iLOBleed Rootkit Targets Hewlett-Packard Servers

In the last days of 2021, malware researchers have identified yet another Windows threat. However, it seems to lack compatibility and, instead, it targets one particular set of systems – HP devices running the Integrated Lights-Out (iLO) server management technology. Hence the name of the implant, the iLOBleed Rootkit.

Rootkits are a type of malware, which specialize in granting their operators long-term, privileged access to the compromised device. In addition to this, they are extra difficult to identify and remove due to their ability to conceal their components in firmware, drivers, and even operating system components. The situation with the iLOBleed Rootkit is not any different – it is able to hijack the Integrated Lights-Out firmware in HP devices.

iLOBleed Deploys Wipers to Infected Systems

Often, rootkit is used for espionage, but the authors of the iLOBleed Rootkit appear to have different plans. Although the implant enables them to perform a wide range of tasks on compromised servers, the criminals are opting to wipe the data of their victims. It is not clear what sort of wiper they use, and whether it is a previously known malware family, or a custom-built script. Regardless of their approach, it is clear that the iLOBleed Rootkit can carry out a devastating attack.

The first variants of the iLOBleed Rootkit were compiled in the summer of 2020, but the payload has undergone significant updates since then. There is no information about the delivery mechanism that the criminals use, and how the rootkit gets planted on company servers. Of course, as a preventive measure, network administrators should enhance the security of the systems.

January 3, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.