#FudModule
Malware/Tool
2022-09-22 • 라자루스 그룹의 BYOVD를 활용한 루트킷 악성코드 분석 보고서
FudModule is a Windows kernel rootkit used by Lazarus-linked operators to disable or evade endpoint security. Documented generations progressed from bring-your-own-vulnerable-driver techniques, including abuse of a Dell DBUtil driver, to exploitation of previously unknown Windows driver flaws for administrator-to-kernel code execution. It was deployed in targeted fake-job campaigns and has also followed browser exploitation. The rootkit operates as a defense-evasion component that removes security visibility so other malware can continue running.
-
11
Tagged Reports
-
8
Unique Authors
-
1,425
Active Days