Live data from Hacker News

Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

bleepingcomputer.com

1–10 of 84 posts

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#2
Intel AMT strikes again. I imagine this problem will only increase in the future, now that more malware creators know they can try to use this CPU backdoor (okay, this "totally-not-intended-for-bad-things and super-useful remote connection enterprise feature").

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#4
Money Quote:

> When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things.

Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!"

m(

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#5
post #2

Intel AMT strikes again. I imagine this problem will only increase in the future, now that more malware creators know they can try to use this CPU backdoor (okay, this "totally-not-intended-for-bad-things and super-useful remote connection enterprise feature" ).

Exploiting vPro / AMT / any remote access mechanism from any chip maker is hardly a new idea.

AMT and AMD's equivalent (don't remember the name) has been a holy grail for security researchers and malware authors alike for many years. People have been begging Intel for a very long time to make business-tier chips without remote access capabilities.

For personal computing, at least we have enthusiast chips. For example, my i7 K model lacks the technology.

EDIT: AMD's remote tech is called Platform Security Processor (PSP). Thank you, jacquesm!

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#6
post #4

Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(

This just means that it is broken by design and will probably never be fixed. Nice.

Does anyone know about similar AMD vulnerabilities?

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#7
post #5
post #2

Intel AMT strikes again. I imagine this problem will only increase in the future, now that more malware creators know they can try to use this CPU backdoor (okay, this "totally-not-intended-for-bad-things and super-useful remote connection enterprise feature" ).

Exploiting vPro / AMT / any remote access mechanism from any chip maker is hardly a new idea. AMT and AMD's equivalent (don't remember the name) has been a holy grail for security researchers and malware authors alike for many years. People have been begging Intel for a very long time to make business-tier chips without remote access capabilities. For personal computing, at least we have enthusiast chips. For example…

Who knows if the feature is not still present in silicon but just software-disabled?

It's not really new that Intel and AMD do binning to get more yield.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#8
post #6
post #4

Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(

This just means that it is broken by design and will probably never be fixed. Nice. Does anyone know about similar AMD vulnerabilities?

Yes, AMD chips have almost exactly the same features as Intel ME.

The cynic in me thinks that some execs got FISA orders.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#10
post #5
post #2

Intel AMT strikes again. I imagine this problem will only increase in the future, now that more malware creators know they can try to use this CPU backdoor (okay, this "totally-not-intended-for-bad-things and super-useful remote connection enterprise feature" ).

Exploiting vPro / AMT / any remote access mechanism from any chip maker is hardly a new idea. AMT and AMD's equivalent (don't remember the name) has been a holy grail for security researchers and malware authors alike for many years. People have been begging Intel for a very long time to make business-tier chips without remote access capabilities. For personal computing, at least we have enthusiast chips. For example…

> don't remember the name

PSP: Platform Security Processor

Post reply on HN