Page 1 of 2 12 LastLast
Results 1 to 10 of 11
Like Tree6Likes

Thread: Mebromi: Here comes the first BIOS rootkit

  1. #1
    Newbie
    Overall activity: 0%

    Join Date
    Aug 2011
    Location
    cyberspace
    Posts
    42
    Liked
    5 times
    Points
    1,543

    Angry Mebromi: Here comes the first BIOS rootkit

    Mebromi is the first BIOS rootkit in the wild. Here is the complete article.

    The malware is called Mebromi and contains a bit of everything: a BIOS rootkit specifically targeting Award BIOS, a MBR rootkit, a kernel mode rootkit, a PE file infector and a Trojan downloader. At this time, Mebromi is not designed to infect 64-bit operating system and it is not able to infect the system if run with limited privileges.
    How do we protect our computer systems now?

  2. #2
    sm1
    sm1 is offline
    Experienced User
    Overall activity: 13.0%

    Join Date
    Nov 2009
    Posts
    801
    Liked
    75 times
    Points
    9,785
    Quote Originally Posted by linked View Post
    How do we protect our computer systems now?
    As said in the article the virus cannot infect our system with limited privileges. So either use limited/standard user account or don't hastily allow all UAC prompts

  3. #3
    *nix Technical Support
    Overall activity: 0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,850
    Liked
    320 times
    Points
    27,014
    Quote Originally Posted by sm1 View Post
    As said in the article the virus cannot infect our system with limited privileges. So either use limited/standard user account or don't hastily allow all UAC prompts
    Indeed.

    Also, weren't there other BIOS rootkits before? Or were they just MBR and my mind's playing tricks on me?
    pacman -Syyu life not found in sync db

  4. #4
    Newbie
    Overall activity: 0%

    Join Date
    Aug 2011
    Location
    cyberspace
    Posts
    42
    Liked
    5 times
    Points
    1,543
    Quote Originally Posted by sm1 View Post
    As said in the article the virus cannot infect our system with limited privileges. So either use limited/standard user account or don't hastily allow all UAC prompts
    Indeed, I guess that's the only way left to be protected.

    ---------- Post added at 03:33 AM ---------- Previous post was at 03:27 AM ----------

    Quote Originally Posted by hellnoire View Post
    Indeed.

    Also, weren't there other BIOS rootkits before? Or were they just MBR and my mind's playing tricks on me?
    Dunno if I have heard about any BIOS rootkits before. But the article mentions about a proof of concept "IceLord".

    This turned to be a very interesting discovery as it appears to be the first real malware targeting system BIOS since a well-known proof of concept called IceLord in 2007.
    The article does mentions about CIH/Chernobyl infection, the infamous virus discovered in 1998 that was able to flash the motherboard BIOS, erasing it.

  5. #5
    *nix Technical Support
    Overall activity: 0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,850
    Liked
    320 times
    Points
    27,014
    Quote Originally Posted by linked View Post
    Dunno if I have heard about any BIOS rootkits before. But the article mentions about a proof of concept "IceLord".

    The article does mentions about CIH/Chernobyl infection, the infamous virus discovered in 1998 that was able to flash the motherboard BIOS, erasing it.
    I remember reading about Chernobyl/CIH when I was first playing SiN 1, seeing as one of the mirrors of the demo had a virus on it and no one knew of it. I was lucky enough not to get it then. And that might have been what I was thinking, a proof of concept one.

  6. #6
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,153
    Liked
    1544 times
    Points
    4,220
    Thanks for the heads up linked. I wasn't aware of the existance of Mebroni and now I will stay alert for it.
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

  7. #7
    Administrator
    Overall activity: 0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,879
    Liked
    1723 times
    Points
    52,283
    If the Mebromi rootkit is stable, then the coder must be really good at it.
    The fact is it's not easy and very rarely people know how to code a BIOS rootkit.

  8. #8
    Verified Member
    Overall activity: 0%

    Join Date
    Aug 2011
    Location
    India
    Posts
    43
    Liked
    1 times
    Points
    2,064
    I hope KIS has something in it's arsenal to fight this Mebromi.... I have only 16 days left before I buy a new subscription/ Win one here

  9. #9
    Moderator
    Overall activity: 7.0%

    Join Date
    Dec 2008
    Posts
    7,200
    Liked
    1305 times
    Points
    67,807
    Thank you
    a BIOS rootkit specifically targeting Award BIOS
    Once Award BIOS had an antivirus inside (Trend Micro PC Cillin).
    Some motherboards have a backup BIOS
    in regards to previous malware targeting BIOS you may like to read here
    Errare humanum est, perseverare autem diabolicum

  10. #10
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,153
    Liked
    1544 times
    Points
    4,220
    Thanks for the additional information Leo.

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. A rootkit in a network card
    By leofelix in forum Spyware/Viruses
    Replies: 6
  2. ITW x64 TDL3 rootkit
    By Boyfriend in forum Spyware/Viruses
    Replies: 43
  3. Rootkit.TmpHider
    By Ceyfer √ in forum Spyware/Viruses
    Replies: 24
  4. TDSS Rootkit Analysis
    By Ceyfer √ in forum Spyware/Viruses
    Replies: 7
  5. MBR Rootkit!!!! Help ASAP!!!
    By lilangel186 in forum Spyware/Viruses
    Replies: 6

Tags for this Thread

All times are GMT +8. The time now is 06:42 AM.