#BYOVD

Malware/Tool

2022-09-22 • 라자루스 그룹의 BYOVD를 활용한 루트킷 악성코드 분석 보고서

BYOVD, or Bring Your Own Vulnerable Driver, is a Windows attack technique in which an attacker installs an exploitable driver to move from administrative access into kernel mode. Lazarus used known vulnerable drivers, including a Dell driver affected by CVE-2021-21551, to enable versions of the FudModule data-only rootkit. Kernel access let FudModule manipulate kernel structures, impair Event Tracing for Windows telemetry, and bypass or disable security technology. Later activity replaced BYOVD with exploitation of CVE-2024-21338 in the built-in AppLocker driver for greater stealth.

Tagged Reports

« Back