Description
BlackLotus is a UEFI bootkit that attacks Windows systems and drew significant research attention in 2023. Microsoft published investigation guidance for the BlackLotus campaign, which abused the CVE-2022-21894 vulnerability, and researchers published detailed analyses of its bootkit and rootkit stages. Because a bootkit executes before the operating system loads, infections of this family warrant a careful review of boot integrity on affected machines.
Stats
- First seen
- March 2023
- Last seen
- October 2026
Also known as
Blacklotus
Alert name variants
| Alert Name |
|---|
| Gen:Variant.BlackLotus.1 |
| Gen:Variant.BlackLotus.4 |
| Rootkit.BlackLotus.A |
| Win32.Trojan.BlackLotus |
| Win64.Trojan.Blacklotus |
| Win64.Trojan.BlackLotus |
