MoonBounce

From Wikipedia, the free encyclopedia

ClassificationRootkit
AuthorAPT41
MoonBounce
Malware details
TypeBootkit
ClassificationRootkit
AuthorAPT41
Technical details
PlatformMicrosoft Windows

MoonBounce is a UEFI firmware-based rootkit. It is linked to the Chinese APT41 hacker group. MoonBounce was discovered by the researchers at Kaspersky in 2021.[1] It can disable Windows security tools and bypass User Account Control.[2]

Data shows that the attacks are highly targeted.[3] The malware is a landmark in UEFI rootkit evolution.[4] It is the third known malware UEFI bootkit found.[citation needed]

References

Related Articles

Wikiwand AI