Russian hackers are upping the ante of their cyberattacks.
The next level of cyber warfare may not be here thanks to the latest weapon being utilized by Russian hackers.
SEE ALSO: Cryptocurrency exchange claimed it was 'practically impossible' to hack. It was hacked.Researchers with the cybersecurity company ESET have discovered what is believed to be the first known UEFI rootkit malware used in a cyber attack. In a blog post, ESET explains:
“The discovery of the first in-the-wild UEFI rootkit is notable for two reasons. First, it shows that UEFI rootkits are a real threat, and not merely an attractive conference topic. And second, it serves as a heads-up, especially to all those who might be in the crosshairs of Sednit. This APT group, also known as APT28, STRONTIUM, Sofacy and Fancy Bear, may be even more dangerous than previously thought.”
If the name “Fancy Bear” sounds familiar, it’s because they’re the hacking group embedded in Russia’s GRU intelligence agency that has been found responsible for the 2016 DNC emails hack and various misinformation campaigns surrounding the US elections. Earlier this summer, special counsel Robert Mueller indicted a number of Russian nationals with the Fancy Bear hacking group for their role in these attacks.
Previously these Russian hackers had deployed various methods ranging from social engineering to spear-phishing emails as the means of their attacks. This discovery of sophisticated rootkit malware being deployed takes this all to a whole new level.
This instance of malware has been dubbed LoJax as it copies portions of LoJack’s Absolute LoJack software, which is intended to find stolen laptops and remotely wipe the hard drive of a missing computer. Because of this, this rootkit malware only affects PCs.
The main issue with rootkit malware is that it embeds itself into a computer’s firmware and can’t be easily removed. Reinstalling the operating system or replacing the hard drive of the computer will not cut off the hackers’ access to the device. In fact, according to ESET, the main two options of recourse once infected is to manually reflash a computer’s memory with new firmware, which is a fairly difficult, technical process, or to just completely replace the computer’s motherboard. Basically, if a computer is compromised by LoJax, your best option is probably to toss that computer in the trash.
According to ESET, different components of the LoJax malware has already been discovered in attacks deployed against “a few government organizations in the Balkans as well as in Central and Eastern Europe. ESET’s investigation concluded that the hackers were ”successful at least once in writing a malicious UEFI module into a system’s SPI flash memory.”
This discovery should serve as a warning that the hacking threat is only escalating as malicious actors look to fool-proof future methods of attack.
Copyright © 2023 Powered by
Russian hackers are taking their cyber warfare to the next level-鼓盆之戚网
sitemap
文章
2516
浏览
3994
获赞
34
The first photos of Harry and Meghan's new baby are finally here
Well, the wait is finally over. The Duke and Duchess of Sussex have put us out of our misery and rev#StayTheFHome urges people to stop the spread of the coronavirus
In an effort to get people to stay inside and reduce community exposure to the coronavirus, a GermanThe best gifts for the gamer who travels
There are so many options these days for people who adore video games, have places to go, and moneyWatch this Australian magpie perfectly mimic the sound of emergency sirens
Footage of an Australian bird mimicking the sound of emergency sirens has gone viral in the midst ofThese $315 denim panties are deeply upsetting
"Weird, bad jeans" are practically their own fashion genre by now, and brands are well aware that maSheriff's baffling tweet about a boulder in the road goes gloriously viral
If you're navigating the snowy roads roads of Telluride in San Miguel County, Colorado, you had bettWho are you supposed to sing 'Happy Birthday' to when washing your hands?
This morning I sang "Happy Birthday to You" to myself in the bathroom even though it isn't my birthdIf the holidays suck for you, head to the nicest place on the internet
This is a wonderful time of the year, where friends and family gather in love and harmony — inChina plans to ban Bitcoin mining, report claims
China plans to put an end to cryptocurrency mining in the country, Reuters reported Tuesday citing aCare facility gets through isolation with a game of life
Seniors in an assisted living facility are cheering themselves up during social distancing with a ga'Watchmen,' 'Contagion' PSAs tell us how to keep safe from coronavirus
As city- and statewide lockdowns continue to prevent the spread of coronavirus, more and more celebrYouTube to curb videos promoting 5G coronavirus conspiracy theories
Conspiracy theories that link 5G to the coronavirus are spreading fast on social media. It's resultiWhat to expect at WWDC 2020: Plenty of new features across all Apple devices
On June 22, Apple will hold is annual World Wide Developers Conference (WWDC). But rather than gatheInside Quinn, a new site for audio erotica
“I wanted to leave you on a rather nice note,” a male French voice coos in your ear. &ldApple reports strong revenue for services like App Store, Apple Music
Consumers aren't rushing to buy as many iPhones, iPads, or other Apple products as before the pandem