• Big Story
  • News
    • News
    • Consumer Technology
    • Market Updates
    • Technology Insights
  • Interviews
  • Opinion
  • Digital Transformation Series
  • Special Reports
    • MWC Africa
    • Nigeria 5G Spectrum Auction
Friday, June 12, 2026
  • Login
  • Register
Technology Times | Latest and Breaking Nigeria Tech News
No Result
View All Result
Technology Times | Latest and Breaking Nigeria Tech News
No Result
View All Result
Technology Times | Latest and Breaking Nigeria Tech News
No Result
View All Result
Your text
Remita Remita Remita
ADVERTISEMENT

MoonBounce, ‘More Elusive’ Firmware on Rampage, Computer Users Warned

Technology Times StaffbyTechnology Times Staff
24/01/2022
in News
Reading Time: 3 mins read
1 0
A A
0
moonbounce-firmware-on-rampage-kaspersky

Tech savvy young Nigerian pictured using a Lenovo laptop in Lagos

ADVERTISEMENT
Stay connected via Google News
Add as preferred source on Google

MoonBounce, a rampaging firmware declared “more elusive” because its malicious implant can hide within essential parts of computers, Kaspersky, a cybersecurity firm, has alerted users.

Kaspersky says its researchers have uncovered the third case the firmware bootkit in the wild that is able to hide within a computer’s Unified Extensible Firmware MoonBounce, the cybersecurity firm says is “more elusive and more persistent” and third known firmware bootkit “shows major advancement.”

“MoonBounce demonstrates a sophisticated attack flow, with evident advancement in comparison to formerly reported UEFI firmware bootkits. The campaign has been attributed with considerable confidence to the well-known advanced persistent threat (APT) actor APT41”, according to the tech firm.

moonbounce-firmware-on-rampage-kaspersky
Technology Times file photo shows a lady working on a laptop computer. The rampaging MoonBouncee firmware hides inside essential parts of the computer, Kaspersky says.

Inside MoonBounce, The Elusive Firmware Difficult To Delete

“UEFI firmware is a critical component in the vast majority of machines” according to the Kaspersky alert which says that “its code is responsible for booting up the device and passing control to the software that loads the operating system.

“This code rests in what’s called SPI flash, a non-volatile storage external to the hard disk. If this firmware contains malicious code, then this code will be launched before the operating system, making malware implanted by a firmware bootkit especially difficult to delete; it can’t be removed simply by reformatting a hard drive or reinstalling an OS. What’s more, because the code is located outside of the hard drive, such bootkits’ activity go virtually undetected by most security solutions unless they have a feature that specifically scans this part of the device”, the tech security firm says.
Accordingly “the implant rests in the CORE_DXE component of the firmware, which is called upon early during the UEFI boot sequence. Then, through a series of hooks that intercept certain functions, the implant’s components make their way into the operating system, where they reach out to a command & control server in order to retrieve further malicious payloads, which we were unable to retrieve. It’s worth noting that the infection chain itself does not leave any traces on the hard drive, as its components operate in memory only, thus facilitating a fileless attack with a small footprint.

“While we can’t definitely connect the additional malware implants found during our investigation with MoonBounce specifically, it does appear as if some Chinese-speaking threat actors are sharing tools with one other to aid in their various campaigns; there especially seems to be a low confidence connection between MoonBounce and Microcin,” adds Denis Legezo, senior security researcher with GReAT says.

Kaspersky says it “has attributed MoonBounce with considerable confidence to APT41, which has been widely reported to be a Chinese-speaking threat actor that’s conducted cyberespionage and cybercrime campaigns around the world since at least 2012. In addition, the existence of some of the aforementioned malware in the same network suggests a possible connection between APT41 and other Chinese-speaking threat actors.”

Related Articles

Airtel: Affordability, digital literacy gaps slow Africa’s digital inclusion

VP backs expansion of digital education programme reaching 72,000 Nigerian students

IMF wants Nigeria to bring stablecoins, crypto under stronger regulation

Nigeria eyes AI, IoT to transform electricity sector

Nigeria’s data centre market to surpass $1 billion by 2031

NCC: Telcos complete over 5,000 sites as Nigeria’s coverage expansion hits 40% milestone

Flutterwave, Tempo alliance eyes Stablecoin cross-border payments

FG launches Innovation Hub at OAU to boost tech talent development

Nigeria mullls fibre-connected police stations with AI investigative tools 

NCC names Emiko as interim DBI board chairman

While investigating MoonBounce, Kaspersky says its researchers uncovered several malicious loaders and post-exploitation malware across several nodes of the same network.

