Open cardosec

Case 87850F · Malware & intel · L5 Expert

UEFI bootkits and BlackLotus

Practise as: Deep dive · Interview

Interview questionHow did BlackLotus bypass Secure Boot on fully patched Windows 11, and why is fixing it so hard?

  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Bootkits run before the OS loader, so they can tamper with the kernel before EDR, HVCI or BitLocker protections start
  2. BlackLotus (ESET, 2023) used CVE-2022-21894: old signed but vulnerable Windows boot managers that were not yet in DBX
  3. It enrolled an attacker-owned MOK for persistence on the ESP and could disable HVCI, BitLocker and Defender
  4. Patching the OS does not help while vulnerable signed binaries stay trusted; revocation needs DBX/SVN updates
  5. DBX revocation can brick old boot media, so Microsoft (CVE-2023-24932, KB5025885) staged opt-in, manual mitigations

If the interviewer pushes back

  • How would you detect a bootkit when you cannot trust anything the running OS tells you?
  • Compare an ESP-resident bootkit with SPI flash implants like LoJax or MosaicRegressor for persistence and remediation.

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.