Description
LoJax is a UEFI rootkit used by APT28 to persist remote access software on targeted systems, making it one of the first UEFI rootkits observed in the wild.
Stats
- First seen
- April 2022
- Last seen
- October 2026
Also known as
Lojax
MITRE ATT&CK techniques
5 techniques across 3 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Trojan.EFI.LoJax.36859417 |
| Trojan.LoJax.2 |
| Win32.Backdoor.Lojax |
| Win32.Backdoor.LoJax |
| Win32.Rootkit.LoJax |
| Win64.Backdoor.Lojax |
| Win64.Backdoor.LoJax |
| Win64.Trojan.Lojax |