“This includes ScrambleCross or Sidewalk, an in-memory implant that can communicate to a C2 server to exchange information and execute additional plugins, Mimikat_ssp, a publicly available post-exploitation tool used to dump credentials and security secrets, a formerly unknown Golang based backdoor, and Microcin, malware that is typically used by the SixLittleMonkeys threat actor.

“It could be that MoonBounce downloads these pieces of malware or that previous infection by one of these pieces of malware serves as way of compromising the machine so that MoonBounce can gain a foothold in the network. Another possible infection method for MoonBounce would be if the machine was compromised before it was supplied to the target company. In either case, it is assessed that the infection occurs through remote access to the targeted machine. In addition, while LoJax and MosaicRegressor utilised additions of DXE drivers, MoonBounce modifies an existing firmware component for a more subtle and stealthier attack”, according to Kaspersky.

In order to stay protected from UEFI bootkits like MoonBounce, Kaspersky recommends:

· Provide your SOC team with access to the latest threat intelligence (TI). The Kaspersky Threat Intelligence Portal is a single point of access for the company’s TI, providing cyberattack data and insights gathered by Kaspersky over more than 20 years.

· For endpoint level detection, investigation, and timely remediation of incidents implement EDR solutions;

· Use a robust endpoint security product that can detect the use of firmware, such as Kaspersky Endpoint Security for Business.

· Regularly update your UEFI firmware and only use firmware from trusted vendors.

· Enable Secure Boot by default, notably BootGuard and TPMs where applicable

Stay ahead with real-time reports, breaking news, and exclusive insights delivered directly to your phone. Don't settle for outdated information. Join TECHNOLOGYTIMES NEWS on WhatsApp for 24/7 updates.

Join Our Whatsapp Channel
Share20Tweet12Share3SendShare
Previous Post

Survey: 94% of Nigerian children Interested in Information Technology

Next Post

Huawei Mobile Cloud Unfold Free Storage for Mobile Users

Technology Times Staff

Technology Times Staff

News and Reports from Technology Times Newsroom. Call/SMS/WhatsApp: +234 815 7000 100

Related Posts

nigeria-weighs-social-media-age-restrictions
News

Nigeria weighs social media age restrictions as NDPC begins polls

byIretomiwa Balogun
10/03/2026
cybersecurity-tops-borno-digital-transformation
News

Cybersecurity tops Borno’s agenda as state pushes digital transformation

byOladapo Riliwan
12/12/2025
ex-africa-prudential-ceo-heads-heirs-technologies
News

Former Africa Prudential CEO to lead Heirs Technologies 

byTechnology Times Staff
14/03/2024
The business team of the social networking service, Skype has announced that Skype for Business now secures messages and chats as well as improve mobility with the integration of Intune.
Consumer Technology

Skype for Business ‘locks’ messages, chats with Intune

byElizabeth Edozie
07/05/2016
NY State Computer and Cyber Crime Defense Attorney
News

Nigerian tech security body, Microsoft join forces on cyber security

byDonatus Anichukwueze
09/11/2016
BlackBerry
Consumer Technology

Globacom repackages VAS bundles

byKayode Oladeinde
13/07/2015
Google Logo
News

US gay marriage ruling spikes Google searches

byKayode Oladeinde
29/06/2015
iPhone6s
News

Natcom ties content pact with Nigeria’s mobile operators

byOluwaseun Balogun
22/01/2016
elon-musk-obeys-order-starlink-nigeria-naira
News

Elon Musk bows to NCC order to charge Starlink Nigeria subscribers in Naira

byTechnology Times Staff
22/02/2023
nigeria-5g-auction-what-operators-stakeholders-think
Market Updates

Huawei, Jumia to launch Huawei G Power smartphone in Nigeria

byKayode Oladeinde
12/07/2016
Next Post
huawei-mobile-cloud-opens-free-storage

Huawei Mobile Cloud Unfold Free Storage for Mobile Users

Buhari on National Policy on 5G for Nigeria

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

7 + 2 =

Latest Articles

airtel-digital-literacy-slows-digital-inclusion

Airtel: Affordability, digital literacy gaps slow Africa’s digital inclusion

11/06/2026
nigeria-vp-backs-digital-education-expansion

VP backs expansion of digital education programme reaching 72,000 Nigerian students

11/06/2026
imf-wants-nigeria-regulate-stablecoins-crypto

IMF wants Nigeria to bring stablecoins, crypto under stronger regulation

11/06/2026
nigeria-eyes-ai-iot-to-transform-electricity

Nigeria eyes AI, IoT to transform electricity sector

10/06/2026
nigerias-data-centre-to-surpass-1-bn-by-2031

Nigeria’s data centre market to surpass $1 billion by 2031

10/06/2026
ADVERTISEMENT
CrownCrystal Technologies CrownCrystal Technologies CrownCrystal Technologies
ADVERTISEMENT
ADVERTISEMENT

