/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail UEFI bootkit BlackLotus, capable of bypassing UEFI Secure Boot even on up-to-date Windows 11 systems and selling for $5K since October 2022

The first in-the-wild UEFI bootkit bypassing UEFI Secure Boot on fully updated UEFI systems is now a reality

WeLiveSecurity Martin Smolár

Context & Ripple Effects

BlackLotus turns a longstanding firmware-level persistence problem into a Secure Boot bypass against fully updated Windows systems. Earlier reporting had already documented MoonBounce surviving a hard-drive swap and a separate UEFI rootkit that persisted through OS reinstalls and drive replacements, establishing why pre-OS compromise is unusually difficult to remove.

The important follow-on issue is remediation: related coverage says the flaws BlackLotus uses were patched, but vulnerable Windows binaries had not been revoked, leaving the trust chain exposed on affected PCs.

First-order effects

  • BlackLotus buyers can target up-to-date Windows 11 systems with a bootkit that defeats Secure Boot, undermining a protection intended to stop untrusted code before the operating system loads.
  • Microsoft and Windows administrators face a remediation gap where applying the underlying patch alone does not neutralize already-trusted vulnerable boot components.

Second-order effects

  • Security teams must treat firmware and boot components as part of incident response, since an OS reinstall or drive replacement may not remove UEFI-level persistence.
  • Attackers selling bootkits gain a more credible market proposition when Secure Boot bypasses work on fully updated systems rather than only on unpatched machines.

Third-order effects

  • The UEFI security boundary is becoming a sustained attack surface rather than a Windows-only hardening layer, as later coverage of a Linux-focused UEFI bootkit shows bootkit targeting expanding across operating systems.
  • If revocation remains slower or more disruptive than patching, platform vendors will face growing pressure to manage the full boot trust chain, not just ship fixes for individual flaws.

The trend: Bootkit activity is shifting toward durable compromises of the UEFI trust chain, forcing endpoint defense beyond operating-system patching.

Discussion

  • @esetresearch @esetresearch on x
    #ESETResearch analyze first in-the-wild UEFI bootkit bypassing UEFI Secure Boot even on fully updated Windows 11 systems. Its functionality indicates it is the #BlackLotus UEFI bootkit, for sale on hacking forums since at least Oct 6, 2022. @smolar_m https://www.welivesecurity.co…
  • @aall86 Andrea Allievi on x
    https://www.welivesecurity.com/ ... This is really genius. I haven't seen something so advanced since 10 years ago! Woow!
  • @welivesecurity @welivesecurity on x
    #Breaking: ESET researchers are the first to publish an analysis of #BlackLotus, the first in-the-wild UEFI #bootkit that can run even on fully up-to-date #Windows 11 systems with UEFI Secure Boot enabled. Learn more in our blog: https://www.welivesecurity.com/ ...