/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Kaspersky researchers spot malware embedded in UEFI firmware on motherboards of victims' devices, affecting diplomats working on issues related to North Korea

The tool attacks a device's UEFI firmware—which makes it especially hard to detect and destroy.

Wired Andy Greenberg

Context & Ripple Effects

Kaspersky's discovery sits at the start of a documented arc: five years earlier, Hacking Team's spyware had already shown a UEFI rootkit could survive OS reinstalls, and Wired had reported that firmware often ships unsigned and unauthenticated. What makes this sighting different is the target set — diplomats handling North Korea issues — putting firmware persistence directly into state-aligned espionage.

The finding also foreshadows what Kaspersky would later formalize: the MoonBounce UEFI bootkit in 2022 and a malicious UEFI rootkit active in the wild since 2016 both confirm that firmware-resident implants moved from one-off spyware kits to a recurring tool class.

First-order effects

  • Targeted diplomats face infections that standard remediation — reimaging or even swapping the hard drive — does not remove, since the implant lives on the motherboard's firmware.
  • Kaspersky gains rare visibility into below-OS attacks, reinforcing its role as the primary public tracker of UEFI threats.

Second-order effects

  • Security teams protecting diplomatic and government estates are pushed to add firmware integrity verification and hardware replacement to incident-response playbooks, raising the cost of cleanup well beyond typical malware incidents.
  • Detection vendors face pressure to extend monitoring beneath the operating system, where conventional endpoint agents have no view.

Third-order effects

  • If firmware persistence keeps proving effective against high-value targets, motherboard and firmware vendors will come under sustained pressure to sign and authenticate firmware updates — closing the gap flagged back in 2015.
  • State-linked actors appear to be institutionalizing deep-persistence tooling, a trajectory consistent with North Korea's reported buildup of dedicated cyber units aimed at information and asset theft.

The trend: State-aligned espionage is shifting its persistence layer down the stack from the operating system into UEFI firmware, with Kaspersky repeatedly documenting each step of that descent.

Discussion

  • @craiu Costin Raiu on x
    Here's our new research on #MosaicRegressor - an in the wild, UEFI bootkit that installs a custom made malware framework: https://securelist.com/...
  • @malwarekiwi Tom Hegel on x
    Awesome discovery here. It links to older infra from my past report (see “Who is behind the attack?” section). These days, that old report is mostly associated with APT41 and others. https://twitter.com/...
  • @ihackbanme Zuk on x
    Just one more example of how far the industry is from detecting the real stuff. Amazing findings/research 🤯🔥 https://twitter.com/...
  • @virusbtn Virus Bulletin on x
    Kaspersky researchers analyse MosaicRegressor, a malware framework that includes a UEFI bootkit, only the second to have been found used in the wild, and which is based on HackingTeam's leaked VectorEDK tool https://securelist.com/... https://twitter.com/...
  • @wired @wired on x
    Five years after the notorious spy contractor Hacking Team had its code leaked online, a customized version of one of its stealthiest spyware samples has shown up in the hands of possibly Chinese-speaking hackers. https://www.wired.com/...
  • @e_kaspersky Eugene Kaspersky on x
    A China-linked group repurposed Hacking Team's stealthy spyware ⇒ https://www.wired.com/... by @a_greenberg ⇐ The tool attacks a device's UEFI firmware—which makes it especially hard to detect and destroy https://twitter.com/...
  • @ericgeller Eric Geller on x
    Some interesting new research here from Kaspersky: “A Chinese-speaking actor” has been using malware-laced computer firmware images to hack “diplomats and members of an NGO from Africa, Asia and Europe,” all of whom had some connection to North Korea. https://securelist.com/...
  • @e_kaspersky Eugene Kaspersky on x
    #MosaicRegressor: malicious UEFI firmware found in the wild ⇒ https://kas.pr/g6fy by @_marklech_ & @2igosha ❗ The attack was found by firmware scanning technology integrated in @kaspersky products ❗ Victims: diplomatic entities and NGOs in Africa, Asia & Europe https://twitter.co…