Researchers of ESET, they discovered a previously undocumented UEFI bootkit lurking in the EFI system partition (ESP)
The bootkit, which ESET has called ESPecter, is capable of bypassing Windows Driver Signature Enforcement and nesting its own driver in the firmware to steal sensitive information and data from compromised machines. ESPecter is the second known UEFI bootkit to hide in ESP and demonstrates how real threats are no longer limited to SPI flash implants, such as those used by Lojax, discovered by ESET in 2018.
ESPecter was discovered on a compromised machine with a client component with keylogging and document access capabilities, reinforcing ESET's belief that ESPecter is primarily used for espionage purposes.
"Interestingly, the origins of this threat date back to at least 2012; it previously operated as a bootkit for legacy BIOS systems. Although it has been known for some time, ESPecter, its operations and its update, have gone unnoticed and have not been documented until now," he says Anton Cherepanov, researcher at ESET who discovered and analyzed the threat together with your colleague Martin Smolár.
"Over the past few years, we have seen proof-of-concept cases of UEFI bootkits, leaked documents, and even stolen source code that suggest the existence of real UEFI malware in the form of SPI or ESP flash implants. Despite all this, only four real cases of UEFI malware have been discovered, including ESPecter," explains Cherepanov.
By examining ESET telemetry, researchers were able to trace the origins of this bootkit back to 2012. Interestingly, the components of the malware have barely changed in all these years, and the differences between the 2012 and 2020 versions are not as significant as one would expect. Despite this today the threat actors behind ESPecter have likely decided to move their malware from legacy BIOS systems to modern UEFI systems.
The second payload deployed by ESPecter is a backdoor that supports a rich set of commands and contains various automatic data exfiltration capabilities, including document theft, keylogging, and monitoring the victim's screen by periodically taking screenshots. All collected data is stored in a hidden directory.
“ESPecter demonstrates that threat actors rely on UEFI firmware implants when it comes to pre-OS persistence and, despite existing security systems such as UEFI Secure Boot, invest their time in creating malware that could easily be blocked by these same systems, if enabled and configured correctly,” adds Smolár.
To protect yourself from ESPecter or similar threats, ESET recommends users to follow these simple rules: always use the latest firmware version; ensure that the system is configured correctly and that Secure Boot is enabled; and configure Privileged Account Management to prevent attackers from accessing privileged accounts needed to install the bootkit.
More technical details on ESPecter, at that link su WeLiveSecurity.






