APT28__2018__ESET-LoJax.pdf
ID: a0745aa4-1f68-4498-95ab-11864e83fec1
STIX ID: report--a0745aa4-1f68-4498-95ab-11864e83fec1
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2018-09-21
Last Modified Date: 2018-09-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET documents the first known in-the-wild UEFI rootkit (SecDxe / LoJax) attributed to the Sednit (APT28) ecosystem: attackers used custom tools to dump, patch and reflash SPI firmware, installed a malicious DXE driver that drops a trojanized LoJack/Computrace small agent (rpcnetp.exe) and a launcher (autoche.exe), and abused BIOS write-protection weaknesses (race conditions, misconfigured BLE/SMM_BWP) to persist across OS reinstall and disk replacement; the paper provides technical analysis, remediation guidance and IOCs.
