Amid a shift in malware targeting UEFI firmware, Kaspersky details new MoonBounce UEFI bootkit that can survive even after swapping the infected PC's hard drive
Catalin Cimpanu / The Record :
Context & Ripple Effects
MoonBounce extends a lineage Kaspersky has been documenting for years: Hacking Team's UEFI rootkit showed firmware persistence was possible back in 2015, and Kaspersky itself later found malware implanted in the UEFI firmware of motherboards belonging to diplomats focused on North Korea. The new detail here is degree of persistence — MoonBounce lives at the UEFI level and survives even swapping the infected machine's hard drive.
The report also lands mid-arc in a broader escalation: Kaspersky subsequently tracked a malicious UEFI-based rootkit used in the wild since 2016, and by 2023 the technique had reached the criminal market with BlackLotus, a $5K bootkit sold since October 2022 that bypasses UEFI Secure Boot.
First-order effects
- Organizations cleaning MoonBounce infections can no longer treat a drive swap or OS reinstall as remediation — the implant persists in firmware, so responders must reflash or replace the motherboard's SPI flash to be sure the machine is clean.
- Kaspersky's disclosure hands incident-response teams a detection target while tipping off the operators behind MoonBounce that their toolchain is burned.
Second-order effects
- Endpoint security vendors face pressure to add firmware-layer visibility, since traditional on-disk antivirus cannot see a bootkit that loads before the OS.
- Once a state-grade technique like this is publicly documented, it becomes a template for commercial tooling — the path that led to BlackLotus being sold as a ready-made bootkit within about a year.
Third-order effects
- If firmware implants keep spreading down the sophistication curve, PC trust models built on assuming the bootloader is clean break down, pushing vendors toward hardware-rooted verification and aggressive Secure Boot binary revocation — a mechanism Microsoft's slow use of already left patched systems exposed to BlackLotus.
- The battleground expanding beyond Windows — ESET's discovery of the first Linux-targeting UEFI bootkit suggests firmware persistence is becoming platform-agnostic rather than a Windows-specific threat.
The trend: Malware persistence is migrating from the operating system into UEFI firmware, moving from rare state-actor implants toward commoditized bootkits across platforms.