#LIGHTSHIFT

Malware/Tool

2023-03-09 • Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW

LIGHTSHIFT is an in-memory dropper used by North Korean group UNC2970 in a Bring Your Own Vulnerable Driver operation. It was recovered by XOR-decoding Share.DAT from C:\ProgramData\USOShared. Once loaded, LIGHTSHIFT delivers the LIGHTSHOW payload in memory, invokes its exports in sequence, and writes a hexadecimal address returned by the final call to C:\Windows\windows.ini. LIGHTSHOW then drops a legitimate but vulnerable driver and manipulates kernel data structures to support defense evasion. LIGHTSHIFT therefore serves as the memory-resident deployment stage for the host-specific LIGHTSHOW utility rather than performing the driver manipulation itself.

Tagged Reports

« Back