Computrace

Malware

⚠️ Overview

Computrace is a commercial anti-theft and asset tracking software developed by Absolute Software (now part of Seagate Technology after its 2022 acquisition), originally intended to locate stolen devices. It has been repurposed by threat actors as a persistence mechanism, categorised as a backdoor and bootkit when abused. First publicly documented as a malware vector in September 2018 by ESET during the “LoJax” campaign, it leverages the legitimate agent embedded in the firmware of millions of enterprise PCs from vendors such as Dell, Lenovo, and HP.

🔧 Technical Capabilities

The Computrace agent persists at the firmware level (BIOS/UEFI), surviving OS reinstallation and hard drive replacement. It communicates with Absolute’s command‑and‑control (C2) servers over HTTP/HTTPS using the domain search.absolute.com and similar. Attackers abuse the agent by modifying configuration files (e.g., rpcnetp.exe) to redirect C2 traffic to attacker‑controlled servers, enabling remote code execution and payload delivery. The agent executes as a kernel‑mode driver (rrpcnet.sys) and uses signed modules from Absolute, evading many antivirus products. It also uses encrypted communication channels and can periodically check for new commands, providing stealthy long‑term access. MITRE ATT&CK maps this to T1542.003 (Pre‑OS Boot: Bootkit) and T1574.001 (Hijack Execution Flow: DLL Search Order Hijacking).

📜 History & Notable Incidents

In September 2018, ESET discovered the LoJax malware, which abused the Computrace agent to gain firmware persistence; it targeted government and diplomatic entities in Eastern Europe. In 2018, CVEs CVE‑2018‑11317 and CVE‑2018‑11318 were published for Absolute Computrace, detailing arbitrary code execution and privilege escalation vulnerabilities in the agent’s software. No major law‑enforcement actions have been taken, as the malware exclusively leverages legitimate functionality rather than exploiting a specific flaw in the vendor’s product.

🔍 Detection Indicators

Known file names include rpcnetp.exe, rpcnet.exe, rrpcnet.dll, and rrpcnet.sys; SHA‑256 hashes are published in the ESET LoJax report. Network IOCs involve connections to search.absolute.com or suspicious domains mimicking it. Registry persistence keys appear under HKLMSoftwareAbsolute Software and a shared mutex named “ABSOLUTE_MUTEX” is typical. User‑Agent strings used by the agent often match “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)”.

☠️ Risk & Impact

Once abused, Computrace provides attackers with persistent remote access that survives OS reinstallation, enabling long‑term data exfiltration, credential theft, and espionage. The sectors most affected include government, defence, and large enterprises deploying Absolute’s solution for legitimate asset management. While direct financial losses are uncommon, the operational impact of persistent, undetectable backdoors can be severe, especially in targeted espionage campaigns.

🛡️ Mitigation

Organisations should disable Computrace in the BIOS/UEFI settings if not required for asset recovery. Implement UEFI Secure Boot and monitor for unexpected execution of rpcnet.exe or outbound connections to Absolute domains. EDR rules blocking non‑Absolute‑signed modifications to the agent’s configuration can prevent abuse; ESET’s free LoJax detection tool is also recommended.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.