Bootkit-in-front-of-a-bootkit
Enterprise server platforms are the bedrock of the modern internet. It would stand to reason that the foundation of IT infrastructure, the firmware and hardware of those systems, would be especially well audited and secured against advanced attackers. Unfortunately, history shows that the resilience of these components has suffered from an ever-increasing attack surface and insufficient scrutiny; today, this trend is only accelerating with the mass adoption of complex AI infrastructure at unprecedented rates.
In this work, we focus on analyzing the security of the Data Processing Unit (DPU), which has become ubiquitous in AI datacenters. This computer-in-front-of-a-computer promises to shield its host server by offloading networking, encryption, and security-related logic away from the host processor. But what happens when the DPU itself becomes the weak link? In this presentation, we demonstrate a UEFI secure boot bypass on the Nvidia Bluefield 3 DPU, and use it to build the first known DPU bootkit. We then show how it is possible to launch a DMA attack from the DPU targeting the host.
About the Presenter: Stas Lyakhov
Stas is a security researcher at Eclypsium. With a background in cryptography, reverse engineering, and hardware fault injection, he eventually found his way to tearing apart firmware. He now spends his time assessing the security of embedded devices up and down the stack. On the side, Stas enjoys programming in memory-safe languages and experimenting in the NixOS ecosystem, where he maintains the chipsec package.
About the Presenter: Jesse Michael
Jesse is an experienced security researcher focused on vulnerability detection and mitigation who has worked at all layers of modern computing environments from exploiting worldwide corporate network infrastructure down to hunting vulnerabilities inside processors at the hardware design level. His primary areas of expertise include reverse engineering embedded firmware and exploit development. He has also presented research at DEF CON, Black Hat, PacSec, Hackito Ergo Sum, Ekoparty, and BSides Portland.

