Kaspersky researchers find a malicious UEFI-based rootkit used in the wild since 2016 that keeps PCs infected after an OS reinstall or a hard drive replacement
Turns out they're not all that rare. We just don't know how to find them. — Researchers have unpacked a major cybersecurity find … Source: Securelist .
Context & Ripple Effects
Kaspersky has been cataloging firmware-resident malware for years: Hacking Team's UEFI rootkit that survived OS reinstalls back in 2015, malware embedded directly in victims' motherboard firmware on diplomats' machines in 2020, and the MoonBounce UEFI bootkit detailed in January 2022 that persisted through hard drive swaps.
This new finding extends that arc in a significant way: a UEFI-based rootkit deployed in the wild since 2016, meaning these implants have been operating undetected far longer than their discovery dates suggest — the problem is prevalence we cannot measure, not rarity.
First-order effects
- Victims infected since 2016 face a remediation problem beyond standard practice: reimaging the disk or replacing the drive leaves the implant intact, so cleanup requires reflashing or replacing motherboard firmware itself.
- Security teams at organizations running Kaspersky telemetry gain a new detection signature, but every other endpoint product blind to UEFI internals leaves the same class of infection invisible.
Second-order effects
- Antivirus vendors are pushed to extend scanning below the OS into firmware — a capability gap the BlackLotus revocation failure already exposed, where patched flaws stayed exploitable because vulnerable binaries were never revoked.
- Motherboard and PC makers face growing pressure to ship flashable, verifiable firmware images, since 'wipe and reimage' incident-response playbooks no longer guarantee a clean machine.
Third-order effects
- If firmware persistence keeps spreading across platforms — ESET's recent first Linux-targeted UEFI bootkit shows the technique is no longer Windows-bound — hardware-rooted attestation and measured boot shift from enterprise option to baseline requirement for all endpoints.
- Detection economics invert: as implants hide in the layer beneath the OS, the market moves toward tools that verify firmware integrity rather than scan files, reshaping what endpoint security products must do.
The trend: Firmware-level persistence is maturing from bespoke espionage tooling into an established threat class spanning Windows and Linux, outpacing the industry's ability to detect and revoke compromised boot components.