Découverte d'un logiciel malveillant de microprogrammation UEFI, ce qui ouvre la voie à de futures attaques par rootkit
Everyone hates malware, especially when itâs ultra nefarious. Fortunately, for years malware has been relatively easy to avoid if you take basic precautions, but that may not be the case for much longer, as a new class of rootkit that can infect your UEFI/BIOS has been spotted by Kaspersky engineers, who claim that this malware is so good at hiding, that even a wipe of your SSD wonât clear it out.
Although antivirus and Windows Defender usually stop malware in their tracks, if they donât, you can usually rely on an old school format just to clear out whateverâs been giving you some trouble. The problem with a UEFI rootkit, however, is that it doesnât reside on your hard drive or SSD, it lives on the small BIOS chip on each motherboard. That makes it incredibly hard to get rid of.
The new malware is based on an evolved version of the Spy Shadow Trojan from 2016, and itâs been discovered on both Asus and Gigabyte motherboards. Fortunately, so far itâs been exclusively older H81 motherboards running older UEFI, so it may be that simply updating your motherboardâs firmware will be enough to remove it and newer boards donât appear affected so far.
That could change in the future though. The Kaspersky engineers warned: âthe multiple rootkits discovered so far evidence a blind spot in our industry that needs to be addressed sooner rather than later.â
Look out for firmware security patches coming to a system near you.
