Meet "BadBIOS", the Mac and PC malware that jumps airgaps

User Info: CC Ricers

CC Ricers
3 years ago#1

Three years ago, security consultant Dragos Ruiu was in his lab when he noticed something highly unusual: his MacBook Air, on which he had just installed a fresh copy of OS X, spontaneously updated the firmware that helps it boot. Stranger still, when Ruiu then tried to boot the machine off a CD ROM, it refused. He also found that the machine could delete data and undo configuration changes with no prompting. He didn't know it then, but that odd firmware update would become a high-stakes malware mystery that would consume most of his waking hours.

In the following months, Ruiu observed more odd phenomena that seemed straight out of a science-fiction thriller. A computer running the Open BSD operating system also began to modify its settings and delete its data without explanation or prompting. His network transmitted data specific to the Internet's next-generation IPv6 networking protocol, even from computers that were supposed to have IPv6 completely disabled. Strangest of all was the ability of infected machines to transmit small amounts of network data with other infected machines even when their power cords and Ethernet cables were unplugged and their Wi-Fi and Bluetooth cards were removed. Further investigation soon showed that the list of affected operating systems also included multiple variants of Windows and Linux.

"We were like, 'Okay, we're totally owned,'" Ruiu told Ars. "'We have to erase all our systems and start from scratch,' which we did. It was a very painful exercise. I've been suspicious of stuff around here ever since."

In the intervening three years, Ruiu said, the infections have persisted, almost like a strain of bacteria that's able to survive extreme antibiotic therapies. Within hours or weeks of wiping an infected computer clean, the odd behavior would return. The most visible sign of contamination is a machine's inability to boot off a CD, but other, more subtle behaviors can be observed when using tools such as Process Monitor, which is designed for troubleshooting and forensic investigations.

Another intriguing characteristic: in addition to jumping "airgaps" designed to isolate infected or sensitive machines from all other networked computers, the malware seems to have self-healing capabilities.

Ruiu posited another theory that sounds like something from the screenplay of a post-apocalyptic movie: "badBIOS," as Ruiu dubbed the malware, has the ability to use high-frequency transmissions passed between computer speakers and microphones to bridge airgaps.

Sounds like some mad creepypasta for PC geeks.
WikiLeaks scandal: WikiLeaks is not a true Wiki!

User Info: twopoundcow

3 years ago#2

User Info: MadPinoRage

3 years ago#3
I don't like this scary story.
Unthinking respect for authority is the greatest enemy of truth.
-Albert Einstein

User Info: Abiz_

3 years ago#4
I love a good horror story.
Interestingly enough, video game companies used to be able to make money without selling out like cheap prostitutes.-KaiserWarrior

User Info: KidInTheHall

3 years ago#5
I love the one where the guy hears a scratching noise from inside his PC case and when he opens it there's just a hook.

Ooh gives me goosebumps just thinking about it!
i5-3570k | ASRock Z77 Extreme6 | EVGA 560Ti 448 Classified x2 SLI | 16GB G.Skill Ares | Corsair 600T White | 212 EVO | HX750

User Info: Loshadt

3 years ago#6
And then a skeleton popped out.
Russian is my first language, so yes there may be a spelling error or two.
Kirino is best girl.

User Info: KillerTruffle

3 years ago#7
I like the part where Halloween is the new April 1.
"How do I get rid of a Trojan Horse?" -Sailor_Kakashi
"Leave it outside the gates of Troy overnight." -Davel23

User Info: urtv

3 years ago#8
that's it?where is the woman who was experimented on by trying to make human/animal hybrids through splicing?where is the stitched together bodies?this story sucks

User Info: SinisterSlay

3 years ago#9
It's the cd that has the infection :-)
He who stumbles around in darkness with a stick is blind. But he who... sticks out in darkness... is... fluorescent! - Brother Silence

User Info: electroflame

3 years ago#10
And then Dragos was malware.
Could be worse, they could have been American givers and you would have been smothered in small pox. -fakenamefignuts on Indian-Giving.
Steam ID: electroflame
