TF-MAL-osx.hiddenlotus
📛 Threat Title
Malware family: HiddenLotus
Description
ThreatFox malware family `osx.hiddenlotus`. Printable name: HiddenLotus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.hiddenlotus
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.hiddenlotus
IOC database
- Type
- domain
- Value
osx.hiddenlotus- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.hiddenlotus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.hiddenlotus
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:csiac.dtic.mil
FORT MEADE, Md. — Malicious cyber actors could take advantage of a known vulnerability in the Microsoft Windows secure startup process to bypass Secure Boot protection and execute BlackLotus malware . To guide system administrators and network defenders on how to mitigate this threat, the National Security Agency (NSA) is publicly releasing the "BlackLotus Mitigation Guide" Cybersecurity
-
web:github.com
BlackLotus aka CVE-2023-24932 Detection/ Remediation Scripts for Intune, ConfigMgr, and generic use - ajf8729/BlackLotus
-
web:intelligencecommunitynews.com
Malicious cyber actors could take advantage of a known vulnerability in the Microsoft Windows secure startup process to bypass Secure Boot protection and execute BlackLotus malware . To guide system administrators and network defenders on how to mitigate this threat, the National Security Agency (NSA) is publicly releasing the "BlackLotus Mitigation Guide" Cybersecurity Information Sheet ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to Malwarebytes, The HiddenLotus "dropper" is an application named Lê Thu Hà (HAEDC).pdf, using an old trick of disguising itself as a document - in this case, an Adobe Acrobat file.
-
web:media.defense.gov
BlackLotus is a recently publicized malware product garnering significant attention within tech media. Similar to 2020's BootHole (CVE-2020-10713), BlackLotus takes advantage of a boot loader flaw—specifically CVE-2022-21894 Secure Boot bypass known as "Baton Drop"—to take control of an endpoint from the earliest phase of software boot. Microsoft® issued patches for supported ...
-
web:www.bankinfosecurity.com
The National Security Agency has released mitigation advice for locking down Windows and Linux environments against powerful BlackLotus malware , warning
-
web:www.hstoday.us
Malicious cyber actors could take advantage of a known vulnerability in the Microsoft Windows secure startup process to bypass Secure Boot protection and execute BlackLotus malware . To guide system administrators and network defenders on how to mitigate this threat, the National Security Agency (NSA) is publicly releasing the "BlackLotus Mitigation Guide" Cybersecurity Information Sheet ...
-
web:www.infosecurity-magazine.com
The US National Security Agency (NSA) has released a comprehensive mitigation guide to address the BlackLotus malware . According to the document, BlackLotus exploits a boot loader flaw, known as "Baton Drop," (CVE-2022-21894) to take control of endpoints during the early phase of software boot ...
-
web:www.microsoft.com
A guide to assess whether users have been targeted or compromised by threat actors exploiting CVE-2022-21894 via BlackLotus UEFI bootkit.
-
web:www.nsa.gov
FORT MEADE, Md. — Malicious cyber actors could take advantage of a known vulnerability in the Microsoft Windows secure startup process to bypass Secure Boot protection and execute BlackLotus malware . To guide system administrators and network defenders on how to mitigate this threat, the National Security Agency (NSA) is publicly releasing the "BlackLotus Mitigation Guide" Cybersecurity ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.