrime ecosystem.

#rootkit #bootkit #UEFI #Firmware #NullconGoa2022 #Nullcon
-----------------------------------------------------------------------------------------------
Follow nullcon on Facebook:   / nullcon  
Twitter:   / nullcon  
LinkedIn:   / nullcon  
Website: https://nullcon.net

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
A UEFI firmware bootkit in the wild by Ivan Kwiatkowski | Nullcon Goa 2022

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

💀 Самый опасный компьютерный вирус: вирус BIOS | вирус материнской платы | Lojax | UEFI Rootkit

💀 Самый опасный компьютерный вирус: вирус BIOS | вирус материнской платы | Lojax | UEFI Rootkit

When The Motherboard Comes With a Virus

When The Motherboard Comes With a Virus

Bootkitty - The First UEFI Bootkit That Targets Linux

Bootkitty - The First UEFI Bootkit That Targets Linux

OS development 101 - How to make a bootloader part 1 - Hello World

OS development 101 - How to make a bootloader part 1 - Hello World

Koen Vossen - Ingestify: Rethinking Ingestion for Complex Data - PySport X PyData Eindhoven 2025

Koen Vossen - Ingestify: Rethinking Ingestion for Complex Data - PySport X PyData Eindhoven 2025

Nullcon Goa 2025: Securing the chains: Building defensive layers for software supply chains

Nullcon Goa 2025: Securing the chains: Building defensive layers for software supply chains

💀Самый опасный компьютерный вирус: вирус BIOS | вирус материнской платы | антивирус | UEFI руткит

💀Самый опасный компьютерный вирус: вирус BIOS | вирус материнской платы | антивирус | UEFI руткит

#NullconBerlin2025 | DHCPwned: Owning Cameras One Lease at a Time by Emanuele Barbeno

#NullconBerlin2025 | DHCPwned: Owning Cameras One Lease at a Time by Emanuele Barbeno

UEFI Malware - The Low Level Threat To Millions of PCs

UEFI Malware - The Low Level Threat To Millions of PCs

Meshtastic в России: законно ли использовать?

Meshtastic в России: законно ли использовать?

The New BIOS Hack That Bypasses Every Antivirus

The New BIOS Hack That Bypasses Every Antivirus

#NullconBerlin2025 | Finding insecure cryptographic keys in DKIM, DNSSEC, OpenID Connect & elsewhere

#NullconBerlin2025 | Finding insecure cryptographic keys in DKIM, DNSSEC, OpenID Connect & elsewhere

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

DEF CON 26 - Alexandre Borges - Ring 0 Ring 2 Rootkits  Bypassing Defenses

DEF CON 26 - Alexandre Borges - Ring 0 Ring 2 Rootkits Bypassing Defenses

This Virus Can Destroy Your Motherboard

This Virus Can Destroy Your Motherboard

new vulnerability in your motherboard lasts forever

new vulnerability in your motherboard lasts forever

BootKitty UEFI Bootkit Reverse Engineering: A Deep Dive into First UEFI Bootkit Targeting Linux

BootKitty UEFI Bootkit Reverse Engineering: A Deep Dive into First UEFI Bootkit Targeting Linux

Nullcon Goa 2025 | Large-Scale Exposure Of Orphaned Commits On Major Git Platforms by Kumar Ashwin

Nullcon Goa 2025 | Large-Scale Exposure Of Orphaned Commits On Major Git Platforms by Kumar Ashwin

Не используй DNS провайдера! Защищённые DOT, DOH DNS + VPN + Keenetic

Не используй DNS провайдера! Защищённые DOT, DOH DNS + VPN + Keenetic

The UEFI Firmware Rootkits: Myths and Reality

The UEFI Firmware Rootkits: Myths and Reality

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]