BlackLotus is a UEFI bootkit for Windows that emerged on criminal forums in 2022 and was publicly confirmed in real-world attacks in early 2023. It is widely regarded as the first publicly documented in-the-wild UEFI bootkit able to bypass Secure Boot on fully patched Windows 11 systems by abusing weaknesses in older trusted boot components and incomplete revocation coverage. BlackLotus has been associated primarily with exploitation of CVE-2022-21894, and reporting also links it to the broader Secure Boot revocation problem later addressed around CVE-2023-24932.
The malware operates at the pre-OS stage by compromising the boot chain through the EFI System Partition and related bootloader components, allowing attacker-controlled code to execute before the Windows kernel and most endpoint defenses initialize. This position gives it highly durable persistence below the operating system and enables extensive defense evasion. Reported impacts include the ability to undermine or disable security controls such as Secure Boot protections, BitLocker-related protections, Hypervisor-Protected Code Integrity, and Microsoft Defender before normal OS startup. Analysis has also noted modification of UEFI trust-related state, including MokList, to preserve execution of attacker-controlled boot components while Secure Boot remains enabled.
BlackLotus appears to combine publicly available proof-of-concept code for Secure Boot bypass with established UEFI bootkit tradecraft rather than introducing entirely novel primitives. Researchers have identified similarities between parts of its bootloader-hooking logic and the publicly known Umap project. The malware was sold as a malware-as-a-service offering on underground forums, lowering the barrier to adoption for actors seeking firmware-level persistence and stealth.
The platform targeted with high confidence is Windows systems using UEFI Secure Boot. Its core value to operators is persistence and defense evasion at boot time, with post-exploitation advantages derived from executing before the operating system and security tooling. BlackLotus has become a reference example in discussions of Secure Boot revocation gaps, vulnerable signed bootloaders, and the long-tail risk posed by outdated trust databases in enterprise and consumer firmware ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BlackLotus 2022 2022 ESP Windows N/A
Two CVE IDs, CVE-2026-8863 and CVE-2026-10797, cover the reported shims, and Microsoft revoked the vulnerable binaries in the dbx update shipped with its June 9 Patch Tuesday.
Two CVE IDs, CVE-2026-8863 and CVE-2026-10797, cover the reported shims, and Microsoft revoked the vulnerable binaries in the dbx update shipped with its June 9 Patch Tuesday.
description: Windows Bootmgr signing certificate authority since 2011. Revoked due to CVE-2023-24932
Через такой вектор можно развернуть полноценные UEFI-буткиты - BlackLotus или Bootkitty - даже при включённом Secure Boot. | CVE-2024-7344, обнаруженная исследователем ESET Martin Smolár, затрагивает UEFI-приложение Reloader - компонент нескольких утилит восстановления: Howyar SysReturn, Greenware GreenGuard, Radix SmartRecovery, Sanfong EZ-back System, CES NeoImpact. По данным ESET, также затронуты WASAY eRecoveryRX и SignalComputer HDD King.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Based on function similarity, we detect the replacement of bootmgfw.efi with the shim.
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Attackers could bypass UEFI Secure Boot on a wide range of systems thanks to 11 Microsoft-signed UEFI shim bootloaders carrying vulnerabilities that have remained buried for more than a decade... Exploitation allows untrusted code to run during boot, opening the door to UEFI bootkits ... even with Secure Boot switched on.
Based on function similarity, we detect the replacement of bootmgfw.efi with the shim.
there are "limited indications" suggesting the involvement of a UEFI bootkit, likely exploiting CVE-2023-24932 ... a security feature bypass vulnerability in the Windows Boot Manager
Certain BlackLotus installation packages, as analyzed by ESET, refrain from carrying out the installation of the bootkit in case the affected host employs regional settings associated with Armenia, Belarus, Kazakhstan, Moldova, Russia, or Ukraine.
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Attackers could bypass UEFI Secure Boot on a wide range of systems thanks to 11 Microsoft-signed UEFI shim bootloaders carrying vulnerabilities that have remained buried for more than a decade... Exploitation allows untrusted code to run during boot, opening the door to UEFI bootkits ... even with Secure Boot switched on.
With the modified MokList variable, an attacker can easily load any self-signed shim bootloader, which is actually another vulnerability in the chain used to keep secure boot active.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bootkit cité comme source d’inspiration pour RedLotus.
A UEFI bootkit that bypassed Secure Boot by exploiting older bootloader vulnerabilities, highlighting the risk of outdated Secure Boot certificates and the importance of continued DBX revocation updates.
A UEFI bootkit referenced as a potential post-bypass payload once untrusted code can execute during the boot process despite Secure Boot.
A malicious UEFI bootkit cited as an example of malware that could be installed by abusing vulnerable shim bootloaders to bypass Secure Boot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.