Skip to main content

‘LoJax’ rootkit malware can infect UEFI, a core computer interface

Hacker with Computer
Bill Hinton/Getty Images

Modern computers utilize what is known as a Unified Extensible Firmware Interface (UEFI) to get up and running. When you press the power button on your Mac or PC, the UEFI begins communicating with your computer’s hardware and your operating system of choice, whether that be MacOS, Windows, or Linux. However, in a terrifying turn of events, ESET researchers have discovered a malicious piece of software, a rootkit, that burrows into your UEFI and is nearly impossible to get rid of, even when detected.

Rootkits are malicious bits of computer software that can infect a user’s machine and gain access to areas that are typically off-limits, such a private user data or protected system files. While the concept of rootkits taking advantage of a computer’s UEFI isn’t new, this is the first time that a sample has been detected in the wild.

Recommended Videos

The UEFI rootkit, code-named LoJax, takes advantage of a legitimate software designed by the Canadian company, Absolute Software. The security company offers an anti-theft solution for computers known as LoJack, which can assist victims in locating their stolen property. One of LoJack’s most exceptional features is its ability to stay present on a machine when the operating system is reinstalled, and the now malicious LoJax variation has taken keen advantage of that function.

LoJax has been shown to be the child of cyber espionage and hacking group Fancy Bear. Typically acknowledged as a product of the Russian military intelligence agency, GRU, the group has been behind many prominent attacks including those in the German parliament, the White House, NATO, the Democratic National Committee, and the International Olympic Committee.

What makes a UEFI rootkit particularly dangerous when compared to a standard rootkit is its ability to survive. Not only can LoJax gain access to restricted files on a user’s machine, but it can withstand the digital equivalent of a complete holocaust. Due to the way in which the rootkit attaches to a machine’s SPI flash memory, the chip in which a computer’s UEFI is kept, wiping your internal drive, or even completely replacing it, won’t get rid of it.

The LoJax rootkit can only be removed from a system by either reprogramming the SPI flash memory, a very delicate and complex operation, or by completely swapping out the motherboard. Individuals can help to keep themselves safe against the attack by ensuring that their machines have Secure Boot enabled; this prevents unauthorized firmware on your UEFI from booting your computer.

Michael Archambault
Former Digital Trends Contributor
Michael Archambault is a technology writer and digital marketer located in Long Island, New York. For the past decade…
LG just launched its fastest OLED monitor yet — and you can buy it for $800
LG's UltraGear GX7 OLED gaming monitor sitting on a stand.

LG is coming out with the fastest OLED gaming monitor it has ever released. The new UltraGear GX7 is a 1440p monitor packing a WOLED display from LG Display, and it clocks a blistering 480Hz refresh rate that's worthy of a slot among the best gaming monitors.

We've seen these specs before, just not from LG. Earlier this year, we got the Sony InZone M10S and the Asus ROG Swift PG27AQDP, both of which use the same 1440p panel with a 480Hz refresh rate. LG's offering is interesting compared to the Sony competition, however, as the UltraGear GX7 comes in at $1,000 -- $100 less than the InZone M10S.

Read more
This open-source alternative to ChatGPT just got serious
The beta Canvas feature on Mistral

French AI startup Mistral announced Monday that it is incorporating a half-dozen new features and capabilities into its free generative AI work assistant, dubbed le Chat (French for "the cat"), that will put the open-source chatbot on par with leading frontier models from OpenAI and Anthropic.

Le Chat can now search the web and provide cited sources, similar to what Perplexity and SearchGPT both offer. Mistral's chatbot now also offers a Canvas feature akin to Claude's Artifacts where users can modify and edit content and code. What's more, le Chat can now generate images thanks to an integration with Black Forest Labs' Flux Pro, the same image generator that powers Grok-2's capabilities.

Read more
Windows 11 multitasking is about to get even better
Windows 11 logo on a laptop.

Windows 11 already has great multitasking thanks to Snap Layouts. So, if you know how to split your screen in Windows 11 Snap Layouts, you're already aware of how good it is. And things will get even easier since the Windows 11 KB5046716 update is tinkering around with new Snap Layouts and hidden label ideas, as Phantomofearth noticed and confirmed by Windows Latest.

Windows Latest tested the features and can confirm that Microsoft is testing with different text options for the Snap Layouts, such as:

Read more