Skip to main content
  1. Home
  2. Computing
  3. News

‘LoJax’ rootkit malware can infect UEFI, a core computer interface

Add as a preferred source on Google
Hacker with Computer
Bill Hinton / Getty Images

Modern computers utilize what is known as a Unified Extensible Firmware Interface (UEFI) to get up and running. When you press the power button on your Mac or PC, the UEFI begins communicating with your computer’s hardware and your operating system of choice, whether that be MacOS, Windows, or Linux. However, in a terrifying turn of events, ESET researchers have discovered a malicious piece of software, a rootkit, that burrows into your UEFI and is nearly impossible to get rid of, even when detected.

Rootkits are malicious bits of computer software that can infect a user’s machine and gain access to areas that are typically off-limits, such a private user data or protected system files. While the concept of rootkits taking advantage of a computer’s UEFI isn’t new, this is the first time that a sample has been detected in the wild.

Recommended Videos

The UEFI rootkit, code-named LoJax, takes advantage of a legitimate software designed by the Canadian company, Absolute Software. The security company offers an anti-theft solution for computers known as LoJack, which can assist victims in locating their stolen property. One of LoJack’s most exceptional features is its ability to stay present on a machine when the operating system is reinstalled, and the now malicious LoJax variation has taken keen advantage of that function.

LoJax has been shown to be the child of cyber espionage and hacking group Fancy Bear. Typically acknowledged as a product of the Russian military intelligence agency, GRU, the group has been behind many prominent attacks including those in the German parliament, the White House, NATO, the Democratic National Committee, and the International Olympic Committee.

What makes a UEFI rootkit particularly dangerous when compared to a standard rootkit is its ability to survive. Not only can LoJax gain access to restricted files on a user’s machine, but it can withstand the digital equivalent of a complete holocaust. Due to the way in which the rootkit attaches to a machine’s SPI flash memory, the chip in which a computer’s UEFI is kept, wiping your internal drive, or even completely replacing it, won’t get rid of it.

The LoJax rootkit can only be removed from a system by either reprogramming the SPI flash memory, a very delicate and complex operation, or by completely swapping out the motherboard. Individuals can help to keep themselves safe against the attack by ensuring that their machines have Secure Boot enabled; this prevents unauthorized firmware on your UEFI from booting your computer.

Michael Archambault
Former Digital Trends Contributor
Michael Archambault is a technology writer and digital marketer located in Long Island, New York. For the past decade…
The U.S. needs air traffic controllers, and it’s turning to gamers for help
Secretary Sean Duffy says gamer recruitment is helping the FAA reach its hiring goals.
Airport, Aircraft, Airplane

Perhaps all those hours spent playing Counter-Strike 2, Valorant, or StarCraft II could finally prove useful outside your gaming setup. The U.S. Department of Transportation has been recruiting gamers to become air traffic controllers, and Transportation Secretary Sean Duffy says the unusual approach is already helping the Federal Aviation Administration make progress toward its hiring target.

The FAA says its gamer recruitment push is working

Read more
After Google, Apple may quietly turn iCloud+ into a tiered AI subscription
iOS 27 beta 5 reveals that Apple Intelligence feature limits now scale with your iCloud+ storage tier.
apple-icloud+

iOS 27's fifth beta quietly shows something Apple only hinted at during its last earnings call: paying for a higher iCloud+ tier unlocks more access to Apple Intelligence features, starting with your smart home cameras.

So how is this actually showing up right now?

Read more
Acer’s first Googlebook could finally fix everything Chromebooks got wrong
The leaked 14-inch machine reportedly combines a Core Ultra 7 processor with 32GB RAM and a high-resolution OLED panel.
GoogleBook Featured Image Official

Chromebooks have long been associated with affordable, browser-first laptops. This time around though, Acer's upcoming Googlebook 14 GP714-91N has surfaced through retailer listings and other databases, with configurations reportedly featuring Intel's Core Ultra 7 355, up to 32GB RAM and a 2.8K OLED display. As reported by NotebookCheck, the GP714-91N is linked to Acer's Moonstone Googlebook development.

This is no ordinary Chromebook

Read more