Windows 0-Day Was Exploited By North Korea To Install Advanced Rootkit

windows-0-day-was-exploited-by-north-korea-to-install-advanced-rootkit
Windows 0-Day Was Exploited By North Korea To Install Advanced Rootkit

Posted by msmash from the closer-look dept.

North Korean hackers exploited a critical Windows vulnerability to deploy advanced malware, security researchers revealed. The zero-day flaw, patched by Microsoft last week, allowed attackers to gain system-level access and install a sophisticated rootkit called FudModule. Gen, the firm that discovered the attacks, identified the threat actors as Lazarus, a hacking group linked to North Korea. The exploit targeted individuals in cryptocurrency and aerospace industries, likely aiming to steal digital assets and infiltrate corporate networks. FudModule, first analyzed in 2022, stands out for its ability to operate deep within Windows, evading detection by security defenses. Earlier versions used vulnerable drivers for installation, while a newer variant exploited a bug in Windows’ AppLocker service.

The flow chart is a most thoroughly oversold piece of program documentation. — Frederick Brooks, “The Mythical Man Month”

Working…