• Big Story
  • News
    • News
    • Consumer Technology
    • Market Updates
    • Technology Insights
  • Interviews
  • Opinion
  • Digital Transformation Series
  • Special Reports
    • MWC Africa
    • Nigeria 5G Spectrum Auction
Thursday, November 13, 2025
  • Login
  • Register
Technology Times | Latest and Breaking Nigeria Tech News
No Result
View All Result
Technology Times | Latest and Breaking Nigeria Tech News
No Result
View All Result
Technology Times | Latest and Breaking Nigeria Tech News
No Result
View All Result
Your text
Remita Remita Remita
ADVERTISEMENT
ADVERTISEMENT

MoonBounce, ‘More Elusive’ Firmware on Rampage, Computer Users Warned

Technology Times StaffbyTechnology Times Staff
24/01/2022
in News
Reading Time: 3 mins read
1 0
A A
0
moonbounce-firmware-on-rampage-kaspersky

Tech savvy young Nigerian pictured using a Lenovo laptop in Lagos

ADVERTISEMENT

MoonBounce, a rampaging firmware declared “more elusive” because its malicious implant can hide within essential parts of computers, Kaspersky, a cybersecurity firm, has alerted users.

Kaspersky says its researchers have uncovered the third case the firmware bootkit in the wild that is able to hide within a computer’s Unified Extensible Firmware MoonBounce, the cybersecurity firm says is “more elusive and more persistent” and third known firmware bootkit “shows major advancement.”

“MoonBounce demonstrates a sophisticated attack flow, with evident advancement in comparison to formerly reported UEFI firmware bootkits. The campaign has been attributed with considerable confidence to the well-known advanced persistent threat (APT) actor APT41”, according to the tech firm.

moonbounce-firmware-on-rampage-kaspersky
Technology Times file photo shows a lady working on a laptop computer. The rampaging MoonBouncee firmware hides inside essential parts of the computer, Kaspersky says.

Inside MoonBounce, The Elusive Firmware Difficult To Delete

“UEFI firmware is a critical component in the vast majority of machines” according to the Kaspersky alert which says that “its code is responsible for booting up the device and passing control to the software that loads the operating system.

“This code rests in what’s called SPI flash, a non-volatile storage external to the hard disk. If this firmware contains malicious code, then this code will be launched before the operating system, making malware implanted by a firmware bootkit especially difficult to delete; it can’t be removed simply by reformatting a hard drive or reinstalling an OS. What’s more, because the code is located outside of the hard drive, such bootkits’ activity go virtually undetected by most security solutions unless they have a feature that specifically scans this part of the device”, the tech security firm says.
Accordingly “the implant rests in the CORE_DXE component of the firmware, which is called upon early during the UEFI boot sequence. Then, through a series of hooks that intercept certain functions, the implant’s components make their way into the operating system, where they reach out to a command & control server in order to retrieve further malicious payloads, which we were unable to retrieve. It’s worth noting that the infection chain itself does not leave any traces on the hard drive, as its components operate in memory only, thus facilitating a fileless attack with a small footprint.

“While we can’t definitely connect the additional malware implants found during our investigation with MoonBounce specifically, it does appear as if some Chinese-speaking threat actors are sharing tools with one other to aid in their various campaigns; there especially seems to be a low confidence connection between MoonBounce and Microcin,” adds Denis Legezo, senior security researcher with GReAT says.

Kaspersky says it “has attributed MoonBounce with considerable confidence to APT41, which has been widely reported to be a Chinese-speaking threat actor that’s conducted cyberespionage and cybercrime campaigns around the world since at least 2012. In addition, the existence of some of the aforementioned malware in the same network suggests a possible connection between APT41 and other Chinese-speaking threat actors.”

While investigating MoonBounce, Kaspersky says its researchers uncovered several malicious loaders and post-exploitation malware across several nodes of the same network.

“This includes ScrambleCross or Sidewalk, an in-memory implant that can communicate to a C2 server to exchange information and execute additional plugins, Mimikat_ssp, a publicly available post-exploitation tool used to dump credentials and security secrets, a formerly unknown Golang based backdoor, and Microcin, malware that is typically used by the SixLittleMonkeys threat actor.

“It could be that MoonBounce downloads these pieces of malware or that previous infection by one of these pieces of malware serves as way of compromising the machine so that MoonBounce can gain a foothold in the network. Another possible infection method for MoonBounce would be if the machine was compromised before it was supplied to the target company. In either case, it is assessed that the infection occurs through remote access to the targeted machine. In addition, while LoJax and MosaicRegressor utilised additions of DXE drivers, MoonBounce modifies an existing firmware component for a more subtle and stealthier attack”, according to Kaspersky.

