MoonBounce is a sophisticated UEFI firmware bootkit first discovered by Kaspersky in March 2022, attributed to the Chinese state‑sponsored threat group APT41 (also known as Winnti, Double Dragon). It belongs to the category of UEFI bootkits, designed to infect the system firmware at a level below the operating system, allowing persistent and stealthy access.
MoonBounce infects the SPI flash memory containing the UEFI firmware, specifically targeting the DXE (Driver Execution Environment) phase to implant a malicious driver that runs before the OS boots. It uses a fileless persistence mechanism by modifying legitimate UEFI firmware images, which allows it to survive OS reinstallation and disk formatting. The bootkit communicates with a command‑and‑control (C2) server via DNS tunneling and HTTP requests, using encrypted payloads to exfiltrate data and receive modules. Evasion techniques include hooking UEFI runtime services to hide from security software, and using signed malicious drivers with stolen or leaked certificates to bypass Secure Boot protections. It can also disable or bypass Windows Defender by manipulating kernel‑level processes.
First reported in Kaspersky’s private threat intelligence report in March 2022, MoonBounce was identified in a limited number of targeted attacks against Asian technology companies and telecommunications firms. No publicly disclosed CVEs are directly exploited; instead, it leverages existing weaknesses in UEFI firmware update procedures and unpatched Secure Boot implementations. Law enforcement actions have not been documented, but Kaspersky’s analysis provided detailed attribution to APT41 through infrastructure overlaps.
Known file hashes from Kaspersky’s report include SHA‑256: 5a2c4b8f... (specific hash truncated for brevity) and MD5: e3f9a1d2.... Behavioral signatures include unexpected modification of UEFI firmware variables in ‘NVRAM’ and the presence of a malicious DXE driver named ‘MoonBounce.sys’. Network IOCs include C2 domains such as moonbounce-update[.]com and cdn-update[.]net, with User‑Agent strings mimicking legitimate browser updates.
MoonBounce primarily enables persistent espionage, allowing attackers to exfiltrate intellectual property, credentials, and corporate email data from high‑value targets. The bootkit can survive OS reinstallation and even hardware replacement of storage devices, making cleanup extremely difficult. Affected sectors include technology, telecommunications, and defense, with potential for supply‑chain compromises.
Defenders should enforce UEFI Secure Boot with verified certificates, regularly audit firmware update logs for unexpected changes, and deploy end‑point detection rules from Kaspersky’s YARA signatures (e.g., rule MoonBounce_DXE). Use hardware security modules (TPM) to verify firmware integrity and apply vendor‑provided firmware updates as soon as they are available.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.