GearriceGearrice
  • Tech World
  • Smart Home
  • Mobile Zone
  • 5G
  • Alexa
  • Amazon
  • AMD
  • Android
  • Apple
  • AirPods
  • AirTag
  • Apple Studio
  • Apple TV
  • Apple Watch
  • HomePod
  • iOS
  • iOS 15.4
  • iPad
  • iPhone
  • Mac
  • iMac
  • MacBook
  • Apps
  • Asus
  • Bitcoin
  • Cars
  • ChatGPT
  • Computer
  • Keyboard
  • Contact us
  • Disney
  • Display
  • Electric
  • Elon Musk
  • Gaming
  • Google
  • Chromecast
  • Google Maps
  • HBO
  • How to
  • Huawei
  • HONOR
  • Instagram
  • Intel
  • Internet
  • iQOO
  • Laptop
  • Lenovo
  • LG
  • Meta
  • Facebook
  • Galaxy
  • Metaverse
  • Microsoft
  • Windows
  • Motorola
  • Movies
  • Movistar
  • MWC Barcelona 2022
  • Netflix
  • News
  • Nintendo
  • Nokia
  • Nvidia
  • OPPO
  • OnePlus
  • Realme
  • Orange
  • Oscars
  • Philips
  • PlayStation
  • Pokémon
  • Qualcomm
  • Snapdragon
  • Samsung
  • Solar
  • Sony
  • SpaceX
  • Spotify
  • Tablet
  • Tesla
  • TikTok
  • Tips and Tricks
  • Today
  • Twitch
  • Twitter
  • Vivo
  • VPN
  • WhatsApp
  • Write For Us
  • MIUI
  • POCO
  • Redmi
  • Mouse
  • OLED
  • Prime
  • Scooter
  • Xbox
  • Xiaomi
  • YouTube
Facebook Twitter Instagram
Facebook Twitter Instagram Pinterest
Gearrice Gearrice
Subscribe
  • Tech World
  • Best Deals
  • Gaming
  • Mobile Zone
    • Android
    • Apple
  • Smart Home
GearriceGearrice
Home»Tech World»The latest nightmare is called BlackLotus and it easily bypasses the security of your Windows PC

The latest nightmare is called BlackLotus and it easily bypasses the security of your Windows PC

By Jack Jones02/03/20233 Mins Read
Share
Facebook Twitter LinkedIn Pinterest

This new threat has an extra risk, not only because it is usually invisible to antivirus programs that we install on computers, but because it manages to bypass the security of the Windows PC. Or rather, it has the ability to bypass a security system that we will see below.

Contents hide
1 Bypasses Windows Secure Boot
2 The vulnerability that BlackLotus exploits

Bypasses Windows Secure Boot

In this case, we are dealing with a novel UEFI boot kit for Windows, known for being the first malware capable of bypass secure boot of computers with this operating system. Therefore, it can bring users who have a Windows PC headlong. Even, according to the cybersecurity company ESET, ‘this bootkit can run even on fully updated Windows 11 systems with UEFI Secure Boot enabled‘.

So, by being implemented in the PC’s UEFI firmware, you can gain full control over Windows startup. In this way, it is achieved disable security mechanisms that have the operating system, in this case, the Microsoft system. We must keep in mind that the UEFI firmware was integrated to be the perfect replacement for the old BIOSes.

Furthermore, according to cyber security researcher Scott Scheferman, the license to get hold of this malware is $5,000. And, that’s not all, but for an additional $200 new versions can be released whenever necessary. Although, the problem does not end there for Windows computers.

The biggest drawback of this malware is that, with only a size of 80 Kbytes, it is completely invisible to antivirus. For what has been called, according to cybersecurity researchers, as the first virus known to bypass the secure boot of Windows.

The vulnerability that BlackLotus exploits

This malware is antivirtualization, antidebugging, and code obfuscation. Furthermore, Black Lotus can also disable security solutions. Basically, this is because this malware takes advantage of a security vulnerability which has been tagged as CVE-2022-21894. In this way, it manages to completely bypass Windows protections for UEFI Secure Boot. And not only this, but you can also configure persistence.

USB shortcut malware

In early 2022, Microsoft already tried to address this vulnerability that could be exploited by third parties. Nevertheless, cybercriminals can still exploit itGiven the ‘signed binaries that have been affected have not yet been added to the UEF revocation listI’, according to Martin Smolár, ESET researcher.

Furthermore, another major drawback of this malware is that it is unknown, for the moment, the modus operandi that you use when deploying the boot kit to a Windows computer. Furthermore, if these types of threats were only in the hands of a few people before, now they are available to criminals on all forums. So the risk is higher.

Related Posts

this is the new law that they are about to approve

‘Succession’, what could happen in the fourth season?

make these 10 changes to make your PC more secure

Add A Comment

Leave A Reply Cancel Reply

Tech World

The Future of Pickleball: How Technology Is Shaping the Game

By gearrice24/03/20230

this is the new law that they are about to approve

24/03/2023

‘Succession’, what could happen in the fourth season?

24/03/2023

make these 10 changes to make your PC more secure

24/03/2023

Do you like cheesecake? Soon you will be able to print one. Technology drives the new culinary revolution

24/03/2023
Gearrice
Facebook Twitter Instagram Pinterest
  • Privacy Policy
  • Terms and Conditions
  • Write For Us
© 2023 Gearrice.

Type above and press Enter to search. Press Esc to cancel.