Straight dope on badBIOS?

Computer Security expert Dragos Ruiu apparently stumbled upon some especially nasty and covert piece of malware. He named it badBIOS.

I am not an expert but this story sounds fishy. Apparently this malware can:

  1. Infect Windows, macOS and BSD
  2. Infect PCs and MACs on BIOS level
  3. Instantly infect a computer by simply inserting an infected USB stick
  4. Establish communication between infected computers by using the microphone and speakers to emit and detect ultrasounds (some kind of acoustic coupling)

Does all that seem plausible?

Previous thread.

My Numbers refer to the items above

  1. Sound transmission ? No way. His credibility is totally shot if he thinks that this could even possibly exist.

  2. Seems strange . Normally they only target one OS only.

  3. No , each individual version of BIOS would require individual approaches.
    That is, for each motherboard/computer model, there may be a few different versions, early, first half and 2nd half. (products last on sale for about a year, so the halves would be the first half year and 2nd half year ?)

  4. No . well there was a particular computer that did always execute code on the USB but that was one particular model - too rare.

1. Infect Windows, macOS and BSD

Not impossible, but not at all likely.

2. Infect PCs and MACs on BIOS level

There is no universal BIOS standard. Different BIOS chips are programmed in different ways. I’m extremely skeptical about this one.

3. Instantly infect a computer by simply inserting an infected USB stick

Yep. This happens all the time.

4. Establish communication between infected computers by using the microphone and speakers to emit and detect ultrasounds (some kind of acoustic coupling)

Not impossible, but I’m very skeptical. Most computer hardware doesn’t work up into the ultrasonic range very well, if at all.

My best guess at this point - they have a virus and they keep re-infecting their systems in conventional ways. Either that or it’s all a bunch of hooey.