Tag: FudModule

Home FudModule
Lazarus and the FudModule rootkit: Beyond BYOVD with an admin-to-kernel zero-day
Post

Lazarus and the FudModule rootkit: Beyond BYOVD with an admin-to-kernel zero-day

Cincinnati Cincinnati Key Points Avast discovered an in-the-wild admin-to-kernel exploit for a previously unknown zero-day vulnerability in the appid.sys AppLocker driver.  Thanks to Avast’s prompt report, Microsoft addressed this vulnerability as CVE-2024-21338 in the February Patch Tuesday update.  The exploitation activity was orchestrated by the notorious Lazarus Group, with the end goal of establishing a...