Kasperski Discovers Firmware-Level Spyware Linked to NSA

February 20, 2017

It looks like the NSA is hacking computers around the world by accessing hard-drive firmware, reports Sott in their article, “Russian Researchers Discover NSA Spying and Sabotage Software Hidden in Hard Drives.” We learn that Russian security firm Kaspersky Lab found the sneaky software lurking on hard drives in 30 countries, mostly at government institutions, telecom and energy companies, nuclear research facilities, media outlets, and Islamic activist organizations. Apparently, the vast majority of hard drive brands are vulnerable to the technique. Writer Joseph Menn reports:

According to Kaspersky, the spies made a technological breakthrough by figuring out how to lodge malicious software in the obscure code called firmware that launches every time a computer is turned on. Disk drive firmware is viewed by spies and cybersecurity experts as the second-most valuable real estate on a PC for a hacker, second only to the BIOS code invoked automatically as a computer boots up. ‘The hardware will be able to infect the computer over and over,’ lead Kaspersky researcher Costin Raiu said in an interview.

Though the leaders of the still-active espionage campaign could have taken control of thousands of PCs, giving them the ability to steal files or eavesdrop on anything they wanted, the spies were selective and only established full remote control over machines belonging to the most desirable foreign targets, according to Raiu. He said Kaspersky found only a few especially high-value computers with the hard-drive infections.

Kaspersky’s reconstructions of the spying programs show that they could work in disk drives sold by more than a dozen companies, comprising essentially the entire market. They include Western Digital Corp, Seagate Technology Plc, Toshiba Corp, IBM, Micron Technology Inc and Samsung Electronics Co Ltd.”

Kaspersky did not come right out and name the NSA as the source of the spyware, but did connect it to Stuxnet, a known NSA tool. We also learn that a “former NSA employee” confirmed Kaspersky’s analysis, stating these tools are as valuable as Stuxnet.

Menn notes that this news could increase existing resistance to Western technology overseas due to security concerns. Researcher Raiu specifies that whoever created the spyware must have had access to the proprietary source code for the drives’ firmware. While Western Digital, Seagate, and Micron deny knowledge, Toshiba, Samsung, and IBM remain mum on the subject. Navigate to the article to read more details, or to view the four-minute video (scroll down a bit for that.)

Cynthia Murrell, February 20, 2017

Comments

One Response to “Kasperski Discovers Firmware-Level Spyware Linked to NSA”

  1. Pablo Tousant   on May 6th, 2017 1:46 am

    very nice

  • Archives

  • Recent Posts

  • Meta