Researchers detected "backdoors" on Gigabyte motherboards

vulnerability

If exploited, these flaws can allow attackers to gain unauthorized access to sensitive information or generally cause problems

Recently, information was released Eclypsium researchers have identified anomalous behavior in systems with plates «Gigabyte».

The researchers mention that they detected that the "UEFI firmware" used on the plates performed the replacement and launch of the executable file for the Windows platform, all this without informing the user during system startup. In turn, it is mentioned that the launched executable was downloaded from the network and that it subsequently launched third-party executables.

In a more detailed analysis of the situation, it was shown that identical behavior occurs on hundreds of different models of Gigabyte motherboards and is associated with the operation of the company-supplied App Center application.

Recently, the Eclypsium platform began detecting suspicious backdoor behavior within Gigabyte systems in the wild. These detections were driven by heuristic detection methods, which play an important role in detecting new and previously unknown threats in the supply chain, where legitimate third-party products or technology updates have been compromised.

Regarding the process, it is mentioned thate the executable file is incorporated into the UEFI firmware and that this is stored on disk during the system initialization process at boot time. At the driver launch stage (DXE, Driver Execution Environment), using the WpbtDxe.efi firmware module, this file is loaded into memory and written to the WPBT ACPI table, the contents of which are subsequently loaded and executed by the administrator. Windows session manager ( smss.exe, Windows session manager subsystem).

Before loading, the module checks that the "APP Center Download and Install" feature was enabled in the BIOS/UEFI, as by default this is disabled. During startup on the Windows side, the code replaces the executable file on the system, which is registered as a system service.

Our follow-up analysis found that the firmware on Gigabyte systems is downloading and running a native Windows executable during the system startup process, and this executable then downloads and runs additional payloads in an insecure manner.

After starting the GigabyteUpdateService.exe service, the update is downloaded from the Gigabyte servers, but this is done without proper verification of the downloaded data using a digital signature and without using communication channel encryption.

In addition, it is mentioned that downloading via HTTP without encryption was allowed, but even when accessed via HTTPS, the certificate was not verified, allowing the file to be replaced by MITM attacks and to stage its code execution on the user's system.

This backdoor appears to be implementing intentional functionality and would require a firmware update to completely remove it from affected systems. While our ongoing investigation has not confirmed exploitation by a specific hacker, a widespread active backdoor that is difficult to eliminate represents a supply chain risk for organizations with Gigabyte systems. 

To complicate the situation, complete elimination of the problem requires a firmware update, since the logic for executing third-party code is built into the firmware. As a temporary protection against a MITM attack on Gigabyte board users, it is recommended to block the above URLs in the firewall.

Gigabyte is aware of the inadmissibility of the presence in the firmware of such insecure automatic update services and forcibly integrated into the system, since compromising the infrastructure of the company or a member of the supply chain (supply chain) can lead to attacks on users and the organization, since at the moment the launch of malware is not controlled at the operating system level.

As a result, any threat actor can use this to persistently infect vulnerable systems, either through MITM or a compromised infrastructure.

Finally, if you are interested in knowing more about it, you can consult the details In the following link.


Add as preferred source in Google