Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

FarCenter

(19,429 posts)
Tue Dec 17, 2013, 05:46 PM Dec 2013

Researchers uncover first active BIOS rootkit attack

September 14, 2011

Researchers have discovered what is believed to be the first in-the-wild rootkit that targets BIOS, the built-in software responsible for booting up a computer and managing communication between the machine and its attached devices.

The discovery of Mebromi is notable not because any widespread infections are anticipated – the complexity of a successful attack on the motherboard is high – but because it appears to be the first malware written for the BIOS in at least four years, Webroot researcher Marco Giuliani, who studied the threat, said in a blog post Tuesday.

The potent malware cocktail, consisting of a BIOS rootkit, an MBR (master boot record) rootkit, a kernel-mode rookit, a PE (portable executable) file infector and a trojan downloader, is designed to evade anti-virus detection.

Right now, the active attack exclusively is targeting Chinese users, Giuliani said. The trojan dropper is designed to first infect Award BIOS, manufactured by Phoenix Technologies. Once the BIOS is infected, the malicious code compromises the master boot record, a small program initiated when a computer starts up.

...

The Chinese security firm Qihoo 360 first detected the attack, according to Webroot.


http://www.scmagazine.com/researchers-uncover-first-active-bios-rootkit-attack/article/212035/
2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Researchers uncover first active BIOS rootkit attack (Original Post) FarCenter Dec 2013 OP
Fort Meade Says hi Jesus Malverde Dec 2013 #1
Fort Meade Never Says Anything. FarCenter Dec 2013 #2
Latest Discussions»General Discussion»Researchers uncover first...