Windows driver zero-day exploited by Lazarus hackers to install rootkit
ID: 8766df98-feee-591a-9395-9f137e1164dc
STIX ID: report--8766df98-feee-591a-9395-9f137e1164dc
Feed Name: Bleeping Computer
Threat Score
The report details how the Lazarus APT exploited a zero-day in the Windows AFD.sys driver (CVE-2024-38193) via a Bring Your Own Vulnerable Driver (BYOVD) technique to gain kernel privileges and deploy the FUDModule rootkit, and ties this activity to targeted campaigns against Brazilian cryptocurrency professionals; Microsoft released a patch in August 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
