BlackLotus

Malware type
exploit-kit
Family
Malware family
Profile updated
2026-07-07 14:46:02

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Context

BlackLotus is an advanced malware family known for its capability to bypass secure boot mechanisms and persist on a system through UEFI exploitation. It has been used in attacks against government and financial sectors, showcasing advanced evasion techniques.

Detection coverage

  • 1 YARA rules

Exploited vulnerabilities

  • CVE-2022-21894 (vulnerability)

Detection rules

  • MALPEDIA_Win_Blacklotus_Auto (yara-rule)

Reports & references

  • cocomelonc.github.io — Malwild Book (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Blacklotus (report)
  • kn0s-organization.gitbook.io — Blacklotus Analysis Stage2 Bootkit Rootkit Stage (report)
  • mssplab.github.io — Malware Src Blacklotus (report)
  • ESET — Blacklotus Uefi Bootkit Myth Confirmed (report)
  • Microsoft — Guidance For Investigating Attacks Using Cve 2022 21894 The Blacklotus Campaign (report)
  • blog.bushidotoken.net — Tracking Adversaries Scattered Spider (report)
  • binarly.io — Index (report)

External references