MoonBounce is a highly sophisticated UEFI firmware implant and bootkit targeting Windows systems. It resides in motherboard SPI flash and modifies the UEFI DXE Core rather than introducing a separate DXE driver, making it a rare and stealthy firmware-level threat. By executing during the DXE phase, MoonBounce gains control before the operating system loads and can persist across disk formatting, operating system reinstallation, and even disk replacement.
The implant establishes a multistage, largely memory-resident infection chain. It patches the DXE Core and installs inline hooks on EFI Boot Services functions including AllocatePool, CreateEventEx, and ExitBootServices. These hooks stage shellcode in memory, register boot-event callbacks, and tamper with the Windows boot path at the firmware-to-kernel transition. In pure UEFI boot scenarios, MoonBounce modifies the OS loader in memory and redirects execution during transfer to the Windows kernel. In kernel space, it locates ntoskrnl.exe, resolves kernel APIs via name hashing, alters section permissions, hooks ExAllocatePool, and manually maps a malicious driver into memory.
The kernel-stage driver then injects a user-mode stager into svchost.exe associated with the NETSVCS service group. That stager performs in-memory retrieval and execution of additional payloads over HTTP, enabling follow-on malware deployment without leaving conventional disk artifacts. Reported techniques associated with the chain include inline hooking, shellcode staging, PE manual mapping, APC-based injection, and memory-only payload execution.
MoonBounce has been linked with medium-to-high confidence to APT41, also known as Winnti, and is associated with long-term espionage activity. Reporting has connected affected environments with additional tooling such as SideWalk or ScrambleCross and with post-compromise behavior including reconnaissance, lateral movement, attempted directory database collection, staging for exfiltration, and artifact cleanup. Its design reflects deep knowledge of vendor-specific firmware internals and the Windows boot process.
MoonBounce is notable in the evolution of UEFI threats because it patches an existing benign firmware component instead of simply adding a malicious module. It is widely regarded as more advanced than earlier SPI-flash implants such as LoJax and MosaicRegressor. Classic Secure Boot does not directly prevent its core technique because the implant modifies in-memory reflections of boot components after loading, whereas stronger firmware integrity controls such as Intel Boot Guard and TPM-backed measurements are more relevant mitigations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Bootkits usually targeted MBR/ESP in the early 2010s, but as the cost of firmware attack decreased rapidly, the modern bootkits started to target DXE or even PEI.
The purpose of the malicious driver is to inject user-mode malware into a Windows service of the network services group... The injection leverages the Windows APC (Asynchronous Procedure Call) mechanism.
The injection leverages the Windows APC (Asynchronous Procedure Call) mechanism through the following actions... the executed routine queues the PE-mapping shellcode with its own argument structure to the APC queue of the current thread running in the context of the injected svchost.exe process.
Typical targets are like kernel structures, device drivers, MBR or boot sectors, which they do with techniques SSDT hooking, DKOM, file hiding, process hiding, and rootkit loaders in kernel space.
The code locates the in-memory image base of ntoskrnl.exe, resolves critical kernel APIs via a name-hashing algorithm...
The user-mode malware stager... is a DLL packed with a common software tool called MPRESS.
The purpose of the malicious driver is to inject user-mode malware into a Windows service of the network services group... The injection leverages the Windows APC (Asynchronous Procedure Call) mechanism.
The injection leverages the Windows APC (Asynchronous Procedure Call) mechanism through the following actions... the executed routine queues the PE-mapping shellcode with its own argument structure to the APC queue of the current thread running in the context of the injected svchost.exe process.
The driver continues to inject an embedded PE image, corresponding to a user-mode malware stager, to the matching svchost.exe process.
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Bootkits usually targeted MBR/ESP in the early 2010s, but as the cost of firmware attack decreased rapidly, the modern bootkits started to target DXE or even PEI.
На данный момент мы можем выделить два вектора атаки на UEFI-платформу: перепрошивка SPI и модификация менеджера загрузки.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named UEFI bootkit cited as one of the newer firmware-resident threats.
A highly privileged malware example referenced in the context of UEFI bootkit threats that Secure Boot is designed to block early in the boot process.
UEFI firmware-resident implant that patches the DXE Core (inline hook) to execute very early in the boot/firmware execution path, enabling stealthy, below-OS persistence.
Highly advanced UEFI firmware implant that patches/modifies the DXE Core execution path (inline hook) to execute beneath OS-level controls across legacy and pure UEFI boot paths.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.