4 ms·
What they actually did was to implement kernel-level rootkits. This is why things 'secure boot' and requirement for signed drivers are a thing.
by lotharcable 2y ago
What they actually did was to implement kernel-level rootkits.
This is why things 'secure boot' and requirement for signed drivers are a thing.
- qweqwe14 2y agoThe downside with kernel-level rootkits is you essentially have to compile it for many different kernel versions if you want it to work everywhere. I think I've read about some malware that literally contacted a server, sent the kernel version, and the server would compile the rootkit on demand.
- abofh 2y agoAnd that's service right there - they tried to distribute the most compatible malicious kernel exploits for you, but sometimes you need a bespoke compilation for your system -- and these guys step up and make sure you get one! That's customer service, I think a lot of (all of) our trillion dollar overlords could do a thing or to and learn about providing reliable service.
- worthless-trash 2y agoKernel level code injection doesn't require code signing.