Kaspersky researchers spot malware embedded in UEFI firmware on motherboards of victims' devices, affecting diplomats working on issues related to North Korea
The tool attacks a device's UEFI firmware—which makes it especially hard to detect and destroy.
Context & Ripple Effects
Kaspersky's discovery sits at the start of a documented arc: five years earlier, Hacking Team's spyware had already shown a UEFI rootkit could survive OS reinstalls, and Wired had reported that firmware often ships unsigned and unauthenticated. What makes this sighting different is the target set — diplomats handling North Korea issues — putting firmware persistence directly into state-aligned espionage.
The finding also foreshadows what Kaspersky would later formalize: the MoonBounce UEFI bootkit in 2022 and a malicious UEFI rootkit active in the wild since 2016 both confirm that firmware-resident implants moved from one-off spyware kits to a recurring tool class.
First-order effects
- Targeted diplomats face infections that standard remediation — reimaging or even swapping the hard drive — does not remove, since the implant lives on the motherboard's firmware.
- Kaspersky gains rare visibility into below-OS attacks, reinforcing its role as the primary public tracker of UEFI threats.
Second-order effects
- Security teams protecting diplomatic and government estates are pushed to add firmware integrity verification and hardware replacement to incident-response playbooks, raising the cost of cleanup well beyond typical malware incidents.
- Detection vendors face pressure to extend monitoring beneath the operating system, where conventional endpoint agents have no view.
Third-order effects
- If firmware persistence keeps proving effective against high-value targets, motherboard and firmware vendors will come under sustained pressure to sign and authenticate firmware updates — closing the gap flagged back in 2015.
- State-linked actors appear to be institutionalizing deep-persistence tooling, a trajectory consistent with North Korea's reported buildup of dedicated cyber units aimed at information and asset theft.
The trend: State-aligned espionage is shifting its persistence layer down the stack from the operating system into UEFI firmware, with Kaspersky repeatedly documenting each step of that descent.