In order to stay protected from UEFI bootkits like MoonBounce, Kaspersky recommends:

· Provide your SOC team with access to the latest threat intelligence (TI). The Kaspersky Threat Intelligence Portal is a single point of access for the company’s TI, providing cyberattack data and insights gathered by Kaspersky over more than 20 years.

· For endpoint level detection, investigation, and timely remediation of incidents implement EDR solutions;

· Use a robust endpoint security product that can detect the use of firmware, such as Kaspersky Endpoint Security for Business.

· Regularly update your UEFI firmware and only use firmware from trusted vendors.

Related Articles

FG targets paperless cabinet by December 2025 in digital governance push

Nigeria to unlock ₦14.38trn from digital economy reforms 

Nigeria upgrades tertiary connectivity: NgREN now linked with TERAS platform

AfDIC plans to onboard 30 million artisans on unified digital platform 

Moniepoint unveils ‘M’, AI chatbot to offer insights into Nigeria’s informal economy

FG plans WhatsApp AI chatbot for Nigerian youths 

Nigeria’s ex-cybersecurity director flags ‘structural and regulatory misalignments’ of National Digital Economy and e-Governance Bill 2025

Equinix commits ₦143.6 billion to transform Africa’s digital infrastructure, anchors expansion in Nigeria

Exclusive: ITAN pushes for Naira payments on global tech certifications

FG spotlights Startcoin as model for youth inclusion, innovation in digital economy 

· Enable Secure Boot by default, notably BootGuard and TPMs where applicable

Share20Tweet12Share3SendShare
Previous Post

Survey: 94% of Nigerian children Interested in Information Technology

Next Post

Huawei Mobile Cloud Unfold Free Storage for Mobile Users

Technology Times Staff

Technology Times Staff

News and Reports from Technology Times Newsroom. Call/SMS/WhatsApp: +234 815 7000 100

Related Posts

efcc-nabs-792-romance-crypto-scammers
News

EFCC nabs 792 suspects linked with crypto and romance scams

bySarah Emeka
17/12/2024
Technology Times file photo shows people seen taking selfies on a smartphone at a phone lauch event held in Lagos
Market Updates

World mobile group rejects communication tax plans in Nigeria

bySuccess Kafoi
19/10/2016
mtn-bayobab-leads-restoration-efforts-of-undersea-cable-cuts
News

MTN Group’s Bayobab begins connectivity restoration amidst undersea cable cuts

byFejiro Awowede
15/03/2024
Sponsored data
News

TT Polls: Should NCC fine GSM networks for poor service quality?

byTechnology Times Staff
23/05/2014
Galaxy Backbone says that ongoing road works in Nasarawa state that damaged its optical fibre cables also affected Internet users in parts of the country, including Lagos.
The Big Story

Nasarawa road works caused optical cable damage, Galaxy Backbone says

byTechnology Times Staff
23/02/2020
ITU, UN Women to reward technology for gender equality initiatives
News

ITU, UN Women to reward technology for gender equality initiatives

byKayode Oladeinde
24/07/2014
Nigeria Internet customers
News

ITU: 90% of Internet’s unconnected ‘live in developing countries’

byKayode Oladeinde
26/11/2014
nigeria-ngcert-warns-of-zimbra-email-threats
News

Data Theft: Nigeria’s ngCERT warns of zimbra email vulnerability

byOladapo Riliwan
12/03/2025
BBM finally goes live on Windows Phone
Consumer Technology

BBM to offer person-to-person airtime transfer in Nigeria

byKayode Oladeinde
19/09/2014
Nokia Lumia 930
News

Nokia maker raises N36 billion for next growth phase

byTechnology Times Contributor
28/05/2018
Next Post
huawei-mobile-cloud-opens-free-storage

Huawei Mobile Cloud Unfold Free Storage for Mobile Users

Buhari on National Policy on 5G for Nigeria

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

three × five =

Latest Articles

fg-targets-paperless-cabinet-by-december-2025

FG targets paperless cabinet by December 2025 in digital governance push

12/11/2025
nigeria-unlock-₦14-38trn-from-digital-economy

Nigeria to unlock ₦14.38trn from digital economy reforms 

12/11/2025
nigeria-ngren-now-linked-with-teras-platform

Nigeria upgrades tertiary connectivity: NgREN now linked with TERAS platform

12/11/2025
afdic-onboard-30-million-artisans-on-platform

AfDIC plans to onboard 30 million artisans on unified digital platform 

12/11/2025
moniepoint-unveils-m-ai-chatbot-for-nigeria

Moniepoint unveils ‘M’, AI chatbot to offer insights into Nigeria’s informal economy

