TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hacking Team Uses UEFI BiOS Rootkit to Keep RCS 9 Agent in Target Systems

112 pointsby apaprockialmost 10 years ago

8 comments

acdalmost 10 years ago
This is what I thought when viewing my latest computer that came with an UEFI bios. That the UEFI BIOS is to large and too complex and has way to many functions to be a BIOS device, hence a perfect place to put advanced malware.<p>It&#x27;s like an operating system before the operating system, has its own FAT32 system partition where you can store stuff.<p>Also after a few years your manufacturer will stop shipping uefi BIOS updates for your computer due to their interest in selling new computers and then there will be a lurking security whole laying around.
评论 #9883936 未加载
评论 #9884151 未加载
评论 #9884867 未加载
评论 #9884475 未加载
bediger4000almost 10 years ago
This is the most interesting Hacking Team revelation yet.<p>First, a production UEFI bootkit! Yahoo! That&#x27;s a milestone.<p>Second, fiddling with Bitcoin wallets. Between the bootkit and the Bitcoin fiddling, Hacking Team is just a small step away from a Zeus Botnet. That is, HT is hanging ten on the precipice of crime, it looks like.<p>Third, this line from HT CEO David Vincenzetti:<p><i>a modification of the actual Bitcoiin [sic], something different, fully traceable and supported by clearing houses and the global financial system as a whole might have a future.</i><p>If truly Vincenzetti&#x27;s viewpoint, that line demonstrates a slide to authoritarianism. According to accounts, Vincenzetti was an early privacy advocate. A cypherpunk wouldn&#x27;t be able to speak the phrase &quot;fully traceable&quot; except as an insult.<p>Are we seeing the result of money corrupting, or are authoritarian world views the inevitable result of working in the defense industrial complex?
评论 #9885059 未加载
评论 #9885523 未加载
评论 #9885435 未加载
评论 #9884988 未加载
userbinatoralmost 10 years ago
Look up Computrace; it&#x27;s very similar in operation but is installed by default in most BIOS&#x27; as a theft-prevention measure.<p><i>Admins managing servers can also opt to buy a server with physical BIOS write-protection, wherein the user will need to put a jumper or turn on a dip switch in order to update the BIOS.</i><p>Motherboards with hardware write-protected BIOSes were common around the turn of the century, when flash EEPROMs started replacing EPROMs for BIOS storage. Too bad the amount of tiny extra BOM cost and what seems to be increasingly buggier BIOSes that require frequent updates has made them mostly disappear...<p>I wonder how much the &quot;it can always be updated later&quot; mentality prevalent today has lead to a higher defect rate in code - it seems to me that if it&#x27;s harder to change something once it&#x27;s released, there is more incentive to get it right the first time. I can&#x27;t remember there being any significant bugs with BIOS in the early machines I used (386&#x2F;486 era) and those basically never needed to be updated; although PCs have gotten considerably more complex since, especially with things like UEFI, perhaps not all of that complexity is warranted and it wouldn&#x27;t have manifested itself if BIOS&#x27; had remained difficult-to-modify?
z3t4almost 10 years ago
All it takes to install a (BIOS) rootkit is root access ... In windows this means answering Yes on the question &quot;Do you want to allow the following program to make changes to your computer&quot;.<p>Remember to flash the BIOS if you&#x27;ve been hacked!
评论 #9883927 未加载
gesmanalmost 10 years ago
UEFI BIOS - Road to hell that was paved with good intentions
评论 #9884943 未加载
评论 #9887954 未加载
评论 #9887310 未加载
defectivealmost 10 years ago
Luckily, this at least requires physical access.
评论 #9883777 未加载
fdbalmost 10 years ago
Silly question perhaps, but does this apply to Macs as well?
paulmdalmost 10 years ago
Hey guys that BadBios is totally impossible, agreed? What a scrub, UEFI viruses are impossible. lol psychotic break amirite<p>I caught a message on the Windows install rebooot about &quot;Intel AMT activated&quot; during a clean reformat - but in BIOS it shows deactivated on reboot. Kaspersky&#x2F;Malwarebytes&#x2F;CCleaner shows clean on every scan for system files - I&#x27;m seriously wondering whether I need to dump this machine hardware and all. The cause for the reformat in the first place was a potential virus infection, maybe a rootkit. I didn&#x27;t want to let it back on my network after I scanned a cryptolocker variant in my temp folder.
评论 #9883324 未加载
评论 #9884435 未加载