Researchers reported that BlackLotus is the first known in-the-wild UEFI bootkit able to bypass UEFI Secure Boot on fully updated Windows 11 and other UEFI systems. The malware abuses weaknesses tied to CVE-2022-21894 and later CVE-2023-24932, allowing it to execute in the earliest software stage of boot, establish persistence across restarts, and evade normal remediation. ESET said BlackLotus had been advertised on underground forums since at least October 2022 and documented real-world samples that install a kernel driver and a user-mode payload, with follow-on capability for HTTP-based command-and-control and additional payload delivery.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft published support guidance for managing Windows Boot Manager revocations tied to Secure Boot changes associated with CVE-2023-24932, documenting how administrators should handle the mitigation.
On 2026-05-20, LOLDrivers published an entry for blacklotus_driver.sys with sample hashes, service creation details, and detection resources for the malicious driver component associated with BlackLotus.
On 2023-06-22, the U.S. NSA released guidance on defending against BlackLotus, warning that patching alone may not fully mitigate the threat and recommending additional Secure Boot and endpoint hardening steps.
The bootkit was described as having circulated since October 2022 and was identified by ESET as a real threat seen in the wild, not just an advertised product.
On 2023-03-06, Ars Technica reported on stealthy UEFI malware bypassing Secure Boot through a Windows flaw, amplifying public awareness of the BlackLotus threat.
On 2023-03-01, ESET published research analyzing BlackLotus and said it was the first known in-the-wild UEFI bootkit able to bypass UEFI Secure Boot on fully patched systems by abusing CVE-2022-21894.
ESET reported that the BlackLotus UEFI bootkit had been advertised on underground forums for $5,000 since at least early October 2022, indicating the malware was available to buyers before public technical analysis appeared.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
loldrivers.io
Open sourcesupport.microsoft.com
Open sourcesupport.microsoft.com
Open sourcesupport.microsoft.com
Open sourcebleepingcomputer.com
Open sourcearstechnica.com
Open sourcecsoonline.com
Open sourceeset.com
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.