Researchers detail UEFI bootkit BlackLotus, capable of bypassing UEFI Secure Boot even on up-to-date Windows 11 systems and selling for $5K since October 2022
The first in-the-wild UEFI bootkit bypassing UEFI Secure Boot on fully updated UEFI systems is now a reality
Context & Ripple Effects
BlackLotus turns a longstanding firmware-level persistence problem into a Secure Boot bypass against fully updated Windows systems. Earlier reporting had already documented MoonBounce surviving a hard-drive swap and a separate UEFI rootkit that persisted through OS reinstalls and drive replacements, establishing why pre-OS compromise is unusually difficult to remove.
The important follow-on issue is remediation: related coverage says the flaws BlackLotus uses were patched, but vulnerable Windows binaries had not been revoked, leaving the trust chain exposed on affected PCs.
First-order effects
- BlackLotus buyers can target up-to-date Windows 11 systems with a bootkit that defeats Secure Boot, undermining a protection intended to stop untrusted code before the operating system loads.
- Microsoft and Windows administrators face a remediation gap where applying the underlying patch alone does not neutralize already-trusted vulnerable boot components.
Second-order effects
- Security teams must treat firmware and boot components as part of incident response, since an OS reinstall or drive replacement may not remove UEFI-level persistence.
- Attackers selling bootkits gain a more credible market proposition when Secure Boot bypasses work on fully updated systems rather than only on unpatched machines.
Third-order effects
- The UEFI security boundary is becoming a sustained attack surface rather than a Windows-only hardening layer, as later coverage of a Linux-focused UEFI bootkit shows bootkit targeting expanding across operating systems.
- If revocation remains slower or more disruptive than patching, platform vendors will face growing pressure to manage the full boot trust chain, not just ship fixes for individual flaws.
The trend: Bootkit activity is shifting toward durable compromises of the UEFI trust chain, forcing endpoint defense beyond operating-system patching.