Platinum Chip

Intel AMT abused to deliver Windows exploits

A short update to my last post about Intel ME:

Microsoft has recently reported that a hacker group known as Platinum has been able to exploit AMT's Serial-over-LAN (SOL) feature to transfer malware payloads on local networks.

According to the Register, Infected systems can also communicate with other machines over LAN via any physical connection - regardless of the host machine's networking status, as a consequence of AMT's remote management features - and could possibly also enable an exploitable subset og AMT on other machines in order to exploit them.

Microsoft and Intel said that "this isn’t a vulnerability in AMT, but an abuse of its capabilities", according to Threatpost.

