Thursday, November 14, 2024

Windows driver zero-day exploited by Lazarus hackers to install rootkit

Windows driver zero-day exploited by Lazarus hackers to install rootkit
Image: Midjourney

The notorious North Korean Lazarus hacking group exploited a zero-day flaw in the Windows AFD.sys driver to elevate privileges and install the FUDModule rootkit on targeted systems.

Microsoft fixed the flaw, tracked as CVE-2024-38193 during its August 2024 Patch Tuesday, along with seven other zero-day vulnerabilities.

CVE-2024-38193 is a Bring Your Own Vulnerable Driver (BYOVD) vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), which acts as an entry point into the Windows Kernel for the Winsock protocol.

The flaw was discovered by Gen Digital researchers, who say that the Lazarus hacking group exploited the AFD.sys flaw as a zero-day to install the FUDModule rootkit, used to evade detection by turning off Windows monitoring features.

“In early June, Luigino Camastra and Milanek discovered that the Lazarus group was exploiting a hidden security flaw in a crucial part of Windows called the AFD.sys driver,” warned Gen Digital.

“This flaw allowed them to gain unauthorized access to sensitive system areas. We also discovered that they used a special type of malware called Fudmodule to hide their activities from security software.”

A Bring Your Own Vulnerable Driver attack is when attackers install drivers with known vulnerabilities on targeted machines, which are then exploited to gain kernel-level privileges. Threat actors often abuse third-party drivers, such as antivirus or hardware drivers, which require high privileges to interact with the kernel.

What makes this particular vulnerability more dangerous is that the vulnerability was in AFD.sys, a driver that is installed by default on all Windows devices. This allowed the threat actors to conduct this type of attack without having to install an older, vulnerable driver that may be blocked by Windows and easily detected.

The Lazarus group has previously abused the Windows appid.sys and Dell dbutil_2_3.sys kernel drivers in BYOVD attacks to install FUDModule.

The Lazarus hacking group

While Gen Digital did not share details about who was targeted in the attack and when the attacks occurred, Lazarus is known to target financial and cryptocurrency firms in million-dollar cyberheists used to fund the North Korean government’s weapons and cyber programs.

The group gained notoriety after the 2014 Sony Pictures blackmail hack and the 2017 global WannaCry ransomware campaign that encrypted businesses worldwide.

In April 2022, the US government linked the Lazarus group to a cyberattack on Axie Infinity that allowed the threat actors to steal over $617 million worth of cryptocurrency.

The US government offers a reward of up to $5 million for tips on the DPRK hackers’ malicious activity to help identify or locate them.

Related Articles

Latest Articles