Researchers use Intel SGX to put malware beyond the reach of antivirus software

Researchers use Intel SGX to put malware beyond the reach of antivirus software

Researchers have found a way to run malicious code on systems with Intel processors in such a way that the malware can’t be analyzed or identified by antivirus software, using the processor’s own features to protect the bad code. As such, the research shows that SGX can be used in a way that isn’t really supposed to be possible: malware can reside within a protected enclave such that the unencrypted code of that malware is never exposed to the host operating system, including antivirus software. Further, the malware isn’t constrained by the enclave: it can subvert the host application to access operating system APIs, opening the door to attacks such as ransomware-style encryption of a victim’s files.

Source: arstechnica.com