4 ms·
Um huh? How could ransomware break computers? Perhaps their data is gone but formatting and reinstalling Windows isn't feasible?
by SpikeDad 8y ago
Um huh? How could ransomware break computers? Perhaps their data is gone but formatting and reinstalling Windows isn't feasible?
- Crosseye_Jack 8y agoDepends on the level of trust you place into the compromised systems and your threat model. Basically they are going down the "nuke it from orbit" route, lets say they miss a system that reinfects the rest somehow. As for formatting windows, sadly these days that is no longer enough to be sure with a "well crafted" malware. Lets take the industry favourite laptop tracking platform CompuTrace (now named Lo-Jack iirc). The BIOS/UEFI Module that is its heart is a small EXE that gets executed by windows on every boot (Just like the Superfish incident, though that did use a diff way to get executed on windows launch, lo-jack gets executed by windows, superfish replaced a file that would get executed). In Lo-Jack case its a small dropper exe that then fetches the real tracking payload once the laptop connects to the internet but it can be (iirc) tricked into downloading and running any exe it likes with system priv's. A BIOS flash of a fixed BIOS is the only "fix". But in my past I've had fun injecting stuff into and modifying BIOS's (Mainly just to unlock extra options or remove whitelists for wifi cards) and most BIOS/UEFI's these days can be flashed from within Windows. Sure to save bricking the machine you would need to get the correct BIOS for that machine but if a company puts in a purchase order for 100 office machines they are not going to differ too much. If you have a payload running on a machine you could call home with its motherboard make, model and revision. Download the bios from the vendor, inject a payload into it, send it back to the machine, have the machine flash it in the background and using the same methods Superfish / Jo-Jack use have malware that persists though a format or even a replacement of the drive. I'm sure we have already seen malware using these techniques already in the wild. Signed BIOS updates will protect to some degree but their have been a fair few cases of being able to bypass the sig check (which is often only done during the the read of the bios before the flash takes place). Is it overkill? is it paranoia? Probably. It might just be simply the case that the machines were due to be replaced at some point in the near future anyway so 2 birds, one stone. EDIT: It might of not been Lenovo's use of superfish that was installed via bios on reinstall of Windows, but their own bloatware. It replaced Microsoft's copy of autochk.exe with its own that installs other pieces of Lenovo software. After the shit hit the fan in that case, Lenovo quickly issued BIOS Updates to remove the "feature". But it goes to show how abusing the Windows Platform Binary Table can be used to inject unwanted software into a system.
- rovyko 8y agoIs flashing the BIOS and reformatting the machine sufficient to remove any virus that we know of currently? Or are there other hidden components that need to be cleared?
- Crosseye_Jack 8y agoThe NSA have been using Hard Drive Firmware exploits for years. Such an attack could hide malware that also survives a format[0] (Which is why I brought up a drive replacement in my prev post). I wouldn't be surprised if the same can't be done with SSD Firmware too (we have already seen people do "bad things" with USB Memory sticks [1]) Also if a full BIOS flash has been performed you might be SOL as after a power cycle the modified BIOS is now the first thing loaded by your system (Or it might be the VBIOS, its been a while.) which could prevent future flashing of the BIOS or fake the flashing process but not actually flash anything. If you have a board that can recovery flash you might be able to recover but how do you trust the system afterwards? As the BIOS is usually stored on a SPI Flash you could use an external programmer to dump the content of the flash and do a diff on the firmware file. You have to think about who is your attacker. Are the Kiddies going to go to such lengths to stay persistent on a consumers laptop they use as a facebook machine? Prob not. But is it outside the scope of a determined attacker (or nation state) who managed to get a first stage attack malware inside a large company? IMO it would depend on how valuable they determine access to your network / data is. [0] https://www.theregister.co.uk/2015/02/17/kaspersky_labs_equation_group/ https://www.theregister.co.uk/2015/02/17/kaspersky_labs_equa... [1] https://www.youtube.com/watch?v=nuruzFqMgIw https://www.youtube.com/watch?v=nuruzFqMgIw EDIT: I've not spoke about VBIOS infections as the GPU Vendors on at least modern cards have been really locking down their GPUS and as far as I've seen, I've yet to see any credible claims of attacks on GPU's in the wild (They could be out there, I've just not come across any.). But such an attack would be scary as hell (imo) as its a black box that has DMA access to the CPU (think like the Mac Thunderbolt attacks of old) and other devices on the PCI-e bus. Its one of the places I would be spending my time researching.
- amelius 8y agoNot sure. Who knows what hides inside Intel ME.