Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Hard drives beware, the NSA is coming for you

Add as a preferred source on Google

A new report from the threat research team at Kaspersky Labs has discovered the existence of a highly advanced set of trojans developed in concert by the NSA and its partners, capable of breaking into any hard drive and going undetected for years on end.

The effort, launched on behalf of what Kaspersky is calling the “Equation Group,” was a specialized operation designed to implement surveillance on some of the NSA’s highest profile targets. Unlike the blanket collection methods we saw with the taps of Google’s fiber optic lines or phone call record archives, the NSA kept the secrets of their hard drive intrusion comparatively close to their chest, only bringing out the big guns when it was an absolute necessity.

Recommended Videos

Kaspersky believes this is due to the highly advanced nature of the code that was used to infiltrate the drives, which could have cost upwards of several million dollars to construct, implement, and maintain over the past decade. The agency wasn’t willing to risk having that technology fall into the wrong hands through overuse, and as far as the Russian threat research group could find, the only targets it’s been used on are computers within specific I.P. ranges, most of them in the Middle East.

The code was capable of infiltrating drives from many of the largest providers including Seagate, Western Digital, and Toshiba, rewriting the firmware on each, and making itself resilient to any method of removal including flash wipes.

This is capability that only a nation-state could cook up, and anonymous sources still working within the agency have been able to confirm the existence of the program used to develop it. Kaspersky’s findings suggest the group behind the exploit has been active for at least 15 years, and the hard-drive infecting malware, called GrayFish by Kaspersky, has been around since 2008.

The news comes just a day after the Lab unveiled details of one of the largest banking trojan operations in history, which yielded the hackers behind the scam upwards of one billion dollars, collected over a span of just under two years.

None of the manufacturers of the drives in question claim to have known about the defects in their devices, and state they have never worked or collaborated with the NSA to install secret backdoors in their hardware.

Chris Stobing
Former Digital Trends Contributor
Self-proclaimed geek and nerd extraordinaire, Chris Stobing is a writer and blogger from the heart of Silicon Valley. Raised…
Lenovo’s next ThinkBook looks unbelievably thin in this leak
Say hello to Aeroblade, the ThinkBook that could redefine how thin a laptop can get.
Lenovo ThinkBook Aeroblade front view

Lenovo might have a new obsession, and it's all about being thin. Windows Latest got its hands on marketing images of an unannounced Lenovo laptop, and buried in the files is a name we've never seen before: Aeroblade. The device itself is clearly branded as a ThinkBook, so this could launch as the ThinkBook Aeroblade.

If you're not familiar, ThinkBook sits just below the premium ThinkPad lineup and is built for small and medium businesses who want that ThinkPad look without the ThinkPad price tag.

Read more
Apple fixed three Mac Screen Sharing flaws, and now it’s patching another one
macOS 26.6.1 arrives roughly 10 days after Apple shipped three separate Screen Sharing security fixes in macOS 26.6.
MacBook Pro on Table

Apple has released macOS Tahoe 26.6.1 to fix a Screen Sharing vulnerability that could let an attacker on the same network authenticate without valid credentials.

The timing makes this update more interesting than its small version number suggests. Apple’s security notes for macOS 26.6, released July 27, already listed three separate vulnerabilities affecting Screen Sharing Server.

Read more
Dell’s iconic XPS lineup may be heading into Google’s Googlebook ecosystem
Dell's iconic XPS lineup may be heading to Google's laptop platform for the first time.
Googlebook featured image.

A fresh benchmark leak suggests Dell is quietly building its first Googlebook under the XPS name, joining Lenovo and Asus as the hardware partner for Google's upcoming laptop platform (via Chrome Unboxed).

The leak trail started with an internal board codenamed "Mica" showing up in Chromium's development pipeline. It was tied to Qualcomm's "Bluey" architecture built specifically for Snapdragon X-series Googlebooks. 

Read more