DiscoverESET Research podcastFinding the mythical BlackLotus bootkit
Finding the mythical BlackLotus bootkit

Finding the mythical BlackLotus bootkit

Update: 2023-07-12
Share

Description

Towards the end of 2022, an unknown threat actor boasted online that they created a new and powerful UEFI bootkit called BlackLotus. Its most distinctive feature? It could mysteriously bypass UEFI Secure Boot, a feature built into all modern computers to prevent them from running unauthorized software. What at first sounded like a myth turned into reality a few months later when ESET researchers discovered a sample that perfectly matched all the mentioned attributes of a UEFI bootkit known as BlackLotus. Listen to the fascinating story of ESET Malware Researcher Martin Smolár describing his threat hunt to our host ESET Distinguished Researcher Aryeh Goretsky. For more info about this research, read the blogpost on WeLiveSecurity.com.


Host:


Aryeh Goretsky, ESET Distinguished Researcher


Guest:


Martin Smolár, ESET Malware Researcher


Materials:


BlackLotus UEFI bootkit: Myth confirmed

Comments 
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Finding the mythical BlackLotus bootkit

Finding the mythical BlackLotus bootkit

ESET Research