TrickBoot: Malware gefährdet die Firmware-Sicherheit

Sicherheitsforscher haben herausgefunden, dass sich die berüchtigte Trickbot-Malware geändert hat (TrickBoot) und nun auf Firmware abzielt.

Tarnkappe.info
TrickBot Returns with a Vengeance, Sporting Rare Bootkit Functions - A new "TrickBoot" module scans for vulnerable firmware and has the ability to read, write and eras... https://threatpost.com/trickbot-returns-bootkit-functions/161873/ #vulnerabilityscanning #read-writeeverything #firmwareinspection #vulnerabilities #malwareanalysis #rweverything #eclypsium #microsoft #trickboot #advintel #firmware #takedown #trickbot #malware #bootkit #botnet #bios #uefi
TrickBot Returns with a Vengeance, Sporting Rare Bootkit Functions

A new "TrickBoot" module scans for vulnerable firmware and has the ability to read, write and erase it on devices.

Threatpost - English - Global - threatpost.com

😰

RT @[email protected]

2020-12-03:🔥 And ... [Major Discovery] 🤖"Persist, Brick, Profit -#TrickBot Offers New “#TrickBoot” UEFI-Focused Functionality"

🆕*First* Time Crimeware Group Pursued UEFI Firmware Exploitation | #YARA+IOCs in MISP JSON/CSV

@[email protected] | @[email protected]
https://www.advanced-intel.com/post/persist-brick-profit-trickbot-offers-new-trickboot-uefi-focused-functionality

Persist, Brick, Profit -TrickBot Offers New “TrickBoot” UEFI-Focused Functionality

By AdvIntel & Eclypsium Key Takeaways: TrickBot malware now has functionality designed to inspect the UEFI/BIOS firmware of targeted systems. This marks a significant step in the evolution of TrickBot. Firmware level threats carry unique strategic importance for attackers. It is clear that TrickBot will benefit greatly