SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
Date    Saturday June 10 2017, @08:03AM
Author    n1
Topic   
from the looks-shady,-but-it's-good-for-business dept.
https://soylentnews.org/article.pl?sid=17/06/09/2317209

Arthur T Knackerbracket has found the following story:

Microsoft's security team has come across a malware family that uses Intel's Active Management Technology (AMT) Serial-over-LAN (SOL) interface as a file transfer tool.

Because of the way the Intel AMT SOL technology works, SOL traffic bypasses the local computer's networking stack, so local firewalls or security products won't be able to detect or block the malware while it's exfiltrating data from infected hosts.

This is because Intel AMT SOL is part of the Intel ME (Management Engine), a separate processor embedded with Intel CPUs, which runs its own operating system.

Intel ME runs even when the main processor is powered off, and while this feature looks pretty shady, Intel built ME to provide remote administration capabilities to companies that manage large networks of thousands of computers.

-- submitted from IRC


Original Submission

Links

  1. "following story" - https://www.bleepingcomputer.com/news/security/malware-uses-obscure-intel-cpu-feature-to-steal-data-and-avoid-firewalls/
  2. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=20687

© Copyright 2023 - SoylentNews, All Rights Reserved

printed from SoylentNews, Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls on 2023-07-08 19:18:46