| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1014 | Rootkit |
LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.[1] |
|
| Enterprise | T1112 | 修改注册表 |
LoJax has modified the Registry key |
|
| Enterprise | T1547 | .001 | 启动或登录自动启动执行: Registry Run Keys / Startup Folder |
LoJax has modified the Registry key |
| Enterprise | T1564 | .004 | 隐藏伪装: NTFS File Attributes |
LoJax has loaded an embedded NTFS DXE driver to be able to access and write to NTFS partitions.[1] |
| Enterprise | T1542 | .001 | 预操作系统引导: System Firmware |
LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.[1] |