{"id":182350,"date":"2022-01-24T16:59:49","date_gmt":"2022-01-24T15:59:49","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=182350"},"modified":"2025-07-01T20:58:41","modified_gmt":"2025-07-02T03:58:41","slug":"moonbounce-malware-survives-os-reinstallations","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/moonbounce-malware-survives-os-reinstallations\/","title":{"rendered":"MoonBounce malware survives OS reinstallations"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">As many of you may know, specifically if you\u2019ve had <strong>malware issues<\/strong> on your PC, reinstalling your operating system usually does the trick in removing the malicious content. However, it appears that MoonBounce is a new strain that lives in the computer\u2019s memory and UEFI firmware. What this means is that it will <strong>carry over into the OS reinstallation<\/strong>, as it doesn\u2019t store files on the hard drive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The discovery was made by <a href=\"https:\/\/kaspersky-anti-virus.en.softonic.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Kaspersky<\/a>, a company noted for anti-malware and antivirus software. It started when they noted a PC infected by malware with no idea how it got there. With further investigation, it became clear that it <strong>hid in the system\u2019s UEFI firmware<\/strong>, which is why scanning the storage drives didn\u2019t work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, this isn\u2019t the first time that UEFI malware has been discovered. Lojax appeared in 2018 and Mosaic Regressor in 2020. Kaspersky indicates that MoonBounce is more potent, as it has a workflow system that\u2019s more complicated to unravel. It also has <strong>advanced technical sophistication<\/strong>, which is tech terminology for saying it\u2019s incredibly intelligent.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"852\" height=\"698\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2022\/01\/MoonBounce-malware-survives-OS-reinstallations-1.jpg\" alt=\"MoonBounce malware survives OS reinstallations\" class=\"wp-image-182351\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/01\/MoonBounce-malware-survives-OS-reinstallations-1.jpg 852w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/01\/MoonBounce-malware-survives-OS-reinstallations-1-300x246.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/01\/MoonBounce-malware-survives-OS-reinstallations-1-768x629.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/01\/MoonBounce-malware-survives-OS-reinstallations-1-150x123.jpg 150w\" sizes=\"auto, (max-width: 852px) 100vw, 852px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">How MoonBounce works is by placing malware in the CORE_DXE section of the UEFI firmware. It\u2019s the central part that boots your computer. When the PC tries to call certain functions, it releases commands that infect your operating system. So even if you reinstall the OS, it will just repeat this process.<br><a href=\"https:\/\/usa.kaspersky.com\/about\/press-releases\/2022_kaspersky-uncovers-third-known-firmware-bootkit\" target=\"_blank\" rel=\"noreferrer noopener\">Kaspersky is working on ways<\/a> to <strong>detect and remove UEFI malware<\/strong> like MoonBounce with bootkit and firmware scanners. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since it doesn\u2019t leave any trace of infection on hard drives, it appears to be the best solution going forward. Until then, we recommend you update your UEFI firmware in the BIOS. To do so, simply check out the website of your motherboard\u2019s manufacturer for the latest releases.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As many of you may know, specifically if you\u2019ve had malware issues on your PC, reinstalling your operating system usually does the trick in removing the malicious content. However, it appears that MoonBounce is a new strain that lives in the computer\u2019s memory and UEFI firmware. What this means is that it will carry over &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/moonbounce-malware-survives-os-reinstallations\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;MoonBounce malware survives OS reinstallations&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9205,"featured_media":182352,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-182350","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/182350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9205"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=182350"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/182350\/revisions"}],"predecessor-version":[{"id":324502,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/182350\/revisions\/324502"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/182352"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=182350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=182350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=182350"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=182350"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=182350"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=182350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}