logo

APT28__2018__ESET-LoJax.pdf

ID: a0745aa4-1f68-4498-95ab-11864e83fec1

STIX ID: report--a0745aa4-1f68-4498-95ab-11864e83fec1

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2018-09-21

Last Modified Date: 2018-09-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET documents the first known in-the-wild UEFI rootkit (SecDxe / LoJax) attributed to the Sednit (APT28) ecosystem: attackers used custom tools to dump, patch and reflash SPI firmware, installed a malicious DXE driver that drops a trojanized LoJack/Computrace small agent (rpcnetp.exe) and a launcher (autoche.exe), and abused BIOS write-protection weaknesses (race conditions, misconfigured BLE/SMM_BWP) to persist across OS reinstall and disk replacement; the paper provides technical analysis, remediation guidance and IOCs.