Skip to main content

UEFI Rootkits among CIA hacking tools revealed by Wikileaks

posted onMarch 13, 2017
by l33tdawg
Credit:

The recent release of a list of CIA hacking secrets by whistle-blower site Wikileaks has left security teams scrambling to analyze their code to see just what is vulnerable and what isn’t. This is something that may take some time given the massive scope of the data which even includes Smart TV’s being turned into surveillance devices as well as tools aimed at compromising the ubiquitous iOS and Android operating systems.

The Wikileaks documents allege that the CIA’s Embedded Development Branch (EDB) developed two OS X specific tools called DerStarke and another called DarkMatter to deploy malware based on UEFI exploits.

Many modern PC’s and laptops use UEFI firmware (Unified Extensible Firmware Interface) which is the replacement for the old BIOS. UEFI rootkits can be especially dangerous as they can survive and reinfect the OS kernel even after a disk wipe and OS re installation. UEFI updates typically require user interaction compared to a software AntiVirus update which is mostly automatic. Unfortunately the average consumer has poor knowledge of UEFI/BIOS and does not know how to update it, meaning UEFI vulnerabilities can remain in a system potentially for the life of the system.

Source

Tags

Industry News

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Simplenews subscription

Stay informed - subscribe to our newsletter.
The subscriber's email address.
Keeping Knowledge Free for Over a Decade

Copyright © 2018 Hack In The Box. All rights reserved.

36th Floor, Menara Maxis, Kuala Lumpur City Centre 50088 Kuala Lumpur Malaysia
Tel: +603-2615-7299 Fax: +603-2615-0088