Most Read

  • nucap-china-eyes-nigerias-plan-to-connect-20-m

    China eyes stake in Nigeria’s plan to connect 20 million unserved citizens

    65 shares
    Share 26 Tweet 16
  • Unlimited mobile data doesn’t exist anywhere, MTN CEO tells Nigerians

    61 shares
    Share 24 Tweet 15
  • NCC: Telcos complete over 5,000 sites as Nigeria’s coverage expansion hits 40% milestone

    60 shares
    Share 24 Tweet 15
  • Nigeria’s AI future depends on strong digital infrastructure, ex-NITDA Director says

    60 shares
    Share 24 Tweet 15
  • Nigeria’s data centre market to surpass $1 billion by 2031

    59 shares
    Share 24 Tweet 15
  • MTN sets Q3 Nigeria launch for fintech super-app, unveils new TV service

    57 shares
    Share 23 Tweet 14
  • MTN Nigeria says TikTok, HD streaming, auto backups cause fast data depletion

    56 shares
    Share 22 Tweet 14
  • Flutterwave, Tempo alliance eyes Stablecoin cross-border payments

    55 shares
    Share 22 Tweet 14
  • NIPOST inks landmark Zonos deal to ease Nigerian exports to U.S. market

    702 shares
    Share 281 Tweet 176
  • FG launches Innovation Hub at OAU to boost tech talent development

    54 shares
    Share 22 Tweet 14
eGovernance Nigeria Magazine eGovernance Nigeria Magazine eGovernance Nigeria Magazine
ADVERTISEMENT

Latest Videos

  • TT TV
data-privacy-and-nigerias-online-consumers

Data privacy and Nigeria’s online consumers | Technology Times Live TV

11/08/2025
9mobile Rebranding Livestream | Technology Meets Tenacity | Technology Times Live

9mobile Rebranding Livestream | Technology Meets Tenacity | Technology Times Live

08/08/2025
teniola-advocates-dynamic-billing-for-nigerians

Teniola advocates dynamic billing to protect Nigerian consumers | Technology Times Policy eXchange

14/04/2025
watch-mtn-nigeria-board-lawsuit-interview

#Watch: MTN Nigeria’s board is filled with ex-regulators—is this a conflict of interest?

24/03/2025
engr-banjo-on-local-content-in-nigeris-telecoms

Watch: Engr. Banjo on local content in Nigeria’s telecoms market

23/03/2025
Load More
Facebook Twitter Youtube LinkedIn RSS

ABOUT TECHNOLOGY TIMES

technology-times-logo

Nigeria Technology Media Group

Founded in 2004, Technology Times’ trusted technology news, market intelligence, views and business services reach readers and partners across Nigeria, Africa and beyond.

Advertising

Sign up for TT eNews

Get in touch here

CONTACT US

WhatsApp: +234 201 454 1818
WhatsApp: +234 815 700 0100
Email: info@technologytimes.ng
Web: www.technologytimes.ng

LEGAL & COMPLIANCE

technology-times-logoHome

TT Privacy Policy

TT Terms & Conditions

TT Website Disclaimer

TT Guest Post Guidelines

TT Sitemap

VOffice

  • credicorp-portal-for-nigeria-consumer-credit

    CREDICORP: FG opens portal on www.credicorp.ng for Nigerians to access consumer credit

    15755 shares
    Share 6302 Tweet 3939
  • CUG: NCC caps call rate at ₦50, bans data bundling

    5066 shares
    Share 2026 Tweet 1267
  • 9mobile rebrands today, targets multibillion-naira comeback in mobile market

    4426 shares
    Share 1770 Tweet 1107
  • Exclusive: Boardroom battle erupts at 9mobile, threatens spectrum trade deal with MTN

    3896 shares
    Share 1558 Tweet 974

©2004-2025 Technology Times, owned and operated by Digital Transformation Media Limited (DTML), Nigeria or its affiliates. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Add as a preferred source on Google
Add as preferred source on Google
No Result
View All Result
  • Big Story
  • News
    • News
    • Consumer Technology
    • Market Updates
    • Technology Insights
  • Interviews
  • Opinion
  • Digital Transformation Series
  • Special Reports
    • MWC Africa
    • Nigeria 5G Spectrum Auction
  • Login
  • Sign Up

©2004-2025 Technology Times, owned and operated by Digital Transformation Media Limited (DTML), Nigeria or its affiliates. All rights reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy Page.