/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers Create First Firmware Worm That Attacks Macs

Trammell Hudson's Projects Darlene Storm / Computerworld : Macs can be remotely infected with firmware malware that remains after reformatting JC Torres / SlashGear : These OS X malware are like zombies that refuse to die Aaron Mamiit / Tech Times : Thunderstrike 2 Is The Latest Nightmare Of Mac Owners: What You Should Know About This Deadly Firmware Vlad Dudau / Neowin : Security experts create worm that infects Mac firmware and is nearly impossible to get rid of Mike Beasley / 9to5Mac : Security researchers build on PC vulnerabilities to create first firmware-based Mac worm Oliver Haslam / Redmond Pie : Security Researchers Discover PC Firmware Vulnerabilities In Mac Tyler Lee / Ubergizmo : Researchers Create First Firmware Worm That Can Infect Macs Chris Barylick / O'Grady's PowerPage : Researchers demonstrate proof of concept for firmware worm that can directly target Macs Mark Wilson / BetaNews : Macs are vulnerable to Thunderstrike 2 firmware malware that survives formatting Thomas Fox-Brewster / Forbes : Thunderstrike 2: Remote Attacks Can Now Install Super Stealth ‘Firmworm’ Backdoors On Apple Macs Lee Mathews / Geek.com : Firmware worm that infects Mac cooked up by researchers William White / InvestorPlace : Monday Apple Rumors: Apple May Be Testing Its Own Wireless Network Roger Fingas / AppleInsider : Macs vulnerable to same remote firmware exploits as Windows PCs, researchers find Maya Kamath / TechWorm : Researchers create 'Thunderstrike 2′ the first firmware worm to attack Apple Mac Andrea Peterson / Washington Post : No, your Mac isn't immune to malware Gareth Halfacree / bit-tech.net : Apple machines hit by Thunderstrike 2 ‘firmworm’ Adam Clark Estes / Gizmodo : The World's First Firmware Worm for Mac Is Here, and It Sounds Scary Usman / iPhone in Canada Blog : Researchers Have Developed a Firmware Worm that Attacks Macs Rich Mogull / MacNN : Hacking team creates Thunderstrike-based Mac firmware worm Evan Selleck / iPhone Hacks : The first firmware worm, ‘Thunderstrike 2,’ capable of infecting Macs has been created by researchers Juli Clover / MacRumors : First Firmware Worm Able to Infect Macs Created by Researchers Robert Hackett / Fortune : This Apple computer bug sounds incredibly nasty Stephen Libbey / TechSpot : Researchers demonstrate stealth firmware worm for Macs Mike Wehner / The Daily Dot : Dangerous new flaw proves that Macs aren't as safe as you think Cadie Thompson / Tech Insider : There's a scary worm that can attack your Macs remotely Tweets: Matthew Garrett / @mjg59 : Not that I want to keep on about this or anything, but the attack vector in http://www.wired.com/... is entirely mitigated by UEFI Secure Boot

Wired Kim Zetter

Context & Ripple Effects

Thunderstrike 2 is the second act of a research thread that began when Trammell Hudson showed he could rewrite Mac firmware over Thunderbolt, warning that most Intel Thunderbolt Macs were exposed. The June report of an older-firmware rootkit hole already suggested the layer beneath OS X was reachable; this work turns that access into something self-spreading.

The timing matters because it lands alongside a separate zero-day in fully patched OS X reported the same day — together they sketch a two-stage threat where an OS-level flaw delivers the payload and firmware keeps it alive through reinstalls.

First-order effects

  • Macs infected by the proof-of-concept stay compromised even after the drive is wiped and OS X reinstalled, since the worm lives in firmware rather than on disk.
  • Apple's response surface shifts from shipping OS X patches to validating and updating EFI/Thunderbolt firmware across its installed base, a slower and riskier fix path.

Second-order effects

  • Because Thunderstrike 2 behaves as a worm, an infected accessory or machine can carry the payload to other Macs, making shared hardware and peripheral supply chains part of the threat model for enterprise buyers who previously treated Macs as low-risk fleet devices.
  • Security vendors have to add pre-boot firmware scanning to Mac tooling, since disk-level antivirus cannot see or remove what sits below the operating system.

Third-order effects

  • The pattern points to firmware becoming the durable battleground: researchers later found an alarming number of Macs still exposed through outdated EFI firmware years after these disclosures, showing that patching below the OS lags badly without vendor-enforced update mechanisms.

The trend: Malware research is moving beneath the operating system into firmware, where reformatting offers no cure and the burden of remediation falls on hardware makers like Apple.