Researchers uncovered compromised UEFI firmware images carrying a malicious implant that persisted in SPI flash and deployed a previously unseen malware family dubbed MosaicRegressor. The rogue firmware reused and modified components from Hacking Team’s leaked VectorEDK UEFI bootkit to drop IntelUpdate.exe into the Windows Startup folder and restore it if deleted, giving attackers durable access below the operating system. The finding followed earlier public reporting on LoJax, the first UEFI rootkit observed in the wild, underscoring that firmware-level persistence had moved from theory to active operations.
The malware framework was used in targeted espionage campaigns from 2017 to 2019 against diplomats and NGO members in Africa, Asia, and Europe, with identified victims linked to North Korea. MosaicRegressor operated as a modular, multi-stage platform using multiple downloaders over HTTP/HTTPS, BITS, WinHTTP, and even mail.ru email accounts to retrieve payloads. Attribution remained low confidence, but researchers cited Chinese-language artifacts, a Royal Road weaponized document, and infrastructure overlap with activity associated with the Winnti umbrella, suggesting possible ties to a Chinese-speaking threat actor.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Securelist published research describing compromised UEFI firmware images that deployed the newly named MosaicRegressor malware framework. The report linked the activity to targeted espionage from 2017 to 2019 and assessed with low confidence that a Chinese-speaking actor was responsible.
Researchers confirmed that two victims were infected with the malicious UEFI bootkit in 2019, before deployment of the BitsReg component. The implant persisted in SPI flash and dropped IntelUpdate.exe into the Windows Startup folder.
ESET published research on LoJax, identifying it as the first publicly known UEFI rootkit found in the wild. Later MosaicRegressor reporting described its own UEFI implant as the second such publicly known case.
An intelligence report on the Winnti umbrella and associated state-sponsored attackers was published, providing background later referenced in MosaicRegressor attribution analysis through infrastructure overlap.
Telemetry showed several dozen victims received MosaicRegressor components during this period. The victims included diplomatic entities and NGOs in Africa, Asia, and Europe, all with some connection to North Korea.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 73 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcewelivesecurity.com
Open source401trg.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.