惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
T
The Blog of Author Tim Ferriss
H
Help Net Security
博客园 - 叶小钗
云风的 BLOG
云风的 BLOG
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
D
DataBreaches.Net
博客园 - 聂微东
A
About on SuperTechFans
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
Martin Fowler
Martin Fowler
博客园 - 【当耐特】
S
SegmentFault 最新的问题
Blog — PlanetScale
Blog — PlanetScale
酷 壳 – CoolShell
酷 壳 – CoolShell
G
Google Developers Blog
I
InfoQ
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
B
Blog
Engineering at Meta
Engineering at Meta
V
V2EX
Hugging Face - Blog
Hugging Face - Blog

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Navigating the BlackLotus Threat: Unraveling the UEFI Boo...
Intel 471 · 2023-07-27 · via Intel 471 Blog

Threat Overview - BlackLotus

Every so often, a unique and significant cyber threat emerges in the wild. The BlackLotus UEFI BootKit is one such threat. Written in assembly and C languages, this malware targets Windows systems, even fully patched Windows 11 installations. Unlike other BootKits that target the UEFI firmware stored in the flash storage chip, BlackLotus is distinguished by its ability to disable Secure Boot and other Windows security features such as Hypervisor-protected Code Integrity (HVCI), BitLocker, and Windows Defender.

Campaign Overview

BlackLotus is a cunningly sophisticated UEFI bootkit that targets the Unified Extensible Firmware Interface (UEFI), a specification for a software program connecting a computer's firmware to its operating system. In doing so, it holds the power to manipulate the booting sequence in modern computers, making it a formidable foe in the realm of cyber threats.

The BlackLotus campaign exploits a vulnerability, known as "Baton Drop" (CVE-2022-21894). This flaw enables the threat actors to bypass various security features in Windows, including obtaining keys for BitLocker, a feature that Microsoft allows for hard drive encryption. Despite Microsoft patching this vulnerability in January 2022, the update is disabled by default, requiring manual updating.

Technical Details

Once Secure Boot is bypassed, BlackLotus can disable other Windows security features, deploying its own kernel-mode and user-mode payloads in the early stages of the OS startup. This affords the attackers high-level privileges and stealthy operations, making it a significant threat even to fully patched Windows 11 systems with UEFI Secure Boot enabled.

The National Security Agency (NSA) has recommended measures to protect systems against this threat. These include the latest security patches application, recovery media update, and optional mitigations activation such as Code Integrity Boot Policy. The NSA also advises hardening defensive policies, monitoring device integrity measurements and boot configuration, and customizing UEFI Secure Boot to deny older and vulnerable boot loaders.

At Cyborg Security, our commitment to navigating such threats remains unswerving. We constantly update our Hunt Packages and Hunt Package Collections to keep up with threats, including BlackLotus. As more detection opportunities are identified, new Hunt Packages will be released. For more in-depth analysis and mitigation recommendations, we encourage you to consult the NSA's advisory.

Taking Action Against BlackLotus

Staying one step ahead of cyber threats requires a proactive approach, and leveraging the right resources is paramount. In the face of threats like BlackLotus, Cyborg Security's Hunt Packages can be a game-changer.

Our Hunt Packages, which include threat hunting content and a hunt management module, are designed to equip you with the tools to combat emerging threats like BlackLotus. The free access to these Hunt Packages can enhance your detection engineering capabilities and put you on the front foot against potential cyber threats.

If you don't have a HUNTER Community account yet, we encourage you to sign up for one. It's completely free and will grant you access to our continually updated library of Hunt Packages. Now is the time to act, build your defense, and ensure you're prepared for whatever the cyber threat landscape throws your way.

Don't just trust your security controls; verify them with Cyborg Security's HUNTER Platform.

.

GET THE FREE HUNT PACKAGES!

CHECK OUT OTHER EMERGING THREATS >