Netskope Threat Labs

BlackLotus

ATP Sandbox Adv. HeuristicsAVNetskope IPS

BlackLotus is a UEFI bootkit that attacks Windows systems and drew significant research attention in 2023. Microsoft published investigation guidance for the BlackLotus campaign, which abused the CVE-2022-21894 vulnerability, and researchers published detailed analyses of its bootkit and rootkit stages. Because a bootkit executes before the operating system loads, infections of this family warrant a careful review of boot integrity on affected machines.

First seen
March 2023
Last seen
October 2026
Blacklotus
Alert Name
Gen:Variant.BlackLotus.1
Gen:Variant.BlackLotus.4
Rootkit.BlackLotus.A
Win32.Trojan.BlackLotus
Win64.Trojan.Blacklotus
Win64.Trojan.BlackLotus