ATT&CKReferencesESET LoJax Sept 2018

ESET LoJax Sept 2018

ESET. (2018, September). LOJAX First UEFI rootkit found in the wild, courtesy of the Sednit group. Retrieved July 2, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareLoJax

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

T1014
Rootkit
GroupAPT28

APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax.

T1112
Modify Registry
MalwareLoJax

LoJax has modified the Registry key ‘HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute’ from ‘autocheck autochk *’ to ‘autocheck autoche *’.

T1542.001
System Firmware
MalwareLoJax

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

T1547.001
Registry Run Keys / Startup Folder
MalwareLoJax

LoJax has modified the Registry key ‘HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute’ from ‘autocheck autochk *’ to ‘autocheck autoche *’ in order to execute its payload during Windows startup.

T1564.004
NTFS File Attributes
MalwareLoJax

LoJax has loaded an embedded NTFS DXE driver to be able to access and write to NTFS partitions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.