Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
persistence-methodendpoint-security-bypassremote-access-implantcommand-and-control-method

BlackLotus UEFI Bootkit Bypasses Secure Boot and Survives on Patched Windows Systems

Updated 13d agoFirst seen May 25, 20269 sources

Researchers reported that BlackLotus is the first known in-the-wild UEFI bootkit able to bypass UEFI Secure Boot on fully updated Windows 11 and other UEFI systems. The malware abuses weaknesses tied to CVE-2022-21894 and later CVE-2023-24932, allowing it to execute in the earliest software stage of boot, establish persistence across restarts, and evade normal remediation. ESET said BlackLotus had been advertised on underground forums since at least October 2022 and documented real-world samples that install a kernel driver and a user-mode payload, with follow-on capability for HTTP-based command-and-control and additional payload delivery.

Share:
BlackLotus UEFI Bootkit Bypasses Secure Boot and Survives on Patched Windows Systems
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
May 25, 20261mo ago

Microsoft issues guidance for CVE-2023-24932 Secure Boot revocations

Microsoft published support guidance for managing Windows Boot Manager revocations tied to Secure Boot changes associated with CVE-2023-24932, documenting how administrators should handle the mitigation.

How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932 - Microsoft Support
May 20, 20261mo ago

LOLDrivers adds BlackLotus driver entry

On 2026-05-20, LOLDrivers published an entry for blacklotus_driver.sys with sample hashes, service creation details, and detection resources for the malicious driver component associated with BlackLotus.

8750b245-af35-4bc6-9af3-dc858f9db64f | LOLDrivers
Jun 22, 20233y ago

NSA releases BlackLotus defense guidance

On 2023-06-22, the U.S. NSA released guidance on defending against BlackLotus, warning that patching alone may not fully mitigate the threat and recommending additional Secure Boot and endpoint hardening steps.

NSA shares tips on blocking BlackLotus UEFI malware attacks

BlackLotus observed circulating in the wild

The bootkit was described as having circulated since October 2022 and was identified by ESET as a real threat seen in the wild, not just an advertised product.

NSA shares tips on blocking BlackLotus UEFI malware attacks
Mar 6, 20233y ago

Ars Technica reports on BlackLotus Secure Boot bypass

On 2023-03-06, Ars Technica reported on stealthy UEFI malware bypassing Secure Boot through a Windows flaw, amplifying public awareness of the BlackLotus threat.

Stealthy UEFI malware bypassing Secure Boot enabled by unpatchable Windows flaw - Ars Technica
Mar 1, 20233y ago

ESET publishes BlackLotus bootkit research

On 2023-03-01, ESET published research analyzing BlackLotus and said it was the first known in-the-wild UEFI bootkit able to bypass UEFI Secure Boot on fully patched systems by abusing CVE-2022-21894.

ESET Research analyzes BlackLotus: A UEFI bootkit that can bypass UEFI Secure Boot on fully patched systems | | ESET

BlackLotus advertised on underground forums

ESET reported that the BlackLotus UEFI bootkit had been advertised on underground forums for $5,000 since at least early October 2022, indicating the malware was available to buyers before public technical analysis appeared.

BlackLotus bootkit can bypass Windows 11 Secure Boot: ESET | CSO Online
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Malware
1 linked
Affected products
4 linked
Windows DefenderWindows 11BitlockerMicrosoft Defender
Organizations
2 linked
EsetMicrosoft Corporation
SOURCE COVERAGE

Sources

9 references tracked. Mallory keeps watching after this page renders.

9 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.