A security researcher has presented a technique dubbed Thunderstrike hack to infect Apple’s Mac PCs with with EFI Bootkit through the Thunderbolt port.

Infect Apple Mac PCs exploiting the Thunderbolt port is possible, the security researcher Trammell Hudson has demonstrated how it is possible during the last edition of the annual Chaos Computer Congress in Hamburg, Germany.

The researcher has demonstrated that it is possible to exploit the port by rewriting the firmware of an Intel Thunderbolt Mac. The hack, called Thunderstrike, exploit a well-known vulnerability in the Thunderbolt Option ROM that was first disclosed in 2012, but that still affects Apple Mac systems. Thunderstrike can infect the Apple

The Thunderstrike hack allows the attacker to infect the Apple Extensible Firmware Interface (EFI) by injecting the malware into the boot ROM of the targeted machine through infected Thunderbolt devices.

The Thunderstrike attack is very insidious because victims have no way to detect it, as explained by Trammell Hudson, even if the user completely re-install the OS X the machine will be still infected because the malicious code resides in the system’s own independent ROM.