Blog | G5 Cyber Security

Thunderbolt devices can infect MacBooks with persistent rootkits

Attackers can infect MacBook computers with highly persistent boot rootkits by connecting malicious devices to them over the Thunderbolt interface. The attack, dubbed Thunderstrike, installs malicious code in a MacBook’s boot ROM (read-only memory), which is stored in a chip on the motherboard. It was devised by a security researcher named Trammell Hudson based on a two-year old vulnerability. The bootkit can even replace Apple’s cryptographic key stored in the ROM with one generated by the attacker.”]

Source: https://www.csoonline.com/article/2862468/thunderbolt-devices-can-infect-macbooks-with-persistent-rootkits.html

Exit mobile version