BlackLotus was identified as the first publicly known UEFI bootkit seen in the wild that can bypass UEFI Secure Boot on fully patched Windows 11 systems by exploiting CVE-2022-21894 and abusing legitimate Microsoft-signed boot binaries that were not added to the UEFI revocation database (dbx). ESET reported that the malware disables protections including HVCI and BitLocker, installs components to the EFI System Partition, enrolls an attacker-controlled Machine Owner Key, and persists through the boot process before loading a malicious kernel driver and an HTTP downloader into winlogon.exe. The malware also protects its files from removal and supports command-and-control tasking for payload delivery, updates, and uninstall.
Microsoft said devices that have not yet received the Secure Boot 2023 certificates will continue to boot and receive normal updates while the certificates are rolled out over the coming months. The certificate transition is required because older 2011 Secure Boot certificates, including the Microsoft Corporation KEK CA 2011, have expired, and the newer certificates are needed to keep delivering dbx revocation updates that block vulnerable bootloaders and bootkits such as BlackLotus. Microsoft said some systems remain delayed because of firmware incompatibilities, OEM support limits, disabled Secure Boot, Legacy BIOS mode, or unsupported Windows 11 installs, but most users do not need urgent action unless Windows reports a firmware-related Secure Boot warning.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In the July 14 KB5101650 release notes, Microsoft said Windows 10 and Windows 11 devices that had not yet received the Secure Boot 2023 certificates would continue to boot normally, receive standard updates, and get the new certificates over the coming months.
The older Microsoft Corporation KEK CA 2011 Secure Boot certificate expired on June 24, 2026 as part of Microsoft's retirement of the 2011 Secure Boot certificates.
ESET published a technical analysis describing BlackLotus as the first publicly known UEFI bootkit observed in the wild that can bypass UEFI Secure Boot on fully patched Windows 11 systems. The report detailed its persistence, Secure Boot bypass chain, payload delivery, and indicators of compromise.
A proof-of-concept exploit for CVE-2022-21894 was released in August 2022, providing public code that could be reused to bypass Secure Boot. Binarly later assessed BlackLotus as combining this public exploit with older UEFI bootkit techniques.
Microsoft patched CVE-2022-21894 in January 2022, but legitimate Microsoft-signed boot binaries affected by the flaw were not added to the UEFI revocation database (dbx), leaving them usable for Secure Boot bypass.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
windowslatest.com
Open sourcebinarly.io
Open sourcewelivesecurity.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.