LoJax is a UEFI firmware implant and rootkit operation publicly identified in 2018 as the first known UEFI rootkit observed in the wild. It is associated with firmware-level persistence in which an added DXE module reinstalls a malicious agent during boot, allowing the compromise to survive operating system reinstallation and even hard drive replacement. The operation is widely linked to the Sednit group, also tracked as APT28, Fancy Bear, Sofacy, and STRONTIUM, a Russia-linked espionage actor. LoJax is notable for abusing low-level platform access to modify SPI flash-resident UEFI firmware and for using the RWEverything utility as part of the process to access firmware components. Its tradecraft demonstrates advanced post-exploitation capability focused on durable persistence below the operating system. The implant exemplifies ATT&CK-aligned system firmware persistence and boot-level compromise rather than ransomware or financially motivated intrusion activity. The broader actor behind LoJax has historically targeted government, military, and related high-value organizations for intelligence collection. In the context of LoJax, the defining capability is stealthy firmware persistence through malicious DXE module insertion and subsequent restoration of an on-disk agent at each boot. This places the operation in the category of advanced espionage-oriented intrusion sets using defense-evasive, post-exploitation firmware techniques.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UEFI-level implant/rootkit example using an added DXE module for persistence across OS reinstall and disk replacement.
UEFI-rootkit activity leveraging a legitimate low-level hardware access utility/driver (RWEverything) to access/modify UEFI-related components as part of persistence and firmware-level compromise.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.