BlackLotus

From Wikipedia, the free encyclopedia

Technical nametrojan.blacklotus
FamilyBlackLotus
TargetWindows 10 and Windows 11 systems[1]
Abused exploitsBaton Drop (CVE-2022-21894)
BlackLotus
Malware details
Technical nametrojan.blacklotus
FamilyBlackLotus
Cyberattack event
TargetWindows 10 and Windows 11 systems[1]
Technical details
Abused exploitsBaton Drop (CVE-2022-21894)
Written inAssembly

BlackLotus is a UEFI bootkit malware discovered publicly in 2022 that bypasses Microsoft's secure boot on fully up-to-date Windows systems. BlackLotus enables persistent, stealthy control of infected machines at the firmware level, making detection and removal particularly difficult.[2]

Secure Boot bypass and persistence

Discovery

References

Related Articles

Wikiwand AI