How to Avoid an Evil-Maid Attack | Total Security

How to Avoid an Evil-Maid Attack | Total Security


Protect Your Business Computers From Unauthorized Physical Access. 

An Evil-Maid attack is the most primitive type of attack there is, but it is also one of the most unpleasant. Watching out for her prey (a device left unattended), the "malicious maid" tries to steal confidential information or install spyware or a remote access tool to enter the corporate network. This article will show you how to protect yourself from intruders.


Classic Example

In December 2007, a delegation from the US Department of Commerce visited Beijing to discuss the common strategy to be adopted to combat piracy. However, when he returned to the United States, the secretary's laptop had spyware that could only be installed by someone who had physical access to the device. The owner of the laptop said he never left the device throughout negotiations and only left it in his (safe) hotel room during meal times on the ground floor.


In theory, a professional only needs 3-4 minutes to infect a device, but things like this tend to happen when the computer is left unattended and unlocked (or not password protected). . Even when basic safety precautions are followed closely, the attack by the malicious maid is likely to be successful.


How Cyber ​​Criminals Access Information

There are many methods of obtaining sensitive information. They depend on the age of the computer and the security software installed. For example, old devices incompatible with Secure Boot can be restarted from external devices and find themselves powerless against Evil-Maid attacks. Secure Boot is usually enabled by default on modern computers.


Communication ports compatible with fast data exchange or direct interaction with device memory can be used as siphons to extract personal data or trade secrets. Thunderbolt, for example, has a very fast data transmission speed thanks to direct memory access, which opens the door to Evil-Maid-type attacks.


Last spring, IT security expert Björn Ruytenberg explained how to hack any active Thunderbolt in a Windows or Linux device, even if it is locked and connections from unknown devices through external ports are disabled. Gutenberg's method, nicknamed Thunderspy, assumes that the scammer can physically access the device and must rewrite the controller firmware.


With Thunderspy, the cybercriminal has to reprogram the Thunderbolt chip with their firmware version. The new program disables the built-in protection and the hacker takes full control of the device.


In theory, the kernel's DMA protection policy fixes the vulnerability but some users do not use it (and those with an operating system older than Windows 10 cannot install it). However, Intel announced a solution to the problem: Thunderbolt 4.


A good old USB drive can also be an attack vector. A miniature device, inserted into a USB port, activates when the user turns on the computer and launches the BadUSB attack.


If the information that the cybercriminal seeks to obtain is very valuable, he may even try to perform a particularly difficult and expensive task: steal the device and replace it with a similar one that already contains the spyware. It is true that the victim will quickly realize it but in general, it only happens after he has entered the password. Fortunately, as we have pointed out, it is both complicated and expensive to set up such an exchange.


How To Reduce The Risks

The easiest and most effective way to protect yourself from Evil-Maid attacks is to keep your computer in a safe place that no one else has access to except you. For example, if possible, avoid leaving it in your hotel room. On the other hand, if your employees need to take a business trip and borrow the company's laptops, here are some tips to reduce the risk:


Use temporary laptops that don't have access to critical business systems or work data, then format the hard drive and reinstall the operating system after each trip.

Ask your employees to turn off laptops as soon as they leave them.

Encrypt the hard drives of all computers that leave company offices.

Install security solutions that block any suspicious outgoing traffic.

Check that your security solution detects BadUSB attacks (which is the case with  Protegent360 Total Security for Business )

Update all programs, especially the operating system, as soon as possible.

Limit direct access to device memory through FireWire, Thunderbolt, PCI, and PCI Express ports on all devices that allow it.


Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software