Thunderstrike is Apple Mac EFI/UEFI firmware malware/rootkit activity referenced in the provided content as a firmware attack requiring physical access. It is discussed in the context of Apple EFI security research and later follow-on work such as Thunderstrike 2. The content states that Thunderstrike demonstrated practical firmware attack paths on Macs, including an Option ROM-based worm in Thunderstrike 2, and highlights Apple’s lack of signed Option ROM enforcement as a security concern. In the supplied material, Thunderstrike is contrasted with the separately named "Prince Harming" flash-lock vulnerability: Thunderstrike required physical access, whereas Prince Harming enabled remote attack scenarios on vulnerable Macs. More broadly, the surrounding content describes EFI/UEFI malware on Apple systems as capable of diskless persistence across OS reinstalls, boot redirection, kernel patching during boot, bypassing full-disk encryption via keylogging, and supporting stealthy firmware compromise, but those capabilities are described for EFI malware/rootkits generally rather than attributed specifically and exclusively to Thunderstrike.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A firmware-level Apple/UEFI attack and rootkit concept referenced as requiring physical access, used for persistence below the operating system.
An EFI/UEFI rootkit referenced as requiring physical access to compromise Apple firmware, used as a comparison point for a more remotely exploitable firmware attack.
A firmware/UEFI attack framework targeting Apple systems, discussed as requiring physical access in its original form and later extended in Thunderstrike 2 with remote attack vectors and an Option ROM worm capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.