Windows PCs from ASUS and Gigabyte are being impacted by the "CosmicStrand" UEFI Root

WYP

News Guru
Windows PCs from ASUS and Gigabyte are being impacted by the "CosmicStrand" UEFI Root

The rootkit is currently impacting PCs in China, Vietnam, Iran, and Russia.



Read more on CosmicStrand.
 
So even removing the battery doesn't clean this trash up? Can someone explain this? I would've guessed that the battery keeps the current settings and if it's empty or removed, a default setup will be loaded. So these rootkits can install themselves even into these default setup routines?! Really 2Spooky4Me.
 
This is irrelevant. As per article, it was a targeted attack against some private individuals. It's not something that's meant to infect every machine. Which also means that it most likely wasn't downloaded, but installed on site or prior to whoever purchased the motherboard/PC.

Targeted attacks like this have CIA written all over. And when you see the list of countries where they were found, it's obvious that they're behind it.

And if it's CIA, then it is also very likely that ASUS and Gigabyte know about it and that they assisted them in some way. Just throwing that out there.
 
Last edited:
Back
Top