
NSA's Guide to Combat and Mitigate BlackLotus Malware Threats.
The NSA has released guidance to help organizations detect and prevent infections of the BlackLotus UEFI bootkit, which can bypass Windows Secure Boot protections. The malware exploits a known Windows flaw called Baton Drop and grants a threat actor complete control over the operating system booting procedure. Organizations are advised to harden user executable policies, monitor the integrity of the boot partition, and customize UEFI Secure Boot to block older, signed Windows boot loaders. Microsoft is expected to completely close the attack vector in the first quarter of 2024.