North Korean hackers installed rootkits on thousands of PCs via Windows zero-day vulnerability

Cybersecurity researchers have discovered that the hacker group Lazarus, believed to be linked to the North Korean government, used a zero-day vulnerability in Windows to install a sophisticated FudModule rootkit. The vulnerability allows you to gain maximum rights in the system.

Image source: anonymous_Pete-Linforth/Pixabay

As reported by Ars Technica with reference to representatives of the Gen company, the vulnerability, which received the identifier CVE-2024-38193, belongs to the “use after free” class and is located in the AFD.sys driver, which is used to work with the Winsock protocol and serves as an entry point into operating system kernel. Microsoft has warned that this vulnerability could be used by attackers to gain system privileges that allow them to execute unverified code.

«The vulnerability allowed attackers to bypass standard security mechanisms and gain access to sensitive areas of the system that are inaccessible to most users and even administrators, says the Gen report. “This type of attack is complex and resource-intensive, and its cost on the black market can reach several hundred thousand dollars.” Recall that the FudModule rootkit was first discovered in 2022. It is able to hide its malicious presence in the system, bypassing antiviruses and other security measures.

Previously, Lazarus hackers used the “Bring your own vulnerable driver” technique to install earlier versions of FudModule. However, this time they took advantage of a bug in the appid.sys system driver, which was present by default in all versions of Windows until today.

Gen has not disclosed details regarding how long hackers have been exploiting the CVE-2024-38193 vulnerability, how many organizations have been affected by the attacks, or whether antivirus programs were able to detect the latest version of FudModule.

admin

Share
Published by
admin

Recent Posts

Ubisoft spoke about the capabilities and innovations of stealth mechanics in Assassin’s Creed Shadows – new gameplay

Image source: Ubisoft Let us remind you that the events of Assassin’s Creed Shadows will…

32 minutes ago

Assembly of the second NASA SLS rocket has started – in a year it will send people on a flight around the Moon

NASA announced that assembly of the second lunar rocket, SLS (Space Launch System), has begun…

32 minutes ago

The creators of Black Myth: Wukong will surprise players before the end of the year – teaser from the head of Game Science

Co-founder and CEO of the Chinese studio Game Science, Feng Ji, hinted that some surprises…

2 hours ago

Nvidia stock is no longer the best performer – MicroStrategy soars 500% in a year thanks to Bitcoin

Last Wednesday, trading volume in MicroStrategy shares exceeded that of Nvidia and Tesla. The company,…

3 hours ago

Tired of waiting: sales of S.T.A.L.K.E.R. 2: Heart of Chornobyl exceeded one million copies within two days of release

The post-apocalyptic open-world shooter S.T.A.L.K.E.R. 2: Heart of Chornobyl from the developers from the GSC…

4 hours ago

TSMC to start producing 1.6-nm chips in two years

TSMC's plans for the next couple of years remain largely unchanged - by the end…

4 hours ago