LoJax
MITRE ATT&CK: S0397 View on attack.mitre.org
Aliases: LoJax
- First seen
- 2018-04-01 00:00:00
- Malware type
- rootkit
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:43:14
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:ua country_code:pl country_code:cz
Context
LoJax is a UEFI rootkit used by APT28 to persist remote access software on targeted systems.
Detection coverage
- 134 Sigma rules
Malware & tools used
- Modify Registry (attack-pattern)
- NTFS File Attributes (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- System Firmware (attack-pattern)
- Rootkit (attack-pattern)
Used by threat actors
- APT28 (threat-actor)
Reports & references
- Broadcom/Symantec — Apt28 Espionage Military Government (report)
- ESET — Signed Kernel Drivers Unguarded Gateway Windows Core (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lojax (report)
- blogs.vmware.com — Detecting Uefi Bootkits In The Wild Part 1 (report)
- youtube.com — Watch (report)
- ESET — Eset Lojax (report)
- habr.com — 668154 (report)
- MITRE ATT&CK — S0397 (report)