Monday, May 11, 2015

Linux Rootkit Targeting GPU.


           Traditional Malwares and Rootkits were developed to attack the CPU of the system and cause mass destruction. Recently a rootkit along with a keylogger has been developed that targets GPU.

            GPU stands for Graphical Processing Unit and it is a separate unit from CPU that looks after all the Graphical works that has been carried out by the computer. The newly developed rootkit and keylogger has excellent stealth feature and also excellent computational power.

            There are two pieces of this Malware. They are

1. Jellyfish Rootkit for Linux 
2. Demon Keylogger

            Jellyfish Rootkit makes the users to believe that GPU can be attacked with malware as it contains dedicated processors and memory. They do not interrupt the normal working of the CPU thus it will not raise any suspicious behaviour.

            Jellyfish rootkit can access the memory without accessing CPU thus undetectable. Another main feature of exploiting the GPU is that the malware will reside in the GPU storage area even after the power shut down.

            Demon Keylogger is also a keylogger that resides in the GPU of the system and the working has been similar to that of the traditional keylogger.

            The proof of concept has been made public and has been available in GitHub. 

             There has been no infection or any full fledged working GPU malware but it is just a start by cyber criminals that this can also be done.

P.S : The post is to create awareness and not to be misused.

            


           


            

No comments:

Post a Comment