Microsoft

UEFI Bootkit Hack: Microsofts Issues Guidance To Avoid

Microsoft has released a list to make it easier to spot a possible BlackLotus UEFI bootkit attack on your machine. The company is now giving tips and reminding you to use the security patch.

In January, Microsoft released information about a vulnerability known as Secure Boot Bypass (CVE-2022-21894). This was followed by the correction of the vulnerability on the January patch day.

At the beginning of March, it was announced that a previously unknown group had developed malware called BlackLotus, which was the first UEFI bootkit capable of defeating Windows’ Secure Boot feature. Now, Microsoft is once again emphasizing the importance of installing the January update and providing a guide to detecting BlackLotus malware infections. It’s not that easy.

Antivirus programs are turned off

If the UEFI bootkit has entered a computer or network using the CVE-2022-21894 vulnerability, it usually evades detection. The malware initially disables antivirus programs and resists removal attempts with appropriate tools. However, there are “side effects” that can indicate a BlackLotus infection.

When analyzing devices infected with BlackLotus, the Microsoft Incident Response Team identified several points in the malware’s installation and execution process that allow for detection.

Indications of BlackLotus UEFI bootkit infection are:

  • Recently created and locked bootloader files
  • Presence of a staging directory used during BlackLotus installation in the EPS:/ file system
  • Hypervisor Protected Code Integrity (HVCI) registry key change
  • network protocols
  • Boot configuration logs
  • Boot partition artifacts

Because BlackLotus needs to write malicious bootloader files to the EFI system partition, also known as ESP, it locks these files to prevent them from being deleted or modified. Recently modified and locked files in the ESP location, particularly if they match known BlackLotus bootloader filenames, “should be considered highly suspicious,” Microsoft said.

Microsoft recommends using the mountvol command line utility to mount the boot partition and check the creation dates of files with creation time mismatches. Another distinguishing feature of BlackLotus is the presence of the “/system32/” directory on the ESP, which stores the files required to install the UEFI malware. According to Microsoft, if BlackLotus is installed successfully, the files in the “ESP:/system32/” directory will be deleted, but the directory will remain.

Disabling antivirus programs is also an indication of hackers.

Recent Posts

Claude AI data leak: Private chats were freely accessible on Google

Due to an insufficiently protected sharing function, private chat logs from the Anthropic AI Claude…

9 hours ago

Mark Zuckerberg’s megayacht Launchpad ignored calls for help off Alaska

Mark Zuckerberg's $300 million superyacht ignored or allegedly did not hear a call for help…

9 hours ago

Why Choose A Light Wheelchair From Medical Department Store For An Active Lifestyle

Struggle to get out of the house because your wheelchair is too heavy to lift,…

9 hours ago

Top-rated Companies Offering Large Format Printing In The US

It's not always easy to find a reliable large format printing company. There are several…

9 hours ago

Galaxy S27 Pro & S27 Ultra: Samsung plans up to 15% larger batteries

Samsung apparently wants to equip its next high-end smartphones in the classic bar-style form factor…

17 hours ago

iOS 26.6: The iPhone update is now available

Apple has released the update to iOS 26.6 for iPhones. In addition to important security…

17 hours ago