Madshrimps Forum Madness

Madshrimps Forum Madness (https://www.madshrimps.be/vbulletin/)
-   WebNews (https://www.madshrimps.be/vbulletin/f22/)
-   -   Rootkit hits Windows Unified Extensible Firmware Interface (https://www.madshrimps.be/vbulletin/f22/rootkit-hits-windows-unified-extensible-firmware-interface-183393/)

Stefan Mileschin 3rd January 2019 07:42

Rootkit hits Windows Unified Extensible Firmware Interface
 
Found by Sednit hunters

Insecurity experts hunting cyber-spy outfit Sednit have discovered the first instance of a rootkit targeting the Windows Unified Extensible Firmware Interface (UEFI) in successful attacks.

According to Threatpost Frédéric Vachon, a malware researcher at ESET published a technical write-up on his findings and said that finding a rootkit targeting a system’s UEFI was significant.

It means that rootkit malware programs can survive on the motherboard’s flash memory, giving it persistence and stealth.

“UEFI rootkits have been researched and discussed heavily in the past few years, but sparse evidence has been presented of real campaigns actively trying to compromise systems at this level”, he said.

Nicknamed LoJax the rootkit is a modified version of Absolute Software’s LoJack recovery software for laptops. The legitimate LoJack software was supposed to help victims of a stolen laptop be able to access their PC without tipping off the bad guys who stole it. It hides on a system’s UEFI and stealthily beacons its whereabouts back to the owner for possible physical recovery of the laptop.

Absolute Software’s code dates to a vulnerable 2009 version, which had several key bugs which allowed Sednit to customise a single byte that contains the domain information for the legitimate software to connect to to download the recovery software.

The infection chain is typical: An attack begins with a phishing email or equivalent, successfully tricking a victim into downloading and executing a small rpcnetp.exe dropper agent. The rpcnetp.exe installs and reaches out to the system’s Internet Explorer browser, which is used to communicate with the configured domains.

https://fudzilla.com/news/47857-root...ware-interface


All times are GMT +1. The time now is 01:06.

Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO