We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scena…
It's not impossible but it's complicated and the more complicated the harder to it is to keep secret. It's easier to just amass exploits for use when needed.
for plausible deniability and to be able to reuse the same attack vector over and over, it's cheaper to just intercept shipments and install/modify what they need:
https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
impossible to reproduce unless you have the exact same equipment.