SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Malware uses Intel AMT feature to steal data, avoid firewalls
Date    Friday June 09 2017, @05:27PM
Author    cmn32480
Topic   
from the swallow-the-red-pill dept.
https://soylentnews.org/article.pl?sid=17/06/09/1723243

DannyB writes:

Malware uses Intel AMT feature to steal data, avoid firewalls

Microsoft's security team has come across a malware family that uses Intel's Active Management Technology (AMT) Serial-over-LAN (SOL) interface as a file transfer tool.

Because of the way the Intel AMT SOL technology works, SOL traffic bypasses the local computer's networking stack, so local firewalls or security products won't be able to detect or block the malware while it's exfiltrating data from infected hosts.

and . . .

Intel AMT SOL exposes hidden networking interface

This is because Intel AMT SOL is part of the Intel ME (Management Engine), a separate processor embedded with Intel CPUs, which runs its own operating system.

Intel ME runs even when the main processor is powered off, and while this feature looks pretty shady, Intel built ME to provide remote administration capabilities to companies that manage large networks of thousands of computers.

I always believed the Intel Management Engine was a bad idea and a huge target for sophisticated hackers. Your hardware. Pre-compromised from the factory. A processor baked into your microprocessor with full access to the hardware. It runs a secret binary blob -- and the primary microprocessor won't run without it.

This probably isn't the last time that this will be exploited. Probably not even be the first, given the difficulty to detect it. The wonderful thing is that your OS isn't aware of the compromise and is unable to interfere with it.


Original Submission

Links

  1. "DannyB" - https://soylentnews.org/~DannyB/
  2. "Malware uses Intel AMT feature to steal data, avoid firewalls" - https://www.bleepingcomputer.com/news/security/malware-uses-obscure-intel-cpu-feature-to-steal-data-and-avoid-firewalls/
  3. "a bad idea" - https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it
  4. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=20672

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Malware uses Intel AMT feature to steal data, avoid firewalls on 2024-04-24 00:07:29