FILTERING BY: CLEAR FILTER

Microsoft Windows afd.sys Zero-Day Exploitation by Lazarus Group

The Lazarus Group is exploiting a zero-day vulnerability in the Microsoft Windows Ancillary Function Driver (afd.sys) to achieve kernel-level execution. This vulnerability allows for a direct privilege escalation path from user-mode to kernel-mode, facilitating the deployment of the FudModule v3 rootkit. This kernel-mode driver utilizes advanced hooking techniques—such as SSDT or DKOM—to ensure stealth by hiding processes, files, and network connections. The campaign specifically targets the subversion of Windows AppLocker and the neutralization of EDR/AV effectiveness, enabling long-term, undetectable espionage and data exfiltration within high-value enterprise and financial environments.


LINK COPIED TO CLIPBOARD