BlackLotus is a UEFI bootkit and malware-as-a-service offering that emerged on criminal forums in 2022 and was publicly confirmed in real-world attacks in 2023. It is widely regarded as the first publicly documented in-the-wild UEFI bootkit capable of bypassing UEFI Secure Boot on fully updated Windows 11 systems by abusing older, still-trusted signed boot components that had not yet been revoked. BlackLotus has been associated primarily with exploitation of CVE-2022-21894 and later reporting also linked its tradecraft to CVE-2023-24932 in the Windows Boot Manager hardening context.
The malware targets the earliest software stages of the Windows boot chain rather than firmware itself. Its installation flow writes malicious components to the EFI System Partition, disables or weakens protections such as BitLocker, Hypervisor-Protected Code Integrity, and Microsoft Defender, and then reboots the host to implant persistent boot-level code. After successful installation, BlackLotus executes automatically during startup before the operating system fully loads, allowing it to tamper with boot integrity, establish durable persistence that can survive operating system reinstallation, and deploy additional payloads with high privileges.
Operationally, BlackLotus uses legitimate but vulnerable signed boot binaries in a bring-your-own-vulnerable-bootloader style approach to defeat Secure Boot enforcement. Once resident, it deploys a kernel driver and a user-mode downloader that communicates with command-and-control infrastructure to retrieve additional payloads, updates, or uninstall instructions. Reported functionality includes downloading and executing additional kernel-mode or user-mode components, evading detection and removal, and maintaining control over the system from a pre-OS foothold.
BlackLotus is a Windows-focused threat and has been repeatedly cited as a benchmark example in discussions of Secure Boot revocation gaps, outdated DBX deployments, and broader boot-chain trust weaknesses. Its significance lies not only in its capabilities but also in demonstrating that patching the underlying vulnerability alone was insufficient until vulnerable signed boot artifacts were explicitly revoked through Secure Boot update mechanisms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
description: Windows Bootmgr signing certificate authority since 2011. Revoked due to CVE-2023-24932
Attackers exploiting these shims can execute untrusted code during the boot process, opening the door to deploying malicious UEFI bootkits such as Bootkitty, HybridPetya, or BlackLotus even on systems where Secure Boot is fully enabled.
Two CVE identifiers were assigned to formally track the issue. CVE ID Focus CVE-2026-8863 Covers the primary shim-bypass issue reported to CERT/CC. | Attackers exploiting these shims can execute untrusted code during the boot process, opening the door to deploying malicious UEFI bootkits such as Bootkitty, HybridPetya, or BlackLotus even on systems where Secure Boot is fully enabled.
The most well-known real-world example is BlackLotus, a UEFI bootkit discovered in 2023 that exploited vulnerabilities in older Windows bootloaders (CVE-2022-21894 and CVE-2023-24932) to bypass Secure Boot on fully updated Windows 11 systems.
Через такой вектор можно развернуть полноценные UEFI-буткиты - BlackLotus или Bootkitty - даже при включённом Secure Boot. | CVE-2024-7344, обнаруженная исследователем ESET Martin Smolár, затрагивает UEFI-приложение Reloader - компонент нескольких утилит восстановления: Howyar SysReturn, Greenware GreenGuard, Radix SmartRecovery, Sanfong EZ-back System, CES NeoImpact. По данным ESET, также затронуты WASAY eRecoveryRX и SignalComputer HDD King.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications could be abused to bypass Secure Boot on most systems using the modern firmware standard.
Reported shims can be exploited to execute untrusted code during system boot, enabling attackers to deploy malicious UEFI bootkits ... even on systems with UEFI Secure Boot enabled. | An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware.
there are "limited indications" suggesting the involvement of a UEFI bootkit, likely exploiting CVE-2023-24932 ... a security feature bypass vulnerability in the Windows Boot Manager
BlackLotus takes advantage of this, bringing its own copies of legitimate – but vulnerable – binaries to the system in order to exploit the vulnerability...
Certain BlackLotus installation packages, as analyzed by ESET, refrain from carrying out the installation of the bootkit in case the affected host employs regional settings associated with Armenia, Belarus, Kazakhstan, Moldova, Russia, or Ukraine.
11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications could be abused to bypass Secure Boot on most systems using the modern firmware standard.
Reported shims can be exploited to execute untrusted code during system boot, enabling attackers to deploy malicious UEFI bootkits ... even on systems with UEFI Secure Boot enabled. | An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware.
The attack worked because the old trusted bootloader signatures had not been revoked at the firmware level. Without the ability to push new DBX revocations, a device that misses the 2023 certificate transition becomes permanently frozen in its ability to blacklist newly discovered malicious bootloaders.
It also deploys an HTTP downloader that enables communication with the Command and Control server and has the ability to load further user-mode or kernel-mode payloads.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A UEFI bootkit that bypassed Secure Boot by exploiting older bootloader vulnerabilities, highlighting the risk of outdated Secure Boot certificates and the importance of continued DBX revocation updates.
A malicious UEFI bootkit cited as an example of malware that could be installed by abusing vulnerable shim bootloaders to bypass Secure Boot.
A UEFI bootkit referenced as an example of malware that can be deployed by abusing old trusted shim bootloaders to bypass Secure Boot.
A named UEFI bootkit referenced as an example of malware that could be installed once Secure Boot is bypassed via vulnerable shim bootloaders.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.