CosmicStrand

  • First known sample

    2016
  • Discovery

    2022
  • Number of targets

    1-100
  • Current status

    –°onsidered active
  • Type

    Firmware rootkit
  • Targeted platforms

    Windows
  • TOP targeted countries

    China , Iran , Russia , Vietnam
  • The way of propagation

    Exploits , Supply-chain attack
  • Purpose/Functions

    Install additional malicious payload
  • Implant

    CosmicStrand UEFI implant 

  • Description

    CosmicStrand is a rootkit developed by an advanced persistent threat (APT) actor that stays on the victim’s machine even if the operating system is rebooted or Windows is reinstalled – making it very dangerous in the long run. It was used mainly to attack private individuals.

    The UEFI firmware is a critical component in the vast majority of hardware. If it is somehow modified to contain malicious code, its activity can be potentially invisible to security solutions and to the operating system’s defenses. Regardless of how many times the operating system is reinstalled, the malware will stay on the device.

    CosmicStrand: the discovery of a sophisticated UEFI firmware rootkit