Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
bleepingcomputer.com
Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
1–10 of 84 posts
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#2Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#3Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#4> When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things.
Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!"
m(
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#5Intel AMT strikes again. I imagine this problem will only increase in the future, now that more malware creators know they can try to use this CPU backdoor (okay, this "totally-not-intended-for-bad-things and super-useful remote connection enterprise feature" ).
AMT and AMD's equivalent (don't remember the name) has been a holy grail for security researchers and malware authors alike for many years. People have been begging Intel for a very long time to make business-tier chips without remote access capabilities.
For personal computing, at least we have enthusiast chips. For example, my i7 K model lacks the technology.
EDIT: AMD's remote tech is called Platform Security Processor (PSP). Thank you, jacquesm!
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#6Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(
Does anyone know about similar AMD vulnerabilities?
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#7Intel AMT strikes again. I imagine this problem will only increase in the future, now that more malware creators know they can try to use this CPU backdoor (okay, this "totally-not-intended-for-bad-things and super-useful remote connection enterprise feature" ).
Exploiting vPro / AMT / any remote access mechanism from any chip maker is hardly a new idea. AMT and AMD's equivalent (don't remember the name) has been a holy grail for security researchers and malware authors alike for many years. People have been begging Intel for a very long time to make business-tier chips without remote access capabilities. For personal computing, at least we have enthusiast chips. For example…
It's not really new that Intel and AMD do binning to get more yield.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#8Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(
This just means that it is broken by design and will probably never be fixed. Nice. Does anyone know about similar AMD vulnerabilities?
The cynic in me thinks that some execs got FISA orders.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#9Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#10Intel AMT strikes again. I imagine this problem will only increase in the future, now that more malware creators know they can try to use this CPU backdoor (okay, this "totally-not-intended-for-bad-things and super-useful remote connection enterprise feature" ).
Exploiting vPro / AMT / any remote access mechanism from any chip maker is hardly a new idea. AMT and AMD's equivalent (don't remember the name) has been a holy grail for security researchers and malware authors alike for many years. People have been begging Intel for a very long time to make business-tier chips without remote access capabilities. For personal computing, at least we have enthusiast chips. For example…
PSP: Platform Security Processor