• yggstyle@lemmy.world
    link
    fedilink
    arrow-up
    43
    arrow-down
    4
    ·
    9 months ago

    Can’t wait until this spurs the security community into doing a deep look at the roms on these cheap Chinese boards. Yeah the malware was caught - but what’s more important is the intent. This is a country that is constantly behind breaches and botnets… and here we have these PCs being marketed as router replacents and mini servers. It doesn’t take much to figure out that this is free back door territory.

    • qaz@lemmy.world
      link
      fedilink
      arrow-up
      9
      ·
      edit-2
      9 months ago

      but what’s more important is the intent

      Afaik, the problem was a trojan inside the cracked windows images they used to avoid paying for windows keys. I doubt the intent was to create a botnet, it seems more like generic cybercrime.

      I personally always wipe the preinstalled OS to avoid issues like this. However, make sure to use a clean image directly from the source. Simply reinstalling from within Windows wouldn’t have helped in this case, because the malware was part of the recovery files.

      The story originated from a video from the “The Net Guy Reviews” YouTube channel. Most articles I’ve seen so far oversimplify the issue and/or get facts wrong, therefore I recommend checking out the original video if you want to learn more.

      • yggstyle@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        9 months ago

        Yeah malware is everywhere - This could simply be a product of an individual actor abusing their position in a supply chain… but this also goes for hardware as well. It is certainly a more difficult vector to attack from but due to its ‘level’ it’s a valuable position to compromise.

  • JCreazy@midwest.social
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    1
    ·
    9 months ago

    Remember kids if you’re going to buy a Chinese pre-built, wipe that shit before use.

    • sylver_dragon@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      9 months ago

      Remember kids if you’re going to buy a Chinese pre-built, wipe that shit before use.

      Always wipe and start fresh. Yes, Chinese brands seem to be worse about security, but there’s no reason to keep bloatware and FSM only know what other crapware the OEM installed.

    • ReversalHatchery@beehaw.org
      link
      fedilink
      arrow-up
      8
      ·
      9 months ago

      To me that always applies, irregardless of the manufacturer. Supply chain attacks are a thing, they are not even necessarily targeted. “I’m not interesting enough” does not apply: everyone has contact with other people, mostly everyone has (or will have) voting rights, and some will have authority over other people.

    • astrsk@kbin.social
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      9 months ago

      Hopefully it’s not built into a rom chip on any number of custom components in these mini PCs making it software independent.

  • Helix 🧬@feddit.de
    link
    fedilink
    English
    arrow-up
    6
    ·
    9 months ago

    Now check the other mini PCs from other random Aliexpress, Banggood, Gearbest and Temu vendors…

  • fin@sh.itjust.works
    link
    fedilink
    arrow-up
    4
    arrow-down
    2
    ·
    9 months ago

    Maybe we should have a working Linux live USB before we buy a new laptop so that we can set it up without connecting it to the home router.

      • Gabu@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        9 months ago

        Which, I would expect, happens to most of these shitty pcs from no-name Chinese brands.

  • Moonrise2473@feddit.it
    link
    fedilink
    arrow-up
    1
    ·
    9 months ago

    I am not saying that the image is to be trusted, but “Win32/Wacatac.B!ml” is just a generic name for anything obfuscated by vmprotect. Most cracks are detected as “Win32/Wacatac.B!ml”

    Also, because it’s detected by microsoft defender itself, if they really had a malicious intent, they would have whitelisted those executables in the disk image.