Case 87850F · Malware & intel · L5 Expert
UEFI bootkits and BlackLotus
Practise as: Deep dive · Interview
Interview questionHow did BlackLotus bypass Secure Boot on fully patched Windows 11, and why is fixing it so hard?
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Bootkits run before the OS loader, so they can tamper with the kernel before EDR, HVCI or BitLocker protections start
- BlackLotus (ESET, 2023) used CVE-2022-21894: old signed but vulnerable Windows boot managers that were not yet in DBX
- It enrolled an attacker-owned MOK for persistence on the ESP and could disable HVCI, BitLocker and Defender
- Patching the OS does not help while vulnerable signed binaries stay trusted; revocation needs DBX/SVN updates
- DBX revocation can brick old boot media, so Microsoft (CVE-2023-24932, KB5025885) staged opt-in, manual mitigations
If the interviewer pushes back
- How would you detect a bootkit when you cannot trust anything the running OS tells you?
- Compare an ESP-resident bootkit with SPI flash implants like LoJax or MosaicRegressor for persistence and remediation.
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.