/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Kaspersky researchers find a malicious UEFI-based rootkit used in the wild since 2016 that keeps PCs infected after an OS reinstall or a hard drive replacement

Turns out they're not all that rare.  We just don't know how to find them.  —  Researchers have unpacked a major cybersecurity find … Source: Securelist .

Ars Technica Dan Goodin

Context & Ripple Effects

Kaspersky has been cataloging firmware-resident malware for years: Hacking Team's UEFI rootkit that survived OS reinstalls back in 2015, malware embedded directly in victims' motherboard firmware on diplomats' machines in 2020, and the MoonBounce UEFI bootkit detailed in January 2022 that persisted through hard drive swaps.

This new finding extends that arc in a significant way: a UEFI-based rootkit deployed in the wild since 2016, meaning these implants have been operating undetected far longer than their discovery dates suggest — the problem is prevalence we cannot measure, not rarity.

First-order effects

  • Victims infected since 2016 face a remediation problem beyond standard practice: reimaging the disk or replacing the drive leaves the implant intact, so cleanup requires reflashing or replacing motherboard firmware itself.
  • Security teams at organizations running Kaspersky telemetry gain a new detection signature, but every other endpoint product blind to UEFI internals leaves the same class of infection invisible.

Second-order effects

  • Antivirus vendors are pushed to extend scanning below the OS into firmware — a capability gap the BlackLotus revocation failure already exposed, where patched flaws stayed exploitable because vulnerable binaries were never revoked.
  • Motherboard and PC makers face growing pressure to ship flashable, verifiable firmware images, since 'wipe and reimage' incident-response playbooks no longer guarantee a clean machine.

Third-order effects

  • If firmware persistence keeps spreading across platforms — ESET's recent first Linux-targeted UEFI bootkit shows the technique is no longer Windows-bound — hardware-rooted attestation and measured boot shift from enterprise option to baseline requirement for all endpoints.
  • Detection economics invert: as implants hide in the layer beneath the OS, the market moves toward tools that verify firmware integrity rather than scan files, reshaping what endpoint security products must do.

The trend: Firmware-level persistence is maturing from bespoke espionage tooling into an established threat class spanning Windows and Linux, outpacing the industry's ability to detect and revoke compromised boot components.

Discussion

  • @justicerage Ivan Kwiatkowski on x
    New blog post about an UEFI firmware bootkit! https://securelist.com/... Research was led by our dearly missed @_marklech_
  • @sunnynehrabro Sunny Nehra on x
    1/ BREAKING: Chinese rootkits found in motherboards of ASUS and GIGABYTE (the two Chinese 🇨🇳 giants). Kaspersky Researchers named it CosmicStrand. This malware being planted in the UEFI firmware image is nearly impractical to be detected or removed by even advanced tech users.
  • @evacide Eva on x
    A Chinese actor has been going hog wild with a UEFI root kit since 2016. https://securelist.com/...
  • @k8em0 @k8em0 on x
    “victims of CosmicStrand in China, Vietnam, Iran & Russia. A point of interest is that all the victims in our user base appear to be private individuals (i.e., using the free version of our product) & we were unable to tie them to any organization or even industry vertical.” http…