Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
LoJax has modified the Registry key |
Enterprise | T1564 | .004 | Hide Artifacts: NTFS File Attributes |
LoJax has loaded an embedded NTFS DXE driver to be able to access and write to NTFS partitions.[1] |
Enterprise | T1112 | Modify Registry |
LoJax has modified the Registry key |
|
Enterprise | T1542 | .001 | Pre-OS Boot: System Firmware |
LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.[1] |
Enterprise | T1014 | Rootkit |
LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.[1] |
ID | Name | References |
---|---|---|
G0007 | APT28 |