Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks
ID: f6ecbc58-f597-589b-81cf-98cb7ee831fc
STIX ID: report--f6ecbc58-f597-589b-81cf-98cb7ee831fc
Feed Name: The Hacker News
Threat Score
The report describes Lazarus Group exploiting a zero-day Windows kernel privilege escalation (CVE-2024-21338) in the appid.sys driver to obtain kernel-level access and deploy the FudModule rootkit, which can disable a range of security products and evade detection; Microsoft revised the flaw's exploitability to “Exploitation Detected,” and Avast analyzed real-world weaponization that expands BYOVD techniques into an in-place driver zero-day exploit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
