#FudModule

Malware/Tool

2023-03-20 • When the Absence of Noise Becomes Signal: Defensive Considerations for Lazarus FudModule

FudModule is a Windows kernel rootkit used by Lazarus-linked operators to disable or evade endpoint security. Documented generations progressed from bring-your-own-vulnerable-driver techniques, including abuse of a Dell DBUtil driver, to exploitation of previously unknown Windows driver flaws for administrator-to-kernel code execution. It was deployed in targeted fake-job campaigns and has also followed browser exploitation. The rootkit operates as a defense-evasion component that removes security visibility so other malware can continue running.

Tagged Reports

« Back