/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hacking Team's malware uses UEFI rootkit to survive OS reinstalls

Surveillance software maker Hacking Team has provided its government customers with the ability to infect the low-level firmware found in laptops and other computers that they wanted to spy on.

PCWorld Lucian Constantin

Context & Ripple Effects

The 2015 leak of Hacking Team's internal data exposed what its government customers were buying: an implant that hides in a computer's UEFI firmware, so it reloads itself even after the drive is wiped and Windows reinstalled. That capability put commercial spyware on the same footing as nation-state tooling for any of the dozens of governments in its client list.

The technique did not stay theoretical. Kaspersky researchers later documented a malicious UEFI rootkit used in the wild since 2016 that also survives both an OS reinstall and a hard-drive replacement, and separately detailed the MoonBounce bootkit as evidence that malware was shifting toward firmware-level targeting. Even mainstream vendors crossed the line in the same window — Lenovo shipped laptops whose 'anti-theft' component acted as an unwanted rootkit reinstalling software.

First-order effects

  • Government customers running Hacking Team's spyware gain persistence that defeats the standard remediation step of reimaging a target's laptop — the infection sits below the operating system where most antivirus tools of the era never looked.
  • Targets under surveillance face a much higher bar for regaining a clean machine: replacing the hard drive or reinstalling Windows no longer removes the implant.

Second-order effects

  • Security vendors are pushed to extend detection below the OS into firmware, a gap Kaspersky's later discoveries of wild UEFI rootkits show was real and exploitable for years before anyone was looking there.
  • Hardware and motherboard makers come under pressure to treat firmware as attack surface, since an implant in this layer outlives every software-based defense the buyer controls.

Third-order effects

  • Firmware becomes a durable battleground between spyware sellers and defenders — a trajectory the coverage traces from Hacking Team's commercial implant to LogoFAIL, which showed UEFI boot protections failing across nearly all Windows and Linux machines.
  • Commercial surveillance firms effectively normalize nation-state-grade tradecraft for a broad government market, forcing regulators and buyers to treat off-the-shelf spyware as a strategic threat rather than a niche product.

The trend: Malware is migrating down the stack from the operating system into UEFI firmware, turning the PC's lowest layer into the new high ground for both commercial spyware and state-grade attackers.