|
In just the last two months, the cybercriminal-controlled botnet known as TrickBot has become, by some measures, public enemy number one for the cybersecurity community. It's survived takedown attempts by Microsoft, a supergroup of security firms, and even US Cyber Command. Now it appears the hackers behind TrickBot are trying a new technique to infect the deepest recesses of infected machines, reaching beyond their operating systems and into their firmware. Security firms AdvIntel and Eclypsium today revealed that they've spotted a new component of the trojan that TrickBot hackers use to infect machines. The previously undiscovered module checks victim computers for vulnerabilities that would allow the hackers to plant a backdoor in deep-seated code known as the Unified Extensible Firmware Interface, which is responsible for loading a device's operating system when it boots up. Because the UEFI sits on a chip on the computer’s motherboard outside of its hard drive, planting malicious code there would allow TrickBot to evade most antivirus detection, software updates, or even a total wipe and reinstallation of the computer's operating system. It could alternatively be used to "brick" target computers, corrupting their firmware to the degree that the motherboard would need to be replaced. The TrickBot operators' use of that technique, which the researchers are calling "TrickBoot," makes the hacker group just one of a handful—and the first that's not state-sponsored—to have experimented in the wild with UEFI-targeted malware, says Vitali Kremez, a cybersecurity researcher for AdvIntel and the company's CEO. But TrickBoot also represents an insidious new tool in the hands of a brazen group of criminals—one that's already used its foothold inside organizations to plant ransomware and partnered with theft-focused North Korean hackers. "The group is looking for novel ways to get very advanced persistence on systems, to survive any software updates and get inside the core of the firmware," says Kremez. If they can successfully penetrate a victim machine's firmware, Kremez adds, "the possibilities are endless, from destruction to basically complete system takeover." While TrickBoot checks for a vulnerable UEFI, the researchers have not yet observed the actual code that would compromise it. Kremez believes hackers are likely downloading a firmware-hacking payload only to certain vulnerable computers once they're identified. "We think they've been handpicking high-value targets of interest," he says. The hackers behind TrickBot, generally believed to be Russia-based, have gained a reputation as some of the most dangerous cybercriminal hackers on the internet. Their botnet, which at its peak has included more than a million enslaved machines, has been used to plant ransomware like Ryuk and Conti inside the networks of countless victims, including hospitals and medical research facilities. The botnet was considered menacing enough that two distinct operations attempted to disrupt it in October: One, carried out by a group of companies including Microsoft, ESET, Symantec, and Lumen Technologies, sought to use court orders to cut TrickBot's connections to the US-based command-and-control servers. Another simultaneous operation by US Cyber Command essentially hacked the botnet, sending new configuration files to its compromised computers designed to cut them off from the TrickBot operators. It's not clear to what degree the hackers have rebuilt TrickBot, though they have added at least 30,000 victims to their collection since then by compromising new computers or buying access from other hackers, according to security firm Hold Security. AdvIntel's Kremez came upon the new firmware-focused feature of TrickBot—whose modular design allows it to download new components on the fly to victim computers—in a sample of the malware in late October, just after the two attempted takedown operations. He believes it may be part of an attempt by TrickBot's operators to gain a foothold that can survive on target machines despite their malware's growing notoriety throughout the security industry. "Because the whole world is watching, they've lost a lot of bots," says Kremez. "So their malware needs to be stealthy, and that's why we believe they focused on this module." To learn more visit OUR FORUM. Windows 10 isn’t as sluggish and bloated as some versions that have come before. Which means you shouldn’t have any serious performance complaints. Then again, why leave free performance on the table by running unnecessary services? There’s a long list of Windows 10 services that most users don’t need. So you can safely disable these unnecessary Windows 10 services and satisfy your craving for pure speed. Some Common Sense Advice First, Windows services all have specific jobs. Some of these jobs are critical for your computer to work properly. If you disable a Windows service that’s needed for the normal operation of your computer, you can get locked out of your machine or may have to undo what you’ve done. We tested disabling all the unnecessary services listed below via the Services app on our computer. However, we can’t take any responsibility for something going wrong with your specific machine. Don’t mess around with random services not listed here and always create a system restore point or system backup before making changes. We rate a process as “safe to disable” if it doesn’t affect the core functionality of your computer, but we don’t recommend that you actually disable every single one of these services since they are not harmful and can be useful too. Do you have a printer? Do you ever use it? Printers are becoming a niche item as we all transition to paperless documentation and use smartphone cameras to scan documents. If you don’t use a printer then you can safely disable the print spooler. This is a service that manages and queues print jobs. Without any print jobs to process, it just sits there using up RAM and CPU time. Windows Image Acquisition is the service that waits until you press the button on your scanner and then manages the process of getting the image where it needs to go. This also affects communication with digital cameras and video cameras that you connect directly to your computer, so be aware of that if you need this function. Unbelievably, there are actually plenty of businesses that still use fax machines. Fax usage is very niche, however, so it’s almost certain that you don’t need fax services on your computer. If you are one of the five people sending and receiving faxes from your computer, well then this doesn’t apply to you. Also, buy a scanner instead. It’s safe to disable the Bluetooth service if you don’t need it. It can be a precaution against Bluetooth attacks too. These days Bluetooth devices such as mice, game controllers, and headphones are common. So only a small number of users who never use Bluetooth should consider this. Windows Search is safe to disable and can have a noticeable effect on your performance because it also disables the Windows search indexer. It’s not something we recommend most people do, however. Instant, fast search performance is one of the best features of Windows 10. It’s an option if you don’t make much use of Windows search or your CPU is really slow. Go ahead and disable it to see if it boosts performance. Windows sends an error report back to Microsoft when things go wrong. Microsoft uses this information to fix problems in future updates. Some people have a privacy issue with this and choose not to send reports. If you don’t want to send error reports to Microsoft, you can go beyond selecting Don’t send every time and disable the entire service. Disabling these services won’t give you drastic speed boosts. Though, you can get an extra frame or two out of your video games or open even more tabs in your browser. There are several more services you can stop. But, we strongly recommend against messing with the Windows services you are unsure about. It’s especially risky to disable services that are essential to your hardware, such as those related to your graphics card. Always research a given Windows service before you disable it. For more Windows 10 Services that can be disabled visit OUR FORUM.
