LoJax

S0397

Malware.View on attack.mitre.org

About this malware

LoJax is a UEFI rootkit used by APT28 to persist remote access software on targeted systems.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1014
Rootkit

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

T1112
Modify Registry

LoJax has modified the Registry key ‘HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute’ from ‘autocheck autochk *’ to ‘autocheck autoche *’.

T1542.001
System Firmware

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

T1547.001
Registry Run Keys / Startup Folder

LoJax has modified the Registry key ‘HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute’ from ‘autocheck autochk *’ to ‘autocheck autoche *’ in order to execute its payload during Windows startup.

T1564.004
NTFS File Attributes

LoJax has loaded an embedded NTFS DXE driver to be able to access and write to NTFS partitions.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET LoJax Sept 2018 Open source
    ESET. (2018, September). LOJAX First UEFI rootkit found in the wild, courtesy of the Sednit group. Retrieved July 2, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.