By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Lazarus hackers exploited Windows zero-day to gain Kernel privileges
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Lazarus hackers exploited Windows zero-day to gain Kernel privileges
Tech News

Lazarus hackers exploited Windows zero-day to gain Kernel privileges

By admin 3 Min Read
Share
SHARE

North Korean threat actors known as the Lazarus Group exploited a flaw in the Windows AppLocker driver (appid.sys) as a zero-day to gain kernel-level access and turn off security tools, allowing them to bypass noisy BYOVD (Bring Your Own Vulnerable Driver) techniques.

This activity was detected by Avast analysts, who promptly reported it to Microsoft, leading to a fix for the flaw, now tracked as CVE-2024-21338, as part of the February 2024 Patch Tuesday. However, Microsoft has not marked the flaw as being exploited as a zero-day.

Avast reports that Lazarus exploited CVE-2024-21338 to create a read/write kernel primitive in an updated version of its FudModule rootkit, which ESET first documented in late 2022. Previously, the rootkit abused a Dell driver for BYOVD attacks.

The new version of FudModule features significant enhancements in stealth and functionality, including new and updated techniques for evading detection and turning off security protections like Microsoft Defender and CrowdStrike Falcon.

Moreover, by retrieving most of the attack chain, Avast discovered a previously undocumented remote access trojan (RAT) used by Lazarus, which the security firm promised to share more details about at BlackHat Asia in April.

Lazarus 0-day exploitation

The malware exploited a vulnerability in Microsoft’s ‘appid.sys’ driver, a Windows AppLocker component that provides application whitelisting capabilities.

Lazarus exploits it by manipulating the Input and Output Control (IOCTL) dispatcher in the appid.sys driver to call an arbitrary pointer, tricking the kernel into executing unsafe code, thus bypassing security checks.

Direct syscalls used in the exploit
<strong>Direct syscalls used in the exploit</strong> <em>(Avast)</em>

The FudModule rootkit, built within the same module as the exploit, executes direct kernel object manipulation (DKOM) operations to turn off security products, hide malicious activities, and maintain persistence on the breached system.

The targeted security products are AhnLab V3 Endpoint Security, Windows Defender, CrowdStrike Falcon, and the HitmanPro anti-malware solution.

Avast observed new stealth features and expanded capabilities in the new rootkit version, like the ability to suspect processes protected by Protected Process Light (PPL) by manipulating handle table entries, selective and targeted disruption via DKOM, enhancements in tampering with Driver Signature Enforcement and Secure Boot, and more.

Avast notes that this new exploit tactic marks a significant evolution in the threat actor’s kernel access capabilities, allowing them to launch stealthier attacks and persist on compromised systems for longer periods.

Rootkit's main function executing individual techiques
<strong>Rootkit&#8217;s main function executing individual techiques</strong> <em>(Avast)</em>

The only effective security measure is to apply the February 2024 Patch Tuesday updates as soon as possible, as Lazarus’ exploitation of a Windows built-in driver makes the attack particularly challenging to detect and stop.

YARA rules to help defenders detect activity linked to the latest version of the FudModule rootkit can be found here.

You Might Also Like

Android 16 Material 3 Expressive Design Overhaul Leaked

Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials

Netgear Orbi 770 Series Review: Wi-Fi 7 Family Harmony

Irish company Miagen to help elite football clubs avoid financial ruin

How Microgravity is Revolutionizing Drug Development in Space

TAGGED: 0-day, BYOVD, Lazarus Group, North Korea, Vulnerability, Windows, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article “We Don’t See a Place for Microtransactions in Single-Player Games,” CD Projekt RED Reiterates
Next Article Three Sixty International – Refresh Your Brand
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

The vast majority of CEOs are fearful of losing their jobs to AI, survey reveals
Business
Turkey’s Role In Focus After Pakistan’s Military Escalation Against India
World News
Steak ‘n Shake to start accepting Bitcoin at over 300 outlets in US from May 16
Crypto
Was Jordon Hudson Banned by UNC Amid Bill Belichick Relationship?
Celebrity
Trump Duped Into Endorsing XRP For Crypto Reserve: Here’s How
Crypto
Four big dynamics drove Colorado lawmakers’ session — from defending against Trump to boosting affordability
Politics
Bandai Namco Reports 995 Percent Increase in Profits From Previous Year
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

The vast majority of CEOs are fearful of losing their jobs to AI, survey reveals

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
The vast majority of CEOs are fearful of losing their jobs to AI, survey reveals
May 9, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?