← Back to Daily Briefing (#APT44)

The Lazarus Group is exploiting a zero-day vulnerability in the Microsoft Windows Ancillary Function Driver (afd.sys) to achieve kernel-level execution. This vulnerability allows for a direct privilege escalation path from user-mode to kernel-mode, facilitating the deployment of the FudModule v3 rootkit. This kernel-mode driver utilizes advanced hooking techniques—such as SSDT or DKOM—to ensure stealth by hiding processes, files, and network connections. The campaign specifically targets the subversion of Windows AppLocker and the neutralization of EDR/AV effectiveness, enabling long-term, undetectable espionage and data exfiltration within high-value enterprise and financial environments.

  • Exploitation Mechanics: Kernel-Mode Escalation
    • Exploitation of the afd.sys driver to bypass user-mode security boundaries.
    • Transition from user-mode to kernel-mode via a zero-day vulnerability.
    • Successful bypass of traditional user-mode security controls.
  • Malware Analysis: FudModule v3 Rootkit
    • Deployment of a highly stealthy kernel-mode .sys driver.
    • Utilization of IOCTL (Input/Output Control) codes for stealthy communication.
    • Implementation of SSDT/DKOM hooking to mask files, processes, and network connections.
  • Evasion and Persistence Strategies
    • Subversion of Windows AppLocker via driver-level exploitation.
    • Neutralization of EDR/AV solutions through kernel-level blind-spot exploitation.
    • Persistence maintained through registry modifications and service hijacking.
  • Threat Intelligence and Impact
    • Attributed to the Lazarus Group, a sophisticated North Korean state-sponsored APT.
    • Critical severity: Total loss of host integrity and system call interception capabilities.
    • Targeted at high-value enterprise and financial sectors for long-term espionage.

Related posts

  1. Cybersecurity News — Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule Rootkit
  2. Blackswan-cybersecurity
  3. Rewterz
  4. Gendigital
  5. Petri
  6. Darkreading
  7. Asec
  8. Ibm
  9. Securityaffairs
  10. Medium

LINK COPIED TO CLIPBOARD