LoJax
LoJax is a type of malware known for its ability to persist on infected systems by targeting the Unified Extensible Firmware Interface (UEFI), a critical component of modern computer systems. LoJax is notable for being one of the first publicly known cases of UEFI rootkit malware, which allows it to survive operating system reinstallation and hard drive replacement. As of October 2023, cybersecurity organizations have attributed LoJax to a threat actor group known as APT28, also referred to as Fancy Bear, which is believed to be associated with Russian intelligence services. This malware has been used primarily for espionage purposes.
Overview
LoJax is a sophisticated malware that targets the UEFI firmware of computers. UEFI is a specification that defines a software interface between an operating system and platform firmware. By infecting the UEFI, LoJax can maintain persistence on a system even if the operating system is reinstalled or the hard drive is replaced. This makes it particularly challenging to detect and remove. LoJax has been primarily used for espionage, targeting government and diplomatic entities.
History
LoJax was first discovered in 2018 by cybersecurity researchers at ESET. The malware was found to be part of a campaign attributed to APT28, a group known for its advanced cyber-espionage operations. The discovery of LoJax marked a significant development in the field of cybersecurity, as it was the first publicly known instance of a UEFI rootkit being used in the wild. The malware's name is derived from LoJack, a legitimate anti-theft software, as LoJax hijacks the legitimate software's functionality to achieve persistence.
Technical characteristics
LoJax is a UEFI rootkit, which means it infects the firmware of a computer at a level below the operating system. This allows it to persist through system reboots and even hardware changes. The malware works by modifying the SPI flash memory, where the UEFI firmware is stored. LoJax is capable of downloading additional payloads and executing them on the infected system, allowing the attackers to maintain control over the compromised device.
Infection vector
LoJax is typically delivered through spear-phishing emails, which are targeted messages designed to trick the recipient into downloading and executing malicious software. Once the initial payload is executed, LoJax exploits vulnerabilities in the system to gain access to the UEFI firmware. The malware then modifies the firmware to include its malicious code, ensuring that it is loaded every time the system boots.
Notable campaigns
LoJax has been used in several notable cyber-espionage campaigns. One of the most significant was its use against government and diplomatic entities in Europe. The campaigns attributed to APT28 have focused on gathering intelligence and compromising sensitive information. The use of LoJax in these operations highlights the advanced capabilities of the threat actor and the challenges in defending against such sophisticated malware.
Detection and mitigation
Detecting LoJax can be challenging due to its ability to persist in the UEFI firmware. However, several strategies can be employed to identify and mitigate the threat. Regular firmware integrity checks can help detect unauthorized modifications to the UEFI. Additionally, implementing secure boot mechanisms can prevent unauthorized firmware from being loaded. Organizations are advised to maintain up-to-date security patches and educate employees about the risks of spear-phishing to reduce the likelihood of initial infection.
History of LoJax Malware
LoJax Infection Process
See also
- lateral movement