Netskope Threat Labs

LoJax

ATP Sandbox Adv. HeuristicsAV

LoJax is a UEFI rootkit used by APT28 to persist remote access software on targeted systems, making it one of the first UEFI rootkits observed in the wild.

First seen
April 2022
Last seen
October 2026
Lojax

5 techniques across 3 tactics.

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0112 Defense Impairment

Alert Name
Trojan.EFI.LoJax.36859417
Trojan.LoJax.2
Win32.Backdoor.Lojax
Win32.Backdoor.LoJax
Win32.Rootkit.LoJax
Win64.Backdoor.Lojax
Win64.Backdoor.LoJax
Win64.Trojan.Lojax