Malicious content exists online. It's one thing to recognize them and steer clear, and it's another thing not to know them at all. Malware still exists; no one can deny it. Add that to the number of vulnerabilities that we learn about almost all the time, and then you can conclude that cyber defenders deserve all the credit that might go their way.
While you were reading the last paragraph, you should already have a good idea of what we are about to discuss. Let's begin.
When I read articles like this, it makes me think twice before installing a web browser extension. The excerpt below briefly explains the type of extensions and how they evade detection.
The extensions pose as free VPN services, ad blockers, translation tools, and weather forecast apps, but instead deploy a multi-stage payload that monitors users’ activities, disables security protections, and enables remote code execution (RCE).
The extension’s developer used steganography to hide after that marker a loader that reaches a remote command-and-control (C&C) server to retrieve an encrypted payload.
The fairly good news about this attack is that it requires physical access to the device. Anything else, as with all vulnerabilities, it's not a good thing.
Here is what's going on:
The problem is that during the boot process the firmware indicates that direct memory access (DMA) protections are enabled, when in reality the IOMMU is not properly configured and activated until immediately before control is handed over to the operating system.
This allows an attacker who has physical access to the targeted system to use a malicious PCIe device to conduct a DMA attack.
Credits
Cover photo by Debby Hudson on Unsplash.
That's it for this week, and I'll see you next time.
SOCIAL SHARE CARD GENERATOR