BlackLotus
- Malware type
- exploit-kit
- Family
- Malware family
- Profile updated
- 2026-07-07 14:46:02
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
BlackLotus is an advanced malware family known for its capability to bypass secure boot mechanisms and persist on a system through UEFI exploitation. It has been used in attacks against government and financial sectors, showcasing advanced evasion techniques.
Detection coverage
- 1 YARA rules
Exploited vulnerabilities
- CVE-2022-21894 (vulnerability)
Detection rules
- MALPEDIA_Win_Blacklotus_Auto (yara-rule)
Reports & references
- cocomelonc.github.io — Malwild Book (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Blacklotus (report)
- kn0s-organization.gitbook.io — Blacklotus Analysis Stage2 Bootkit Rootkit Stage (report)
- mssplab.github.io — Malware Src Blacklotus (report)
- ESET — Blacklotus Uefi Bootkit Myth Confirmed (report)
- Microsoft — Guidance For Investigating Attacks Using Cve 2022 21894 The Blacklotus Campaign (report)
- blog.bushidotoken.net — Tracking Adversaries Scattered Spider (report)
- binarly.io — Index (report)