{"id":118985,"date":"2015-02-17T09:34:49","date_gmt":"2015-02-17T07:34:49","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=118985"},"modified":"2015-02-17T09:39:40","modified_gmt":"2015-02-17T07:39:40","slug":"nsa-injected-spyware-into-your-hard-drive-report","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/118985-nsa-injected-spyware-into-your-hard-drive-report.html","title":{"rendered":"NSA injected spyware into your hard drive: report"},"content":{"rendered":"<p>The United States\u2019 National Security Agency (NSA) is being blamed for hiding spying software in the firmware of hard drives from\u00a0more than a dozen HDD manufacturers.<\/p>\n<p>This includes hard drives from\u00a0Western Digital, Seagate, and Toshiba.<\/p>\n<p><a title=\"Reuters\" href=\"http:\/\/www.reuters.com\/article\/2015\/02\/16\/us-usa-cyberspying-idUSKBN0LK1QV20150216\" target=\"_blank\"><strong>According to Reuters<\/strong><\/a> this spyware provides the NSA with the ability to eavesdrop on the majority of the world&#8217;s computers.<\/p>\n<p><a title=\"Kaspersky Lab\" href=\"http:\/\/www.kaspersky.com\/about\/news\/virus\/2015\/Equation-Group-The-Crown-Creator-of-Cyber-Espionage\" target=\"_blank\"><strong>Kaspersky Lab said that<\/strong><\/a> its Global Research and Analysis Team (GReAT) has recovered two modules which allow reprogramming of the hard drive firmware.<\/p>\n<p>Kaspersky Lab said this is the first known malware capable of infecting the hard drives.<\/p>\n<p>By reprogramming the hard drive firmware (rewriting the hard drive\u2019s operating system), two goals\u00a0are achieved:<\/p>\n<ul>\n<li>An extreme level of persistence that helps to survive disk formatting and OS reinstallation. If the malware gets into the firmware, it is available to \u201cresurrect\u201d itself forever. It may prevent the deletion of a certain disk sector or substitute it with a malicious one during system boot.<\/li>\n<li>The ability to create an invisible, persistent area hidden inside the hard drive. It is used to save exfiltrated information which can be later retrieved by the attackers.<\/li>\n<\/ul>\n<p>Costin Raiu, director of GReAT\u00a0at Kaspersky Lab, warned that once the hard drive gets infected with this malicious payload it is impossible to scan its firmware.<\/p>\n<p>\u201cTo put it simply: for most hard drives there are functions to write into the hardware firmware area, but there are no functions to read it back. It means that we are practically blind, and cannot detect hard drives that have been infected by this malware,\u201d he said.<\/p>\n<p>\u201cAlso, in some cases it may help the group to crack the encryption. Taking into account the fact that their GrayFish implant is active from the very boot of the system, they have the ability to capture the encryption password and save it into this hidden area,\u201d said Raiu.<\/p>\n<h3 class=\"my-4\">More security news<\/h3>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/118651-us-launches-new-cyber-security-agency.html\">US launches new cyber security agency<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/118471-dont-talk-in-front-of-your-smart-tv-it-may-be-listening.html\">Don\u2019t talk in front of your smart TV \u2013 it may be listening<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/118255-adobe-flash-zero-day-exploit.html\">Adobe Flash Zero-Day exploit<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The National Security Agency is being blamed for hiding spying software within hard drives made by Western Digital, Seagate, Toshiba, and other brands<\/p>\n","protected":false},"author":23,"featured_media":77198,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[28919,28917,35,799,9053,18564],"class_list":["post-118985","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-great","tag-hard-drive-firmware","tag-headline","tag-kaspersky-lab","tag-nsa","tag-spyware"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/118985"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=118985"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/118985\/revisions"}],"predecessor-version":[{"id":118999,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/118985\/revisions\/118999"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/77198"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=118985"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=118985"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=118985"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}