Asus and Gigabyte: Mainboards targeted by cybercriminals

VG word pixels

CosmicStrand Malware

Security experts have discovered dangerous malware in the firmware of some motherboards. The manufacturers Asus and Gigabyte have been affected so far.

News

VG word pixels

Stock photo of a motherboard from MSI
So far, the malware has only been detected on Asus or Gigabyte systems.
© Adobe Stock: Maryia

Kaspersky security experts have dangerous UEFI rootkits in Asus and Gigabyte firmware discovered. They therefore warn of attacks aimed at the mainboards of the two manufacturers. That reports that Online magazine Bleeping Computer.

Apparently, the malware has been hiding in the firmware since 2016. Chinese hacker groups are said to be responsible for this used devices before resale should have equipped with the rootkit.

The malware used was identified by Kasperky with “cosmic beach” titled. The level of threat is currently still unclear, since the extent of the affected systems cannot be estimated. However, it is necessary for an attack, initially direct access to the computer to have.

Once deployed successfully, the malware is designed to customize the operating system’s loader and take control. Further malware is then downloaded to further weaken the system. Antivirus programs can do little heresince the UEFI rootkit runs before all other applications during boot-up.

So far, the rootkit has only been found on computers with Asus or Gigabyte mainboards H81 chipset to use. Although this is outdated hardware, some devices are apparently still in circulation.

It is currently unclear whether other manufacturers could be affected. There has not yet been an official warning from Asus or Gigabyte, nor has there been any corresponding security updates.

The MSI Pro X670-P Wifi, MEG X670E Ace and MPG X670E Carbon Wifi motherboards

ASRock, Asus, Biostar, Gigabyte and MSI

Manufacturers announce high-end motherboards for Ryzen 7000

The “Big 5” have announced their high-end mainboards for AMD’s CPU generation Ryzen 7000 and the new AM5 socket. New motherboards with X670(E).

28.7.2022 from
Laura Pippig

Continue to home page

more on the subject

remove virus

Beware of Trojans

CCleaner free: Fake download turns out to be malware

A trojan is currently in circulation, which is distributed via a fake CCleaner license. The malware steals passwords and credit cards…

Password manager test 2021

Password manager

LastPass: Face Recognition Authentication and…

The password manager LastPass now also allows passwordless authentication on desktop devices via fingerprint or face recognition.

An exclamation mark on a red background with ones and zeros

Customer data affected

Energy supplier Entega experiences cyber attack

In Darmstadt, the energy supplier company Entega was the victim of a cyber attack. The attack hit internal accounts but not infrastructure.

lock bit

Beware of these emails

LockBit: False copyright warning brings ransomware

E-mails are currently circulating warning of copyright infringements. In reality, however, it is a ransomware attack with LockBit.

Above

Driving service app

Covered up cyber attack on Uber service

The Uber driving service is currently under criticism because the company covered up a cyber attack. Hackers steal sensitive customer data and blackmail…

Reference-www.pc-magazin.de