I've just read about this: https://www.tripwire.com/state-of-security/security-data-protection/backdoors-hardware-attacks-rakshasa-malware/
Asides from the question in the title, I'd also like to add the following question:
- Is it possible to flash the firmware of the Sound Card so that it would load malicious code through DMA or take control of the Audio Drivers which has high privileges in a Windows machine then have it contact the C2 server?
If this is all possible then does that mean that just plugging an infected PCIe Sound card to practically any PC may it be running Windows or Linux be already compromised despite enabling and proper configuration of IOMMU such as actually setting it as ENABLED in BIOS and setting intel_iommu=on/amd_iommu=on in Linux? This is in assumption that everything else is clean except the Sound card.