Among the end-users of those infected servers were Apple, Amazon and even the US military. To put into perspective the gravity of the attack in simplified terms, the microchips can manipulate the instructions of the operating system when they transit between the RAM and the CPU of the infected server. This allows a remote attacker to intercept logins and passwords to the infected machine and therefore have access to its content. This tampering leaves critical data of Supermicro’s customers vulnerable to the PLA’s intelligence officers.

Hardware attacks are quite common for targeted intelligence gathering, but they are usually done after the final product has left the factory and is en route to its final user. Among the Snowden leaks, lays a catalog that details the hardware attack angles an American intelligence officer had in 2008 to target networks and specified computers of foreign companies and governments. This historic perspective shows that this case not an isolated event but a worrying development for businesses and consumers of a lasting issue; the collateral damage of cyberwarfare.
To sum up, the main story of the article and this historic example highlight the strong necessity of control of all the actors on the supply chain, from the designer to the final customer to maintain critical infrastructure out of harm’s way. Trust along the supply chain is gone, and hardware manufacturers will need to improve and differentiate themselves by including extensive audits in the hardware they sell or use.
Bernhard Bieri
