1⃣TrickBoot is only one line of code away from being able to brick any device it finds to be vulnerable.
2⃣Historically, TrickBot actors have needed to evade and persist at the OS level - now a chance at UEFI level.
3⃣Actors are going lower in the stack to avoid detection.
🕯️Tracking Since Early 2019 on my Git
@malwrhunterteam 💡This is probably the most solid connection to the Clop ransomware operation (".clop") to this lockdown.