HomeSecurityFirmware of several types of hard drives modified with malware

Firmware of several types of hard drives modified with malware

A highly advanced cyberespionage group called Equation modified hard drive firmware, potentially infecting thousands of computers in sensitive industries around the world.

Hard Drives Firmware - Malware
The list of tampered storage drives includes devices manufactured by: Seagate, Western Digital, Toshiba, Maxtor, Micron, Samsung and IBM.

Among the tools used by the team is a module called “nls_933w.dll,” whose purpose is to “reprogram the firmware for several different brands of hard drives.”

Kaspersky says that this module is perhaps the most powerful in use and that it represents a technical achievement that demonstrates the level of sophistication of the team's capabilities.

By implanting the infection into the hard drive firmware, Equation ensured its presence in the system until the storage drive was replaced, since wiping the hard drive and/or reinstalling the operating system would have no effect and the infection would persist.

Researchers identified two malicious modules that could reprogram the hard drive firmware, one of which was written in 2013 and is located on the GrayFish malware platform and is capable of affecting at least 12 brands.

The first version was detected on the EquationDrug platform and researchers found a compilation date from 2010. It affected a total of six brands of the hard drive.

Reprogramming the software of storage devices allows cybercriminals to create a hidden data storage space isolated from the operating system and which could only be accessed through special methods created by them.

The affected units are used by government and diplomatic institutions, telecommunications companies, organizations operating in sectors such as aerospace, energy, nuclear research, oil and gas, military, nanotechnology, transportation, the financial sector, or entities developing encryption technologies.

Security researchers found evidence that the Equation group relies on malware pieces that were assembled in 2002, although the Command & Control server (C&C server) used to transmit the data was registered in 2001. However, they also found that other C&C servers used by the group had been registered since 1996, suggesting that the group has been active for almost 20 years.

A total of six Trojans have been identified by researchers (named EquationLaser, EquationDrug, DoubleFantasy, TripleFantasy, Fanny, and GrayFish by Kaspersky), but their number is likely higher.

In a blog post published on Monday, Kaspersky says Equation has worked with the teams behind Stuxnet and Flame, "always from a position of superiority, as they had access to the exploits earlier than others."

The connection to the Stuxnet perpetrators was discovered in the Fanny worm, which was detected in December 2008. Fanny used two of the zero-day exploits as a tool to attack the Iranian nuclear facility at Natanz. In addition, Fanny was spread via the LNK exploit kit used in the Stuxnet attack.

It is important to note that the exploits were first incorporated into Fanny, and then observed in early versions of Stuxnet. This indicates that the Equation team had access to the vulnerabilities before the team behind Stuxnet.

The fact that the various worms used the same exploits at roughly the same time period leads to the conclusion that the Equation team members and the Stuxnet developers are either the same people or working together, Kaspersky says.

Stuxnet is believed to be part of a joint effort between the NSA, CIA and Israeli counterintelligence. Kaspersky does not attribute this anywhere in its analysis, but it does cite details that point to tools included in a leaked list of utilities used by the NSA.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS