Microsoft Zero-Day Used by Lazarus in Rootkit Attack

https://www.darkreading.com/vulnerabilities-threats/microsoft-zero-day-used-by-lazarus-in-rootkit-attack

North Korean state actors Lazarus Group used a Windows AppLocker zero-day, along with a new and improved rootkit, in a recent cyberattack, researchers report.

Microsoft logo

Microsoft has updated a zero-day exploit in its AppLocker application whitelisting software, but not before the North Korean state-backed Lazarus Group was able to leverage the flaw to pull off a rootkit cyberattack.

Researchers from Avast discovered the Microsoft zero-day flaw, tracked under CVE-2024-21338, and explained that it allowed Lazarus to use an updated version of its proprietary rootkit malware called “FudModule” to cross the admin-to-kernel boundary, according to a new report.

The zero-day was fixed on Feb. 13 as a part of Microsoft’s February Patch Tuesday update, and Avast released details of the exploit on Feb. 29.

Notably, the Avast analysts reported that FudModule has been turbocharged with new functionality, including a feature that suspends protected process light (PPL) processes found in the Microsoft Defender, Crowdstrike Falcon, and HitmanPro platforms.

Further, Lazarus Group ditched its previous bring your own vulnerable driver (BYOVD) tactic to jump from admin to kernel using the more straightforward zero-day exploit approach, the team explained.

Avast also discovered a new Lazarus remote access Trojan (RAT), about which the vendor pledges to release more details later.

“Though their [Lazarus Group’s] signature tactics and techniques are well-recognized by now, they still occasionally manage to surprise us with an unexpected technical sophistication,” the Avast report said. “The FudModule rootkit serves as the latest example, representing one of the most complex tools Lazarus holds in their arsenal.”

Vulnerability management is a crucial function that requires governance and direction from cybersecurity. Although everyone shares responsibility for information security within an organization, effective governance is essential to prevent servers and endpoint patch management from falling behind. This highlights another instance where organized groups exploit zero-day vulnerabilities. What is the Mean Time To Patch (MTTP) in your organization?


Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from CSO Tips

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from CSO Tips

Subscribe now to keep reading and get access to the full archive.

Continue reading