NSA-linked “Equation Group” can infect computers repeatedly via spyware inserted in hard disk firmware
Russian researchers expose breakthrough U.S. spying program — (Reuters) - The U.S. National Security Agency has figured out how to hide spying software deep within hard drives …
Context & Ripple Effects
Kaspersky Lab's disclosure that the Stuxnet-linked Equation Group hides spying tools in hard drive firmware lands alongside its own deep technical reporting on the group's capabilities — and Motherboard quickly noted the technique had been demonstrated publicly a year earlier, meaning the revelation is less a new capability than confirmation of who wields it.
The story anchors what became a decade-long Kaspersky file on firmware-level persistence: the firm later traced how it briefly held Equation Group source code from an infected contractor PC in 2014, and by 2022 documented a UEFI rootkit that survives both an OS reinstall and a hard drive swap.
First-order effects
- Targets of the Equation Group cannot clean infections by reimaging: because the spyware lives in drive firmware below the operating system, it can re-infect each time the machine boots, defeating conventional antivirus and OS reinstalls.
- The attribution to the NSA puts Kaspersky in direct confrontation with the agency it is exposing, raising immediate stakes for the Russian vendor's access to Western enterprise customers.
Second-order effects
- Hard drive and PC makers face pressure to lock down and sign firmware updates, since an unsigned or compromised firmware channel turns every shipped disk into a potential persistence vector.
- The find feeds the broader cat-and-mouse around Equation Group tooling — the same research thread later led Kaspersky to the source code archive it pulled off an infected PC in 2014, escalating scrutiny of the group's operational security.
Third-order effects
- If firmware and pre-boot layers become standard state-espionage real estate, as Kaspersky's 2022 UEFI rootkit finding suggests, endpoint security shifts from protecting the OS toward attesting hardware itself — a structural change for vendors, enterprises, and procurement.
- Sustained exposure of nation-state implants pushes governments toward treating the hardware supply chain as a national-security surface, with audits and provenance requirements rather than software patches as the mitigation of record.
The trend: State cyber-espionage is migrating downward into firmware and boot-level persistence, where disk imaging and OS reinstalls no longer cleanse an infected machine.