LoJax — Malware Profile
LoJax is a UEFI rootkit used by APT28 to persist remote access software on targeted systems.
MITRE ATT&CK techniques (5)
- T1014 Rootkit
- T1112 Modify Registry
- T1542.001 System Firmware
- T1547.001 Registry Run Keys / Startup Folder
- T1564.004 NTFS File Attributes