What do Cristiano Ronaldo, Bruno Mars, and Windows have in common? They're all 35 years old. It is three and a half decades since Microsoft Windows 1.0 was unleashed upon an unsuspecting world. Tottering atop MS-DOS, Windows 1.0 was released on 20 November 1985. A graphical multitasking shell, it would usher in an era of dominance on the PC that lingers on today. The secret sauce was IBM support, which brought a huge chunk of the business world along, for better or worse. Not that dominance was a sure thing back then. Windows 1.0 was by no means the only game in town: this hack has fond memories of GEM (Graphics Environment Manager) which turned up in computers from Amstrad to the Atari ST. At the time Windows was one among many, and it would take a good few iterations before the 3.x line began to dominate. First shown off two years previously, Windows 1.0 would run on 256KB of RAM and a pair of floppy drives (later versions would require a hard disk) and, most significantly, require the user to move a mouse-pointer to make things happen in the 16-bit shell. At least 512KB was needed before performance improved beyond dragging Notepad through treacle. Windows 1.0 also suffered from an initial paucity of apps, with the likes of Calculator and Paint coming in the box while many MS-DOS applications would fire up in full-screen mode. The GUI also insisted on tiling the windows - no overlapping was allowed other than dialogs. After a number of incremental improvements, Windows 1.0 was replaced by Windows 2.0 in 1987, although it lingered on until support for it (as well as versions 2.0 and 3.0) ended in 2001. Windows was the mainstay of Microsoft profits in the 90s, thanks to some sharp elbows on the OEM front from its legal department. The money rolled in, and Redmond wanted more. When smarter mobile phones started kicking off in the late 90s, Microsoft made its first of many failed attempted to break into the mobile market with Windows CE or WinCE as it became known. It didn't last long, despite some notable handsets, but Microsoft kept trying. Enthused by then-CEO Steve Ballmer, who had originally dismissed the iPhone, Microsoft tried again with Windows Phone 7, launched in 2010. Despite excellent hardware from Nokia, which Redmond bought and then gutted, the OS never caught on with developers, and a lack of backward compatibility with the new kit killed demand. As for tablets, Redmond first dipped Windows' toe into the market in 2003 with the Microsoft Tablet PC. Redmond has kept up its interest in this area - and the latest Surface fondle slabs are very nice, if expensive, pieces of kit. Now Windows has evolved into a cloud operating system and is maintaining its position in the mainstream. Microsoft has managed to make the transition from in-box code to cloud better than most, albeit a bit late. Ray Ozzie, hired as Microsoft's cloud guru in 2006, saw the writing on the wall and warned Redmond that Windows would have to get cloudy. He was forced out, although not before founding Azure, the smart folks took note - not least Satya Nadella, who is cloud to the core. It seems odd that senior Windows coders now weren't even a glint in the milkman's eye when the first build of the OS came into being. But the effect of the operating system is undeniable. Looking back, Windows 1.0 was a curiosity in spite of the enthusiasm for the product by Microsoft boss, Bill Gates. Business users were content to stick with DOS while consumers looked to alternatives, including the likes of Atari or Commodore, for their home computing fun. However, Windows 1.0 marked a change for Microsoft and an attempt to focus more on applications. APIs for video and mouse hardware moved things on from the DOS environment and PC software and hardware makers would flock to the platform as the decades rolled by. For better or for worse. Complete details are posted on OUR FORUM. |
Latest Articles
|


