Program

/

CODE BLUE 2026

Time Table

Shade Core: Bringing UEFI Attacks Back to Hypervisor-Protected Modern PCs

UEFI malware is a threat to enterprise endpoints in contexts such as national security. However, as platform security has advanced, many existing UEFI attacks are no longer effective on modern PCs. Hypervisor-based security (HBS) is now enabled by default, and as SMM have been deprivileged, few attacks remain capable of bypassing HBS. Even those are fragile, hypervisor-specific, and easily broken by implementation changes.

In this talk, we present Shade Core, a generic technique for bypassing HBS under any hypervisor. We also introduce Shading Attacks, a new class of BIOS attacks that includes Shade Core. Unlike conventional BIOS attacks, which modify components such as the OS or hypervisor, Shading Attacks require no modification of any post-BIOS component.

This presentation provides analysts with a structured understanding of BIOS malware capabilities against modern PCs, and offers defenders insight into detecting this new class of attacks.

  • Location :

    • Track 1(HALL B)

  • Category :

    • Technical

  • Share :

Speakers

  • 松尾 和輝 の写真

    Kazuki Matsuo

    松尾 和輝

    Kazuki Matsuo (@InfPCTechStack) is a security researcher at FFRI Security, Inc., specializing in UEFI BIOS security. He is the founder of Ring Minus Security (@RingMinus), a community dedicated to below-OS security. His work focuses on negative-ring components, including BIOS, hypervisors, and SMM. He presented his research on backdoors in Option ROMs at Black Hat USA 2024 Briefings, and introduced Shade BIOS, a UEFI-level attack fully independent of antivirus software and OS security, at Black Hat USA 2025 Briefings.