logo

Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks

ID: f6ecbc58-f597-589b-81cf-98cb7ee831fc

STIX ID: report--f6ecbc58-f597-589b-81cf-98cb7ee831fc

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-29

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes Lazarus Group exploiting a zero-day Windows kernel privilege escalation (CVE-2024-21338) in the appid.sys driver to obtain kernel-level access and deploy the FudModule rootkit, which can disable a range of security products and evade detection; Microsoft revised the flaw's exploitability to “Exploitation Detected,” and Avast analyzed real-world weaponization that expands BYOVD techniques into an in-place driver zero-day exploit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.