12/11/2025
CrownCrystal Technologies CrownCrystal Technologies CrownCrystal Technologies
ADVERTISEMENT
ADVERTISEMENT
eGovernance Nigeria Magazine eGovernance Nigeria Magazine eGovernance Nigeria Magazine
ADVERTISEMENT

POPULAR ARTICLES

  • nigeria-unlock-₦14-38trn-from-digital-economy

    Nigeria to unlock ₦14.38trn from digital economy reforms 

    54 shares
    Share 22 Tweet 14
  • FG targets paperless cabinet by December 2025 in digital governance push

    54 shares
    Share 22 Tweet 14
  • FG plans WhatsApp AI chatbot for Nigerian youths 

    52 shares
    Share 21 Tweet 13
  • Nigeria upgrades tertiary connectivity: NgREN now linked with TERAS platform

    52 shares
    Share 21 Tweet 13
  • Moniepoint unveils ‘M’, AI chatbot to offer insights into Nigeria’s informal economy

    54 shares
    Share 22 Tweet 14
  • Minister: In a world’s first, Nigeria establishes National AI Trust

    130 shares
    Share 52 Tweet 33
  • Nigeria eases renewals with contactless passport tech, NIS says

    62 shares
    Share 25 Tweet 16
  • Tecno Spark 30 Series Transformer edition debuts

    120 shares
    Share 48 Tweet 30
  • AfDIC plans to onboard 30 million artisans on unified digital platform 

    50 shares
    Share 20 Tweet 13
  • Nigeria’s ex-cybersecurity director flags ‘structural and regulatory misalignments’ of National Digital Economy and e-Governance Bill 2025

    65 shares
    Share 26 Tweet 16

Latest Videos

  • TT TV
data-privacy-and-nigerias-online-consumers

Data privacy and Nigeria’s online consumers | Technology Times Live TV

11/08/2025
9mobile Rebranding Livestream | Technology Meets Tenacity | Technology Times Live

9mobile Rebranding Livestream | Technology Meets Tenacity | Technology Times Live

08/08/2025
teniola-advocates-dynamic-billing-for-nigerians

Teniola advocates dynamic billing to protect Nigerian consumers | Technology Times Policy eXchange

14/04/2025
watch-mtn-nigeria-board-lawsuit-interview

#Watch: MTN Nigeria’s board is filled with ex-regulators—is this a conflict of interest?

24/03/2025
engr-banjo-on-local-content-in-nigeris-telecoms

Watch: Engr. Banjo on local content in Nigeria’s telecoms market

23/03/2025
Load More
Facebook Twitter Youtube LinkedIn RSS

ABOUT TECHNOLOGY TIMES

technology-times-logo

Nigeria Technology Media Group

Founded in 2004, Technology Times’ trusted technology news, market intelligence, views and business services reach readers and partners across Nigeria, Africa and beyond.

Advertising

Sign up for TT eNews

Get in touch here

CONTACT US

Phone: +234 (0) 1 454 1818
WhatsApp: +234 (0) 815 700 0100
Email: info@technologytimes.ng
Web: www.technologytimes.ng

LEGAL & COMPLIANCE

technology-times-logoHome

TT Privacy Policy

TT Terms & Conditions

TT Website Disclaimer

TT Guest Post Guidelines

TT Sitemap

VOffice

  • credicorp-portal-for-nigeria-consumer-credit

    CREDICORP: FG opens portal on www.credicorp.ng for Nigerians to access consumer credit

    15713 shares
    Share 6285 Tweet 3928
  • CUG: NCC caps call rate at ₦50, bans data bundling

    5054 shares
    Share 2022 Tweet 1264
  • 9mobile rebrands today, targets multibillion-naira comeback in mobile market

    4401 shares
    Share 1760 Tweet 1100
  • Exclusive: Boardroom battle erupts at 9mobile, threatens spectrum trade deal with MTN

    3883 shares
    Share 1553 Tweet 971

©2004-2025 Technology Times, owned and operated by Digital Transformation Media Limited (DTML), Nigeria or its affiliates. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Big Story
  • News
    • News
    • Consumer Technology
    • Market Updates
    • Technology Insights
  • Interviews
  • Opinion
  • Digital Transformation Series
  • Special Reports
    • MWC Africa
    • Nigeria 5G Spectrum Auction
  • Login
  • Sign Up

©2004-2025 Technology Times, owned and operated by Digital Transformation Media Limited (DTML), Nigeria or its affiliates. All rights reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy Page.