LoJax

MITRE ATT&CK: S0397 View on attack.mitre.org

Aliases: LoJax

First seen
2018-04-01 00:00:00
Malware type
rootkit
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:43:14

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:ua country_code:pl country_code:cz

Context

LoJax is a UEFI rootkit used by APT28 to persist remote access software on targeted systems.

Detection coverage

  • 134 Sigma rules

Malware & tools used

  • Modify Registry (attack-pattern)
  • NTFS File Attributes (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • System Firmware (attack-pattern)
  • Rootkit (attack-pattern)

Used by threat actors

Reports & references

  • Broadcom/Symantec — Apt28 Espionage Military Government (report)
  • ESET — Signed Kernel Drivers Unguarded Gateway Windows Core (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lojax (report)
  • blogs.vmware.com — Detecting Uefi Bootkits In The Wild Part 1 (report)
  • youtube.com — Watch (report)
  • ESET — Eset Lojax (report)
  • habr.com — 668154 (report)
  • MITRE ATT&CK — S0397 (report)

External references