A previously undocumented firmware implant has been linked to the Chinese-speaking Winnti advanced persistent threat group (APT41) Kaspersky says it’s the “most advanced UEFI firmware implant discovered in the wild to date” Firmware-based rootkits, once a rarity in the threat landscape, are fast becoming lucrative tools among sophisticated actors to help achieve long standing foothold in a manner that’s not only hard to detect, but also difficult to remove. The infection chain itself does not leave any traces on the hard drive, as its components operate in memory only, thus facilitating a fileless attack with a small footprint.”]
Source: https://thehackernews.com/2022/01/chinese-hackers-spotted-using-new-uefi.html