Skip to main content

Pre-boot malware Nemesis targets financial systems with data theft

researchers use ambient light sensor data to steal browser exhausted man computer problems desk hacking hackers malware frust
Shutterstock
One of the more interesting revelations about the snooping tactics employed by the NSA over the past few years was that the agency had managed to install malware into hard-drive firmware in order to get around deletion during formats. While not as complicated as that, Nemesis malware uses a similar system by hiding outside the reaches of normal clean-ups, dodging even operating system reinstalls by hiding in the boot-record.

IT professionals who don’t want the malware equivalent of the Nemesis character pictured above rampaging within the systems they manage will be on guard against this possibility.

Nemesis is in actuality a collection of programs and malware that is capable of doing lots of different things. It can transfer files around, capture screenshots and keystrokes, inject processes, and even capture financial data from a system. It’s designed to hide away on banking systems and siphon off funds and financially important information for the nefarious individuals behind its injection.

And by hiding itself within the boot-record of a system, it’s able to avoid traditional detection techniques, starting up before the OS has even thought about launching defensive countermeasures.

With that in mind, preventing an infection like this is the best way to avoid its associated issues, while clearing it out after it’s taken hold is much harder. It certainly requires a different approach than usual, as the team at FireEye discussed in their recent exposé (via Ars) on the malware bootkit. Any users who believes their systems are infected with such malware will need to do a complete drive wipe to make sure it’s cleared out.

This will be a process that’s a little more well known among SSD users, as a zeroing of the drive can often improve performance — even if the drive is TRIM enabled. However, it may be more daunting for enterprises or businesses that are more used to ghosting a drive from one system to another without ever starting from scratch.

This isn’t necessarily something that those running modern operating systems need to worry about though. Windows 8 and 10 both utilize Secure Boot, which prevents a replacement of the Windows bootkit from being launched.

That’s perhaps why the bootkit targets enterprise systems and financial services, which have a history of running older operating systems. Yet another good reason to stay up to date with your operating system, as well as with drivers and anti-malware software.

Editors' Recommendations

Jon Martindale
Jon Martindale is the Evergreen Coordinator for Computing, overseeing a team of writers addressing all the latest how to…
Apple Memorial Day sales: Save on Apple Watch, iPad, MacBook, and more
The 14-inch MacBook Pro with M3 Max chip seen from behind.

Most of this year's Memorial Day deals are set to launch very soon, but if you want to get your shopping for Apple devices done early, we're here to help you out with this roundup of the early Apple Memorial Day sales that are already available. Whether you're planning to buy a new iPad, iPhone, AirPods, MacBook, or Apple Watch, we've got some excellent bargains below. If anything catches your eye. it's highly recommended that you complete your purchase as soon as possible because there's no telling how soon these offers will expire -- some may not even make it to Memorial Day itself!
Best Memorial Day iPad deals

Memorial Day is one of the best times of the year to search for iPad deals. There are some fantastic discounts that are available across a variety of models of Apple's tablet, including the entry-level Apple iPad and the creatives-focused Apple iPad Pro, so whatever your purpose is for thinking about getting an iPad, there won't be any shortage of options for you here.

Read more
I ask again: Will Apple ever merge the Mac and iPad?
An Apple iPad and a MacBook together on a desk alongside a pair of headphones.

Every few months, we hear the same argument being made: Apple should bring the Mac and the iPad closer together -- or even merge them and their operating systems completely -- to create some sort of hybrid device that would solve all of Apple’s problems. While I don’t entirely agree with these assessments, they do provide an interesting look into how your Apple devices might work in the coming years.

Bloomberg’s Mark Gurman is the latest to throw his hat into the ring, and the reporter’s Power On newsletter has detailed what he believes Apple should do to shape the future of the Mac and the iPad.

Read more
HP just reset its entire PC lineup
The HP OmniBook X AI PC.

In the new AI PC era, HP is starting fresh with an entirely new branding structure to highlight the power and performance of a fresh set of computers.

While many people may be familiar with the company’s Pavilion, Envy, and Spectre products on the consumer side and the Dragonfly devices for enterprise options, HP will now retire these lines and overhaul its options under two main lines: consumer and commercial. These include the Omni brand for consumers and the Elite brand for commercial. The company unveiled its inaugural products for each line, the HP OmniBook X AI PC and HP EliteBook Ultra AI PC, on Monday during Microsoft’s AI Vision event. I got to see the new devices ahead of the event and check out how this new branding and design looks in person.
A new beginning
These models will be the beginning of an overall brand expansion for HP. On the consumer side, the company plans to have several forms and tiers of Omni products with the goal of making customer selection simpler. Notably, HP plans to keep its Omen gaming PC brand intact during this restructuring.

Read more