badBIOS: worst Malware to date, or Social Experiment (2024)

While it is commonly understood that Malware is a major threat to anyone with a computer, tablet or phone, what is not acknowledged is that Malware is much more than that. In the late-1990s a bit or Malware was released that actually infected the basic operating system that runs every computer, the BIOS (Basic Input/Output System). This bit of malware called Chernobyl was designed to wipe a systems BIOS on a preset date.

Chernobyl (CIH) was a very interesting creation in that it did not change the size of the files or systems it infected. Instead it filled in gaps in existing code to hide its presence. This was important as there was very little room in a BIOS. CIH was a seriously damaging bit of malware that destroyed many computers in its day. What is odd is that after CIH there was very little done to protect the BIOS/Firmware in devices, it is still possible to infect the firmware in computers, batteries, USB drives, keyboards, and more. It did help to push the fledgling data recovery market though.

With this in mind we are taking a look at a new threat that was announced recently named badBIOS. This potential threat was discovered by Dragos Ruiu and, if his claims are true, it looks like he has discovered the worst malware found to date. You see badBIOS infects the firmware in system and from there can control a number of basic system functions. According to Ruiu, badBIOS can infect traditional BIOS, EFI and UEFI which covers almost the entire gamut of computer systems. Additionally (if the information that Ruiu claims is true) by infecting the BIOS of a system it does not matter what OS is running. The BIOS controls the hardware at a level that the OS only interprets.

Now simply having a malware that can infect your system BIOS and lock you out of it (and the OS) is bad enough. However, Ruiu has claimed that badBIOS is even more sinister than this. It apparently can infect any USB drive or device plugged in by infecting the firmware in its controller. It can also communicate using ultrasonic waives that are received by other devices microphones when no other means is available. This last point is interesting as not every system has an audio card or microphone, it also means that this last resort type of communication can only be run at close proximity. Another interesting point is that, again according to Ruiu, it communicates using IPV6.

If this sounds frightening it is because it is. If this is a real piece of malware it represents a new method of attack and one that is going to be very difficult to remove. You could technically replace the BIOS chip on a board, or through the use of a subsystem like Asus’ BIOS flashback, overwrite the entire BIOS with good code. However, there are some holes in the claims by Ruiu that make us skeptical. Although everything he lists is technically possible and within the capabilities of the some of the more advanced malware developers out there, it is not the easiest thing to do. Ruiu has also not provided any proof to his claims and there have been no reports of infection outside of his lab.

So we now have a situation where we potentially have a bit of malware that is unlike anything else we have seen or we have a security researcher that is using an array of technical possibilities to build a boogeyman of a virus in the mind of the press and the consumer. Ruiu is not releasing any information until later at PacSec (in about two weeks). We are not sure what his presentation will show, is this an elaborate hoax intended to create a Chicken Little response or is this a reality that he stumbled on and is really trying to alert us to. To be honest there is not enough information to decide one way or another simply because everything Ruiu describes is possible with current technology and by people that are developing malware. On the other hand if this was a real threat then you would think that Ruiu would want to bring in as many people as possible to help identify and counter the threat badBIOS represents. We will all know for sure at PacSec in Tokyo, let’s hope this is not the threat that it could be and ends up being a social experiment run by Ruiu to see how society reacts to a security threat of this magnitude.

Tell us what you think in our Forum

badBIOS: worst Malware to date, or Social Experiment (2024)
Top Articles
DIY Alternative for Weed-B-Gone or RoundUp: Homemade Recipe is Effecti
Soft Ginger Cookies Recipe AKA "Gingerdoodles" - Lauren's Latest
St Thomas Usvi Craigslist
7 Verification of Employment Letter Templates - HR University
O'reilly's Auto Parts Closest To My Location
Fat People Falling Gif
Missing 2023 Showtimes Near Cinemark West Springfield 15 And Xd
Evil Dead Rise Showtimes Near Massena Movieplex
Northern Whooping Crane Festival highlights conservation and collaboration in Fort Smith, N.W.T. | CBC News
Espn Expert Picks Week 2
Derpixon Kemono
Culver's Flavor Of The Day Monroe
Xm Tennis Channel
Florida (FL) Powerball - Winning Numbers & Results
Love Compatibility Test / Calculator by Horoscope | MyAstrology
The Rise of Breckie Hill: How She Became a Social Media Star | Entertainment
Purple Crip Strain Leafly
U/Apprenhensive_You8924
Peraton Sso
How To Cancel Goodnotes Subscription
H12 Weidian
Cocaine Bear Showtimes Near Regal Opry Mills
Airrack hiring Associate Producer in Los Angeles, CA | LinkedIn
Accident On 215
Home
25 Best Things to Do in Palermo, Sicily (Italy)
Prep Spotlight Tv Mn
BJ 이름 찾는다 꼭 도와줘라 | 짤방 | 일베저장소
Timeline of the September 11 Attacks
§ 855 BGB - Besitzdiener - Gesetze
Violent Night Showtimes Near Johnstown Movieplex
Costco Jobs San Diego
Sandals Travel Agent Login
Rgb Bird Flop
Ice Dodo Unblocked 76
Darknet Opsec Bible 2022
Amazing Lash Bay Colony
Maybe Meant To Be Chapter 43
Bitchinbubba Face
Pay Entergy Bill
20 bank M&A deals with the largest target asset volume in 2023
Colorado Parks And Wildlife Reissue List
Ursula Creed Datasheet
Wunderground Orlando
Firestone Batteries Prices
Post A Bid Monticello Mn
Walmart Careers Stocker
Doe mee met ons loyaliteitsprogramma | Victoria Club
60 Second Burger Run Unblocked
Razor Edge Gotti Pitbull Price
Estes4Me Payroll
Fetllife Com
Latest Posts
Article information

Author: Saturnina Altenwerth DVM

Last Updated:

Views: 5652

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Saturnina Altenwerth DVM

Birthday: 1992-08-21

Address: Apt. 237 662 Haag Mills, East Verenaport, MO 57071-5493

Phone: +331850833384

Job: District Real-Estate Architect

Hobby: Skateboarding, Taxidermy, Air sports, Painting, Knife making, Letterboxing, Inline skating

Introduction: My name is Saturnina Altenwerth DVM, I am a witty, perfect, combative, beautiful, determined, fancy, determined person who loves writing and wants to share my knowledge and understanding with you.