Trickbot malware has been updated with a bootkit module, nicknamed Trickboot, which can search for UEFI/BIOS vulnerabilities. These flaws, if exploited, can give an attacker the ability to brick a device. Trickbot is generally distributed “as-a-service” with Symantec attributing its use to the Wizard Spider group. Trickboot’s operators likely are now in reconnaissance mode, according to a report from security firms Eclypsium and Advanced Intelligence. The vulnerabilities that Trickboot can spot for exploitation are located in the platform controller hub on Intel platforms.”]
Source: https://www.govinfosecurity.com/trickbot-now-uses-bootkit-to-attack-firmware-a-15517