BlackLotus Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
November 4, 2025
Last Seen
July 15, 2026

BlackLotus is a malware family tracked across 8 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 15, 2026.

Overview

BlackLotus is a malware family known for firmware/UEFI-level compromise and bootkit capabilities that enable persistence on Windows devices by loading at startup and potentially bypassing security controls such as Secure Boot. Its significance lies in its stealthy, long-lasting presence that can survive OS reinstall and complicate detection and remediation in enterprise environments.

Related Threat Clusters

Recent Intelligence Reports

  • Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass — Infosecurity-Magazine · July 15, 2026
  • Vulnerable UEFI shims allow decade — Feeds.4Sysops · July 15, 2026
  • Forgotten UEFI shims undermining Secure Boot — Welivesecurity · July 14, 2026
  • Under Cloak Uefi Secure Boot Introducing Cve 2024 7344 — www.welivesecurity.com · June 18, 2026
  • Unified Extensible Firmware Interface UEFI — www.techtarget.com · June 16, 2026
  • Security analysts — www.stmicro.net · June 4, 2026
  • What CISA KEV Is and Isn’t — Thecyberexpress · February 6, 2026
  • CISA Releases Guidance for Managing UEFI Secure Boot on Enterprise Devices — Cybersecuritynews · December 15, 2025

CVSS v3.1 Breakdown