You've Already Been Hacked: What if There Is a Backdoor in Your UEFI OROM?
You’re only 3 weeks away from a new language
Finance Certifications Goldman Sachs and Amazon Teams Trust
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This 34-minute Black Hat conference talk explores the underexamined threat of backdoors in UEFI Option ROM (OROM). Discover how OROM backdoors differ from previous research that only used OROM for persistence or lateral movement. Learn about the specific capabilities and infection scenarios of dedicated OROM backdoors, with demonstrations of three novel proof-of-concept backdoors targeting Windows systems. Examine advanced evasion techniques including C2 server communication during boot, malicious code execution at kernel and userland levels through runtime DXE drivers, concealment of malicious tasks during boot, and bypassing security controls using partial identity mapping. Gain insights into defensive strategies against these sophisticated threats and understand the research initiatives needed to protect systems from UEFI OROM backdoors. Presented by Kazuki Matsuo, Security Researcher from Waseda University and FFRI Security.
Syllabus
You've Already Been Hacked: What if There Is a Backdoor in Your UEFI OROM?
Taught by
Black Hat