LoJax is a Windows-targeting UEFI implant and persistence mechanism publicly associated with Sofacy (Fancy Bear/APT28). It is notable as the first publicly documented UEFI rootkit observed in the wild. The implant abuses components related to the LoJack/Computrace anti-theft technology to achieve firmware-level persistence by modifying system firmware stored in SPI flash, allowing it to survive operating system reinstallation and disk replacement.
LoJax operates below the operating system and is designed to reinstall or deploy a malicious user-mode agent during the boot process. By residing in UEFI firmware, it provides durable post-compromise persistence and complicates remediation because removing the operating system alone does not eliminate the implant. Its discovery established a practical in-the-wild example of adversaries weaponizing firmware persistence for espionage operations.
The malware has been linked to targeted intrusions rather than broad criminal distribution, with reporting tying it to espionage activity by Sofacy against selected victims. The available facts here support its role as a firmware implant used to deploy a malicious Windows component, but do not establish a specific initial infection vector with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A prominent example is the LowJax implant discovered ... in 2018, in which patched UEFI modules of the LoJack anti-theft software ... were used to deploy a malicious user mode agent
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously known UEFI firmware implant referenced as a comparable case to a newly observed firmware-level compromise.
A previously known UEFI implant mentioned as background context for firmware threats.
UEFI firmware implant leveraging patched UEFI modules associated with LoJack/Computrace to deploy a malicious user-mode agent, enabling high-persistence compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.