#LIGHTSHIFT
Malware/Tool
2023-03-09 • Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW
LIGHTSHIFT is an in-memory dropper used by North Korean group UNC2970 in a Bring Your Own Vulnerable Driver operation. It was recovered by XOR-decoding Share.DAT from C:\ProgramData\USOShared. Once loaded, LIGHTSHIFT delivers the LIGHTSHOW payload in memory, invokes its exports in sequence, and writes a hexadecimal address returned by the final call to C:\Windows\windows.ini. LIGHTSHOW then drops a legitimate but vulnerable driver and manipulates kernel data structures to support defense evasion. LIGHTSHIFT therefore serves as the memory-resident deployment stage for the host-specific LIGHTSHOW utility rather than performing the driver manipulation itself.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days