FireEye has uncovered a new piece of malware targeting financial institutions that it's calling Nemesis. This strain of malware is made by a group FireEye calls FIN1, and it's a particularly nasty bug. Once it's introduced to a system, Nemesis hooks into Windows' boot process while remaining next to undetectable from inside the OS. The FIN1 attackers can then exfiltrate nearly any piece of data from an infected system.
Nemesis accomplishes its nefarious task by replacing Windows' MBR. The malware first installs its own custom file system in the free space between disk partitions before hijacking the machine's MBR and redirecting the boot process through its own code. When the infected machine boots up, it also fires up Nemesis. The malware brings up its own virtual system and a number of BIOS-related hooks before passing control back to the Windows boot loader. Nemesis doesn't stop there, though—the several hooks it uses allow it to piggyback several of its components onto Windows' kernel-loading process.
According to FireEye, Nemesis' capabilities include file transfer, screen and keystroke capture, process manipulation, and task scheduling. Since Nemesis' boot code executes before Windows loads and the malware components are stored in its own virtual file system or Windows' registry, it's very hard for anti-virus packages to detect it. To make matters worse, reinstalling the operating system accomplishes nothing—only a full disk wipe will give any guarantee of removing the boot code. Nuking it from orbit is the only way to be sure.
Not all hope is lost, though. Nemesis doesn't install itself on GPT disks, and although FireEye didn't specifically say so, it's possible that UEFI Secure Boot could stop the malware dead in its tracks.
|TR's 2017 Christmas giveaway: eight days left and counting||3|
|Rumor: Ryzen 2 set for Q1 2018 and a Fenghuang APU breaks cover||4|
|MSI gives Radeon RX Vega cards an Air Boost||11|
|Corsair's latest SO-DIMM kit takes 32 GB of DDR4 to 4000 MT/s||2|
|Report: Intel Inside co-marketing program will get a budget cut||26|
|Gingerbread House Day Shortbread||16|
|iMac Pro details and release date come into focus||48|
|Radeon Software Adrenalin Edition: an overview||25|
|Tuesday deals: NVMe storage, a GeForce GTX 1080 Ti, and more||9|
|Full disclosure: while I work for Intel; the opinions I express here are my own I think I understanding the issue you ran into. For the Braswell platf...||+35|