Ransomware can attack the CPU, not just the operating system: How to prevent it?
Ransomware is a serious problem in its current state and is only going to get worse. Any security programs and measures will be rendered useless when ransomware attacks the CPU.
Ransomware can lock your CPU
Ransomware typically locks down system files and other documents inside the operating system, rendering the PC nearly unusable. CPU ransomware, on the other hand, changes the processor's microcode, completely altering its behavior.
Only chip manufacturers like AMD or Intel can provide microcode for their respective processors. This microcode comes preloaded from the factory, and you can receive updates later to improve performance, stability, or fix any bugs. If hackers can exploit a CPU firmware bug to upload malicious microcode to your processor, the game is pretty much over.
While the chances of this happening are pretty low, it's no longer entirely theoretical. Google has demonstrated a way to inject custom microcode into AMD Zen CPUs by exploiting a bug that causes the processor to pick the number 4 every time it's asked to enter a random number.
Worse still, Christiaan Beek, senior director of threat intelligence at cybersecurity firm Rapid7, has developed a viable proof of concept, according to The Register. Fortunately, he hasn't released it, but now that the idea is public, it won't be long before hackers figure it out, too. In Beek's words:
If hackers were researching this threat a few years ago, chances are some of them got smart enough at some point and started creating this.
It's possible that hackers were working on CPU or firmware ransomware. UEFI bootkits that allow hackers to bypass Secure Boot and inject malware into a system's firmware already exist and are openly sold on hacker forums on the dark web . Beek also points to quotes from leaked chats revealed in the 2022 Conti ransomware leak, suggesting that hackers may have been working on ideas for installing ransomware inside a computer's UEFI firmware.
Can you protect yourself?
While antivirus programs can detect ransomware infections early and block the processes from running, CPU ransomware is out of their reach. If the CPU is infected with ransomware, the malware will load before the operating system, bypassing all traditional security measures in place and gaining complete access to every component of the system.
The good news is that you don't need to worry right now, as Beek hasn't seen any samples of the malware working in the wild. It's unlikely that hackers will be able to create a working exploit for at least a few years. Even if a working exploit is discovered, you can be sure that CPU manufacturers will quickly patch the issue and release firmware updates. On top of that, CPU vulnerabilities of this scale are pretty rare to begin with.
Better security is one of the reasons why you should update your PC's BIOS. With the emergence of CPU ransomware, an updated BIOS and CPU drivers are more important than ever. Just keep your software up to date, don't click on random emails and links, and check before running programs downloaded from the Internet, especially if you don't trust the website or sender.
You should read it
- There is a tool to decrypt the ransomware that specializes in attacking businesses
- Ransomware can encrypt cloud data
- General guidelines for decoding ransomware
- What is Ransomware Task Force (RTF)?
- [Infographic] 7 effective ways to protect businesses from Ransomware
- How to decode ransomware InsaneCrypt (Everbe 1.0)
- Why is Ransomware the perfect hack?
- Learn about Ransomware: 6 ransomware on computers
May be interested
- Kaseya suffered a ransomware attack, affecting a series of other technology companiesa ransomware attack against the international information technology company kaseya appears to have infected hundreds of small businesses involved.
- Windows SMB users should close some ports to prevent WannaCrywill ransomware wannacry come back to attack us? try closing some of the ports below to prevent ransomware from attacking!
- What is Ransomware Ryuk? How to prevent it?cybercriminals are using a new form of ransomware to target large businesses and take money from it. since august, the ryuk team has made $ 4 million by installing malicious encryption software on high-value targets.
- What is BlackCat Ransomware? How to prevent?everyone knows that ransomware is scary. and now, a clever new ransomware variant, named blackcat, poses an even greater threat.
- Ransomware turns 35, how terrible was the world's first attack?the 'aids' floppy disk is credited as the world's first ransomware attack.
- Acronis Ransomware Protection, a completely free anti-ransomware solution for Windowsin order to protect users from the growing attack of ransomware malware, researchers at acronis have launched a tool capable of preventing any suspicious activity on the system and protecting data. your data is called acronis ransomware protection.
- Learn about Ransomware: 6 ransomware on computerswhat is ransomware? are there any other ransomware? how does ransomware attack computers and demand ransom from users?
- Detecting a new ransomware strain, not asking for data ransom, but only needing the victim to join the Hacker's Discord serverinternational security researchers have just stumbled upon a strain of ransomware that possesses rather strange behavior. called 'hog', this ransomware still enters the system and encrypts the victim's files.
- Detecting two unusual versions of ransomware, shows that the world of ransomware has become diversifiedinternational cybersecurity researchers recently found two completely new types of ransomware that are quite strange. they carry very different and rarely recorded features, which are the alarm bells, showing that the world of ransomware has become diverse.
- Prevent WannaCry variants by turning off this Windows 10 installationthe recent attack on wannacry has caused fever for the online community. although it has settled down, we should still be careful by protecting the computer from its variants. in this article, tipsmake.com will guide readers to prevent wannacry variants by turning off an installation on windows 10.