Hacking Team's malware uses UEFI rootkit to survive OS reinstalls
Surveillance software maker Hacking Team has provided its government customers with the ability to infect the low-level firmware found in laptops and other computers that they wanted to spy on.
Context & Ripple Effects
The 2015 leak of Hacking Team's internal data exposed what its government customers were buying: an implant that hides in a computer's UEFI firmware, so it reloads itself even after the drive is wiped and Windows reinstalled. That capability put commercial spyware on the same footing as nation-state tooling for any of the dozens of governments in its client list.
The technique did not stay theoretical. Kaspersky researchers later documented a malicious UEFI rootkit used in the wild since 2016 that also survives both an OS reinstall and a hard-drive replacement, and separately detailed the MoonBounce bootkit as evidence that malware was shifting toward firmware-level targeting. Even mainstream vendors crossed the line in the same window — Lenovo shipped laptops whose 'anti-theft' component acted as an unwanted rootkit reinstalling software.
First-order effects
- Government customers running Hacking Team's spyware gain persistence that defeats the standard remediation step of reimaging a target's laptop — the infection sits below the operating system where most antivirus tools of the era never looked.
- Targets under surveillance face a much higher bar for regaining a clean machine: replacing the hard drive or reinstalling Windows no longer removes the implant.
Second-order effects
- Security vendors are pushed to extend detection below the OS into firmware, a gap Kaspersky's later discoveries of wild UEFI rootkits show was real and exploitable for years before anyone was looking there.
- Hardware and motherboard makers come under pressure to treat firmware as attack surface, since an implant in this layer outlives every software-based defense the buyer controls.
Third-order effects
- Firmware becomes a durable battleground between spyware sellers and defenders — a trajectory the coverage traces from Hacking Team's commercial implant to LogoFAIL, which showed UEFI boot protections failing across nearly all Windows and Linux machines.
- Commercial surveillance firms effectively normalize nation-state-grade tradecraft for a broad government market, forcing regulators and buyers to treat off-the-shelf spyware as a strategic threat rather than a niche product.
The trend: Malware is migrating down the stack from the operating system into UEFI firmware, turning the PC's lowest layer into the new high ground for both commercial spyware and state-grade attackers.