Skip to main content

Pre-boot malware Nemesis targets financial systems with data theft

researchers use ambient light sensor data to steal browser exhausted man computer problems desk hacking hackers malware frust
Shutterstock
One of the more interesting revelations about the snooping tactics employed by the NSA over the past few years was that the agency had managed to install malware into hard-drive firmware in order to get around deletion during formats. While not as complicated as that, Nemesis malware uses a similar system by hiding outside the reaches of normal clean-ups, dodging even operating system reinstalls by hiding in the boot-record.

IT professionals who don’t want the malware equivalent of the Nemesis character pictured above rampaging within the systems they manage will be on guard against this possibility.

Nemesis is in actuality a collection of programs and malware that is capable of doing lots of different things. It can transfer files around, capture screenshots and keystrokes, inject processes, and even capture financial data from a system. It’s designed to hide away on banking systems and siphon off funds and financially important information for the nefarious individuals behind its injection.

And by hiding itself within the boot-record of a system, it’s able to avoid traditional detection techniques, starting up before the OS has even thought about launching defensive countermeasures.

With that in mind, preventing an infection like this is the best way to avoid its associated issues, while clearing it out after it’s taken hold is much harder. It certainly requires a different approach than usual, as the team at FireEye discussed in their recent exposé (via Ars) on the malware bootkit. Any users who believes their systems are infected with such malware will need to do a complete drive wipe to make sure it’s cleared out.

This will be a process that’s a little more well known among SSD users, as a zeroing of the drive can often improve performance — even if the drive is TRIM enabled. However, it may be more daunting for enterprises or businesses that are more used to ghosting a drive from one system to another without ever starting from scratch.

This isn’t necessarily something that those running modern operating systems need to worry about though. Windows 8 and 10 both utilize Secure Boot, which prevents a replacement of the Windows bootkit from being launched.

That’s perhaps why the bootkit targets enterprise systems and financial services, which have a history of running older operating systems. Yet another good reason to stay up to date with your operating system, as well as with drivers and anti-malware software.

Editors' Recommendations

Jon Martindale
Jon Martindale is the Evergreen Coordinator for Computing, overseeing a team of writers addressing all the latest how to…
Get this Asus laptop with a year of Microsoft Office for $199
asus vivobook go laptop deal amazon march 2024 lifestyle

You don't need to spend several hundreds of dollars on a new laptop that you'll use as a productivity tool because there are budget-friendly options like the Asus Vivobook Go L510MA. It's actually currently even cheaper from Walmart after an $80 discount, which brings its price down to just $199 from $279 originally. There's no telling how much time is remaining before the offer expires though, so if you want to take advantage of it, you're going to have to proceed with the purchase as soon as possible.

Why you should buy the Asus Vivobook Go L510MA
For a laptop that will be able to handle basic activities like doing online research, building reports, and browsing social media, you can't go wrong with the Asus Vivobook Go L510MA. It's equipped with the Intel Pentium Silver N5030 processor and 4GB of RAM, which are a far cry from the specifications of the best laptops, but it will be enough for simple tasks. The device also comes with a 15.6-inch screen with Full HD resolution, which is pretty large and sharp for its price, but it's still portable as it only weights about 3.5 pounds with a thickness of just 0.72 of an inch.

Read more
These are the 10 best gaming PCs I’d recommend to anyone
Graphics card in the CLX Hathor PC.

We review dozens of gaming PCs each year. In 2024, there are a ton of great options, but we've narrowed them down to a list of the 10 best gaming desktops that deserve your hard-earned money.

In 2024, we still recommend the Alienware Aurora R16 because of its fantastic design, solid performance, and decent value. However, there are several other options depending on your needs and budget. If you want a deeper look into how we evaluate gaming PCs, make sure to read about how we review desktops.

Read more
Samsung’s crazy 57-inch curved 4K monitor is $700 off today
The Samsung Odyssey Neo G9 57-inch mini-LED gaming monitor placed on a desk.

Your investment in gaming PC deals will  go to waste if you don't upgrade your screen, and if you're willing to splurge for the best possible gaming experience, you'll want to go for the 57-inch Samsung Odyssey Neo G9 curved gaming monitor. It's pretty expensive at its original price of $2,500, so you're going to want to take advantage of any discounts that are available. Fortunately, Samsung has slashed its price by $700 so it's down to $1,800 -- it's still not cheap, but once you're playing your favorite games on this monitor, you'll quickly understand why it's worth every single penny.

Why you should buy the 57-inch Samsung Odyssey Neo G9 curved gaming monitor
The Samsung Odyssey Neo G9 curved gaming monitor features a 57-inch screen with dual 4K Ultra HD resolution and a 1000R curvature, so it will fully immerse you in the worlds of the video games that you play with its lifelike details and vivid colors. It also supports HDR 1000 for better visual accuracy, and it uses Quantum Matrix technology for controlled brightness and improved contrast.

Read more