You think ransomware is bad now? Wait until it infects CPUs

Discussion in 'malware problems & news' started by summerheat, May 12, 2025.

  1. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,255
    https://www.theregister.com/2025/05/11/cpu_ransomware_rapid7/

    Scaring :sick:
     
  2. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,847
    Location:
    Italy
    Interesting.
    Making a better setting of the browser used is increasingly critical.
     
  3. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,176
    Location:
    USA
    That this is possible is disturbing.
     
  4. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,255
    How is this related to browser settings? o_O
     
  5. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,847
    Location:
    Italy
    How would a hypothetical CPU-ransomware get into my pc if not remotely?
     
  6. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,255
    If the microcode/firmware of your vendor contains ransomware (either because the vendor itself has become malicious or its download sites are manipulated by hackers), browser settings would not help at all as such updates are usually handled by your OS. Only if you download and install those firmware/microcode updates yourself your AV mightâ„¢ perhaps be able to recognize them as infected (but I doubt that). And even in that case browser settings would not prevent that as installing those updates is not performed from your browser, AFAIK (and should not be possible anyhow because of the browser sandbox).
     
  7. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,847
    Location:
    Italy
    Unclear.
    Suppose I (99.99% so all other users) currently have a clean microcode.
    Are you claiming that through Microsoft system updates I could be infected?

    I asked AI.
    The correct question is the one in the image:

    https://imgbox.com/DclQxPWS


    Currently not possible.

     
    Last edited: May 12, 2025
  8. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,255


    Possibly? 3rd-party microcode is usually closed source. I doubt that Microsoft is doing reverse engineering for that code. I'm not saying that such infections are already happening. But as the article mentions: "There are some indications that criminals are moving toward this end goal, from the UEFI bootkits that go back to 2018 and are now sold on cyber-crime forums to allow miscreants to bypass Secure Boot and embed malware into the firmware, surviving operating system reboots." We all know that many websites have been hacked in the past, so it's certainly not impossible that criminals will be successful in infecting microcode/firmware. And there have been several examples of BIOS and UEFI rootkits in the past.

    What exactly is not possible?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice