What are firmware attacks?

What are firmware attacks?

How a firmware attack works. Firmware is a type of permanent software code used to control each hardware component in a PC. Increasingly, cyber-criminals are designing malware that quietly tampers with the firmware in motherboards, which tell the PC to start up, or with the firmware in hardware drivers.

Can malware affect firmware?

BIOS-level malware usually rewrites the BIOS code and injects a malicious one. Because BIOS is located in memory rather than in the hard drive, this type of malware can’t be detected using regular antivirus. Because of its high memory privileges, it is used by hackers to access the operating system and firmware.

What are the risks of updating firmware?

Updating firmware is time-consuming, can be risky, and can require a system reboot and downtime. Organizations may lack the tooling to safely test and roll out updates, or to even know what firmware they have in their environment and if updates are available in the first place.

What kind of attacks can be done on firmware?

Simple BIOS and newer UEFI systems are frequent points of attack. Hacks to the firmware can come in multiple forms; malware, bootkits and rootkits are all popular delivery vectors. Infected USBs, corrupted drives and bad firmware products, are also something to be aware of.

How to protect against threats against USB enabled devices?

Talking about policy, USB devices should be part of an end user security policy where you can decide either do nothing (not recommended), block them, or control their use (and GFI can help with that). In the last two cases, IT have to be involved.

Why are USB sticks so vulnerable to hacking?

The USB research of Nohl and Jakob Lell showed how they could hide attack code on USB sticks to hijack a computer, alter files or redirect a user’s internet traffic to a malicious site. But not all gadgets and devices are equally vulnerable.

How does the firmware of a USB device work?

They spent months reverse engineering the firmware that runs the basic communication functions of USB devices—the controller chips that allow the devices to communicate with a PC and let users move files on and off of them.