#FudModule
Malware/Tool
2023-03-20 • When the Absence of Noise Becomes Signal: Defensive Considerations for Lazarus FudModule
FudModule is a Windows kernel rootkit used by Lazarus-linked operators to disable or evade endpoint security. Documented generations progressed from bring-your-own-vulnerable-driver techniques, including abuse of a Dell DBUtil driver, to exploitation of previously unknown Windows driver flaws for administrator-to-kernel code execution. It was deployed in targeted fake-job campaigns and has also followed browser exploitation. The rootkit operates as a defense-evasion component that removes security visibility so other malware can continue running.
-
8
Tagged Reports
-
6
Unique Authors
-
1,246
Active Days