logo

Lazarus hackers exploited Windows zero-day to gain Kernel privileges

ID: 53ca4dcb-bb1b-5d6e-b855-e84df0daca17

STIX ID: report--53ca4dcb-bb1b-5d6e-b855-e84df0daca17

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-02-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

### Executive Summary Avast analysts discovered Lazarus exploiting a flaw in the Windows AppLocker driver (CVE-2024-21338) to obtain a kernel-level primitive and deploy an updated FudModule rootkit and an undocumented RAT that can disable security products (including Microsoft Defender and CrowdStrike) and maintain stealthy persistence; Avast reported the activity to Microsoft, which released a February 2024 patch and provided YARA rules for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.