HP iLO Rootkit
-
https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/
In this report, we analyze a rootkit discovered in-the-wild that hides inside the iLO, cannot be removed by firmware upgrades and can be hidden from the sight for a long time. This malware has been used by hackers for some time and we have been monitoring its performance. As far as we know, this is the first report of the discovery of real-world malware in iLO firmware in the world.
-
Appears to require admin access in order to install so not sure how prevalent this could actually be.
-
There have been numerous elevation of privileges flaws.
I'm more curious if it could through a hypervisor?