Academics from Graz University of Technology, the University of Birmingham and the CISPA Helmholtz Center for Information Security yesterday revealed a new type of attack through which hackers can steal data from Intel CPUs. The attack, dubbed “Platypus” (Power Leakage Attacks: Targeting Your Protected User Secrets) , targets the RAPL interface of Intel CPUs.
RAPL, which stands for Average Power Operation Limit, is a feature that allows firmware or software to monitor power consumption on the CPU and DRAM. RAPL, which effectively allows firmware and software applications to read how much electrical power a CPU is using to perform its tasks, is a system that has been used for years to monitor and troubleshoot application and hardware performance.

The team of academics revealed how the new type of attack called “Platypus” can be used to determine what data is being processed inside a CPU by looking at values reported through the RAPL interface.
Access to this type of data is protected by many security mechanisms, such as kernel address space layout randomization (KASLR) or hardware-such as Intel SGX. However, the researchers reported that the “Platypus” attack allows an attacker to bypass all of these mechanisms by examining variations in power consumption values.
In tests, the researchers bypassed KASLR by observing RAPL power consumption values for just 20 seconds and then recovered data from the Linux. In another test, they also recovered data being processed in Intel SGX secure sockets.

A “Platypus” attack that recovered RSA private keys from an SGX pod required the attacker to monitor RAPL data for 100 minutes, while an attack that recovered encryption from an SGX pod and the Linux kernel memory space took 26 hours. The “Platypus” attack, named for the animal’s ability to sense electricity with its beak, is the first of its kind.
While other research groups have been able to observe CPU power measurements by attaching oscilloscopes to CPUs, “Platypus” attacks can be carried out remotely. For example, the attack code can be “packaged” into malicious applications that are installed or deployed on a targeted device. This way, the attack can be carried out without a hacker having to gain physical access to the target system.

Moritz Lipp, one of the researchers who worked on both Platypus and PlunderVolt, told ZDNet that Platypus is different from PlunderVolt, another attack against the power voltage interface of Intel CPUs. However, the two attacks are different. The difference is that PlunderVolt is an active attack that modifies power values, while Platypus is a passive attack that injects data just by looking at power consumption data.
The researchers noted that Platypus works against Intel servers, as well as desktops and laptops. Intel confirmed that some portable and embedded CPUs are also affected. The chipmaker yesterday released microcode updates to block “Platypus” attacks, which the company has made available to industry partners to include in their next security updates for their products. The updates for the “Platypus” attacks targeting Intel CPUs will contain references to CVE-2020-8694 (Linux + Intel), CVE-2020-8695 (Intel) and CVE-2020-12912 (Linux + AMD) – which are believed to have been exploited by hackers to carry out the attack.
