MosaicRegressor is a modular espionage malware framework associated with a rare in-the-wild UEFI bootkit deployment. It was used in targeted operations from 2017 to 2019 against diplomats and non-governmental organization personnel in Africa, Asia, and Europe, with identified victims showing ties to North Korea. The framework is notable for combining conventional multi-stage malware delivery with firmware-level persistence on a small subset of victims. The UEFI component of MosaicRegressor resided in SPI flash and survived operating system reinstallation and hard drive replacement. Its bootkit functionality was built largely from Hacking Team’s leaked VectorEDK codebase with minor customization. The implant used rogue UEFI modules, including DXE drivers and UEFI applications, to execute before the operating system bootloader, locate the Windows installation, drop a user-mode payload into the Windows Startup folder, and restore that payload if it was removed. This gave the operator highly durable persistence and a reliable mechanism to redeploy malware from firmware. Beyond the firmware implant, MosaicRegressor operated as a multi-stage, modular framework for espionage and data collection. Observed downloader and loader variants retrieved additional payloads over multiple channels, including HTTP and HTTPS libraries, BITS, WinHTTP, and email-based transport using standard mail protocols. Later-stage components included payloads designed to collect and archive victim files. Delivery in some cases used decoy documents themed around North Korea. Victimology indicates a focused espionage campaign against diplomatic entities and NGOs rather than broad criminal targeting. Public reporting has described low-confidence attribution to a Chinese-speaking actor based on language artifacts and limited infrastructure overlap with activity previously linked to Winnti-associated clusters, but this attribution remains unconfirmed. MosaicRegressor is therefore best characterized as an advanced espionage framework with unusual firmware persistence capability rather than a financially motivated or ransomware-oriented operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UEFI implant/rootkit example using an added DXE module to maintain persistence and redeploy an agent during boot.
A UEFI bootkit family observed in the wild. The article notes its infection vector is unknown and highlights substantial code reuse from Hacking Team’s Vector-EDK, with execution beginning from DXE drivers that register a callback for EFI_EVENT_GROUP_READY_TO_BOOT.
A multi-stage, modular espionage and data-gathering framework used in targeted attacks against diplomats and NGO members connected to North Korea. It used downloaders and intermediate loaders to fetch payloads, including a document stealer, and in some cases was deployed via a malicious UEFI implant for persistence.
Modular, multi-stage espionage/data-gathering framework delivered via multiple initial downloader variants (e.g., HTTP(S) via cURL/WinHTTP, BITS, and email-based POP3S/SMTPS/IMAPS). In at least two cases, a UEFI firmware implant (VectorEDK-derived) was used as a persistent dropper to reinstall a Windows startup payload (IntelUpdate.exe).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.