http://it.slashdot.org/article.pl?sid=09/03/23/1248214&art_pos=10
so they infected a commercial bios.
And they used flashrom, it appears. :-)
I think I first started warning people about this 10 years ago, but I could not get interest. They did not believe it could be done, then I showed them some examples, and the reaction was -- literally in one case -- "I don't want to know". .
Expect the usual level of clue you get on slashdot in the comments section :-)
ron