Shade Core: Bringing UEFI Attacks Back to Hypervisor-Protected Modern PCs
DAY 2
14:10-
14:50
UEFI malware is a threat to enterprise endpoints in contexts such as national security. However, as platform security has advanced, many existing UEFI attacks are no longer effective on modern PCs. Hypervisor-based security (HBS) is now enabled by default, and as SMM have been deprivileged, few attacks remain capable of bypassing HBS. Even those are fragile, hypervisor-specific, and easily broken by implementation changes.
In this talk, we present Shade Core, a generic technique for bypassing HBS under any hypervisor. We also introduce Shading Attacks, a new class of BIOS attacks that includes Shade Core. Unlike conventional BIOS attacks, which modify components such as the OS or hypervisor, Shading Attacks require no modification of any post-BIOS component.
This presentation provides analysts with a structured understanding of BIOS malware capabilities against modern PCs, and offers defenders insight into detecting this new class of attacks.
-
Location :
-
Track 1(HALL B)
-
-
Category :
-
Technical
-
-
Share :
Speakers
-
Kazuki Matsuo
松尾 和輝
Kazuki Matsuo (@InfPCTechStack) is a security researcher at FFRI Security, Inc., specializing in UEFI BIOS security. He is the founder of Ring Minus Security (@RingMinus), a community dedicated to below-OS security. His work focuses on negative-ring components, including BIOS, hypervisors, and SMM. He presented his research on backdoors in Option ROMs at Black Hat USA 2024 Briefings, and introduced Shade BIOS, a UEFI-level attack fully independent of antivirus software and OS security, at Black Hat USA 2025 Briefings.