#LIGHTSHOW
Malware/Tool
2023-03-09 • Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW
LIGHTSHOW is a Windows defense-evasion utility used by the suspected North Korean group UNC2970. Loaded in memory by the LIGHTSHIFT dropper, it is packed with VMProtect and bound to a specific target through a SHA-256 value derived from the computer name. LIGHTSHOW drops and registers a legitimate but vulnerable driver, loads a dummy DLL to present itself as an authorized caller, and gains arbitrary kernel-memory read and write access. It then patches kernel routines used by endpoint detection products, enabling bring-your-own-vulnerable-driver evasion before unloading and deleting supporting artifacts.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days