Intel investigating BootGuard security key leak following MSI hack

Ransomware
(Image credit: Pixabay)

Intel is allegedly investigating a data leak that saw sensitive BootGuard private keys published on the dark web. 

These private keys are designed to protect the devices from UEFI bootkits, malicious software that’s installed on the device’s firmware, establishing persistence even if the hard drive is replaced. 

The news was broken by BleepingComputer, without elaborating what this investigation entails. In response to the attack, Intel told the publication “it should be noted that Intel BootGuard OEM keys are generated by the system manufacturer, and these are not Intel signing keys."

Useless features

What we do know is that a ransomware operator known as Money Message broke into hardware manufacturer MSI earlier this year and stole sensitive data. 

The group claims it made away with 1.5TB of sensitive information, including source code, firmware intel, and various databases. In order not to publish the stolen files on the dark web, the group allegedly demanded $4 million in ransom.

MSI turned the offer down, claiming the attack and the stolen files represented no real threat to its business operations. In response, the threat actors made the files public.

After that, different cybersecurity researchers started analyzing the leaked data, with some finding what appear to be image signing private keys for 57 MSI products and Intel Boot Guard private keys for 116 MSI products.

Researcher Alex Matrosov told BleepingComputer that the leak could render Boot Guard ineffective on “11th Tiger Lake, 12th Adler Lake, and 13th Raptor Lake" processors.

"We have evidence the whole Intel ecosystem is impacted by this MSI data breach. It's a direct threat to MSI customers and unfortunately not only to them," he said. "The signing keys for fw image allow an attacker to craft malicious firmware updates and it can be delivered through a normal bios update process with MSI update tools."

"The Intel Boot Guard keys leak impacts the whole ecosystem (not only MSI) and makes this security feature useless."

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
New UEFI Secure Boot flaw exposes systems to bootkits
Security
Intel slams Nvidia and AMD, claims chip giants have huge numbers of security flaws
HPE
HPE investigating claims that hacker breached developer environments, source code
Skull and Bones
Experts warn DNA sequencers are vulnerable to bootkit attacks
AMD Ryzen 5 7600X processor
AMD confirms processor security flaws after Asus patch slips out early
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening