LoJax

Malware

⚠️ Overview

LoJax is a UEFI bootkit first documented by ESET researchers in September 2018, attributed to the advanced persistent threat group APT28 (also known as Fancy Bear, Sofacy, or Pawn Storm) with suspected ties to the Russian General Staff Main Intelligence Directorate (GRU). It belongs to the category of firmware-level persistent threats, specifically targeting UEFI firmware to achieve stealthy code execution before the operating system loads.

🔧 Technical Capabilities

LoJax operates by writing a malicious module to the System Management Mode (SMM) portion of the UEFI firmware, allowing it to survive disk reformatting and even operating system reinstallation. The malware drops a driver (typically named rt640x64.sys) that unpacks a UEFI module (DXE driver) during boot, achieving persistence at the firmware level. Propagation occurs through standard initial access vectors such as spear-phishing or compromised credentials, followed by lateral movement using tools like Mimikatz and PsExec. Command-and-control (C2) infrastructure relies on HTTP-based communications, often mimicking legitimate traffic to blend in; ESET identified C2 servers hosting the bootkit via HTTP requests with specific User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; WOW64)". Evasion techniques include disabling Secure Boot by modifying UEFI variables and using a digitally signed but abused legitimate driver (e.g., a vulnerable Realtek driver) to bypass kernel-level defenses.

📜 History & Notable Incidents

LoJax was first publicly identified by ESET during an investigation of APT28 campaigns targeting government and diplomatic entities across Eastern Europe, including the European Union and NATO member states. No specific CVEs are associated with the initial infection, as the exploit chain uses social engineering rather than firmware vulnerabilities; however, the technique relied on weak UEFI configuration management and lack of firmware integrity checks. Following ESET's disclosure, no major law enforcement actions have been reported against the operation, but the group continues to evolve its toolkit.

🔍 Detection Indicators

Known file hashes for dropped components include SHA-1 0x9B1B3E4A... (for rt640x64.sys) as reported by ESET. Behavioral signatures include unexpected SMM and DXE driver writes to the SPI flash memory, detectable via firmware scanning tools like Chipsec. Network IOCs include HTTP requests to IP addresses associated with the APT28 infrastructure, such as 185.86.149[.]211. Registry keys under HKLMSYSTEMCurrentControlSetServices for the malicious driver may persist even after OS reinstallation is attempted.

☠️ Risk & Impact

The primary risk of LoJax is its near-undetectable firmware-level persistence, enabling long-term espionage, data exfiltration, and capability to re-infect cleaned systems. Affected sectors include government, diplomatic, and military organizations, particularly in Eastern Europe and the Balkans, as documented by ESET's whitepaper "LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group" (2018). The malware does not cause direct financial losses but facilitates ongoing espionage and strategic intelligence theft.

🛡️ Mitigation

Defensive measures include enabling and verifying Secure Boot with proper UEFI certificate management, conducting periodic firmware integrity checks using tools like chipsec or FWUpdLba, and applying strict access controls to prevent privilege escalation. Organizations should also monitor for anomalous driver loads and implement hardware-backed attestation (e.g., Intel TXT) as recommended by NIST SP 800-193 framework for platform firmware resilience.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.