SYMBOLCOMMON_NAMEaka. SYNONYMS
win.blacklotus (Back to overview)

BlackLotus

VTCollection    

There is no description at this point.

References
2023-12-13 ⋅ cocomelonc ⋅ cocomelonc
Malware in the wild book
AsyncRAT Babuk BlackCat BlackLotus Carbanak HelloKitty Paradise Stealc WinDealer
2023-08-26 ⋅ BushidoToken Blog ⋅ BushidoToken
Tracking Adversaries: Scattered Spider, the BlackCat affiliate
BlackLotus POORTRY
2023-07-15 ⋅ MSSP Lab ⋅ cocomelonc
Malware source code investigation: BlackLotus - part 1
BlackLotus
2023-05-29 ⋅ kn0s-organization
BlackLotus stage 2 bootkit-rootkit analysis
BlackLotus
2023-04-11 ⋅ Microsoft ⋅ Microsoft Incident Response
Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign
BlackLotus
2023-03-09 ⋅ binarly ⋅ Aleksandr Matrosov
The Untold Story of the BlackLotus UEFI Bootkit
BlackLotus
2023-03-01 ⋅ ESET Research ⋅ Martin Smolár
BlackLotus UEFI bootkit: Myth confirmed
BlackLotus
Yara Rules
[TLP:WHITE] win_blacklotus_auto (20260917 | Detects win.blacklotus.)
rule win_blacklotus_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.blacklotus."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blacklotus"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488bd3 408acf e8???????? 488bcb e8???????? 8a4b0d 4080c7ff }
            // n = 7, score = 100
            //   488bd3               | jge                 0x1524
            //   408acf               | inc                 sp
            //   e8????????           |                     
            //   488bcb               | add                 eax, esi
            //   e8????????           |                     
            //   8a4b0d               | dec                 eax
            //   4080c7ff             | lea                 edx, [0x1f18]

        $sequence_1 = { 4883ec20 488bd9 488bfa 488b4a58 e8???????? }
            // n = 5, score = 100
            //   4883ec20             | mov                 dword ptr [ebp - 0x50], 0xec130ccd
            //   488bd9               | mov                 dword ptr [ebp - 0x4c], 0x1744975f
            //   488bfa               | mov                 dword ptr [ebp - 0x48], 0x3d7ea7c4
            //   488b4a58             | mov                 dword ptr [ebp - 0x51], 0x5746155e
            //   e8????????           |                     

        $sequence_2 = { 488b4940 e8???????? 488905???????? 4885c0 7425 8d4f1f ff5618 }
            // n = 7, score = 100
            //   488b4940             | mov                 ecx, dword ptr [edx + 0x58]
            //   e8????????           |                     
            //   488905????????       |                     
            //   4885c0               | dec                 eax
            //   7425                 | mov                 ecx, ebx
            //   8d4f1f               | dec                 eax
            //   ff5618               | mov                 ebx, ecx

        $sequence_3 = { c7442434f26b6fc5 458bc3 c74424383001672b c744243cfed7ab76 }
            // n = 4, score = 100
            //   c7442434f26b6fc5     | stosb               byte ptr es:[edi], al
            //   458bc3               | stosb               byte ptr es:[edi], al
            //   c74424383001672b     | stosb               byte ptr es:[edi], al
            //   c744243cfed7ab76     | stosb               byte ptr es:[edi], al

        $sequence_4 = { 6683ea60 8d41ff 8bfe 4103c1 6689544508 }
            // n = 5, score = 100
            //   6683ea60             | inc                 edx
            //   8d41ff               | mov                 byte ptr [eax + edx], dh
            //   8bfe                 | inc                 ecx
            //   4103c1               | call                esi
            //   6689544508           | jmp                 0x6e7

        $sequence_5 = { 488d15741d0000 448bc6 488bcb e8???????? 488bf8 4885c0 }
            // n = 6, score = 100
            //   488d15741d0000       | add                 edx, esi
            //   448bc6               | dec                 eax
            //   488bcb               | add                 ecx, ebp
            //   e8????????           |                     
            //   488bf8               | inc                 bx
            //   4885c0               | mov                 edx, dword ptr [esi + ecx*8 + 0x2c]

        $sequence_6 = { 410fb7c1 413bc2 72d9 66423974c210 }
            // n = 4, score = 100
            //   410fb7c1             | cmp                 eax, 0x23f0
            //   413bc2               | dec                 eax
            //   72d9                 | lea                 ecx, [0xfffffc3b]
            //   66423974c210         | cmp                 eax, 0x1db0

        $sequence_7 = { c745a4929d38f5 c745a8bcb6da21 c745ac10fff3d2 c745b0cd0c13ec }
            // n = 4, score = 100
            //   c745a4929d38f5       | sub                 eax, 8
            //   c745a8bcb6da21       | dec                 eax
            //   c745ac10fff3d2       | shr                 eax, 1
            //   c745b0cd0c13ec       | dec                 ecx

        $sequence_8 = { 4885c0 0f883a010000 8d571f 448d4701 488d0dd21f0000 e8???????? 488b4c2478 }
            // n = 7, score = 100
            //   4885c0               | mov                 esi, eax
            //   0f883a010000         | sub                 esi, 2
            //   8d571f               | je                  0xac2
            //   448d4701             | cmp                 esi, 1
            //   488d0dd21f0000       | dec                 eax
            //   e8????????           |                     
            //   488b4c2478           | mov                 ecx, dword ptr [esp + 0x68]

        $sequence_9 = { 48897010 48897818 4c897020 55 488d68c8 4881ec30010000 4c8bd1 }
            // n = 7, score = 100
            //   48897010             | mov                 ecx, esi
            //   48897818             | inc                 esp
            //   4c897020             | mov                 dword ptr [esp + 0x20], edi
            //   55                   | inc                 ecx
            //   488d68c8             | call                esi
            //   4881ec30010000       | mov                 ebx, eax
            //   4c8bd1               | test                eax, eax

    condition:
        7 of them and filesize < 181248
}
Download all Yara Rules