#LIGHTSHOW

Malware/Tool

2023-03-09 • Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW

LIGHTSHOW is a Windows defense-evasion utility used by the suspected North Korean group UNC2970. Loaded in memory by the LIGHTSHIFT dropper, it is packed with VMProtect and bound to a specific target through a SHA-256 value derived from the computer name. LIGHTSHOW drops and registers a legitimate but vulnerable driver, loads a dummy DLL to present itself as an authorized caller, and gains arbitrary kernel-memory read and write access. It then patches kernel routines used by endpoint detection products, enabling bring-your-own-vulnerable-driver evasion before unloading and deleting supporting artifacts.

Tagged Reports

« Back