BlackLotus Eats Secure Boot For Breakfast And Likes It

How to own a computer with just 80kb

BlackLotus was in the news last year after several oddities were detected and submitted to VirusTotal. These initial detections and further suspicious activity reported to ESET suggest that this is new. The infection was highly resilient and survived reimaging, hard drive replacement, and bypassing UEFI Secure Boot. It took a while for experts to unravel BlackLotus and determine exactly what was going on, but they finally succeeded, and the news is not good.

BlackLotus infects the EFI system partition, which is not protected by the same security features found in the motherboard’s UEFI, or more specifically, the SPI chip that updates it every time you flash a new BIOS. This allows the infection to load before the hardware’s secure boot and other security features are loaded, giving it time to perform nasty tricks. The malware registers its machine owner key as valid in combination with shim loaders signed by various Linux distributors. At that point, every reboot will launch the bootkit, allowing the attacker to load any infections that the antivirus has managed and removed.

This is how BlackLotus is actually used, making machines permanently vulnerable to other malware attacks by granting administrator access to processes to exploit other system vulnerabilities present in the system. It is a function to make If infected, there’s nothing you can do to get rid of it other than throwing the motherboard. However, keeping your system up-to-date with patches will limit secondary infections and protect you from secondary infections that BlackLotus tries to load onto your system.

If you want to terrify yourself, read the full story on Ars Technica as we delve into the technical side of this fresh hell.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *