Most computer devices come with an anti-theft solution called Computrace enabled by default, capable to execute arbitrary code with local system privileges, which does not encrypt communication with a remote server.
In a presentation at Black Hat security conference in Las Vegas last week, Kaspersky security experts Vitaly Kamluk and Sergey Belov, along with Anibal Sacco from Cubica Labs, demonstrated how legitimate software Computrace, which is part of the BIOS firmware, can be used as ldqu…