logo

Windows driver zero-day exploited by Lazarus hackers to install rootkit

ID: 8766df98-feee-591a-9395-9f137e1164dc

STIX ID: report--8766df98-feee-591a-9395-9f137e1164dc

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-08-20

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

The report details how the Lazarus APT exploited a zero-day in the Windows AFD.sys driver (CVE-2024-38193) via a Bring Your Own Vulnerable Driver (BYOVD) technique to gain kernel privileges and deploy the FUDModule rootkit, and ties this activity to targeted campaigns against Brazilian cryptocurrency professionals; Microsoft released a patch in August 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.