2022-2024 North Korea Citrine Sleet /Lazarus FUDMODULE ( BYOVD ) Rootkit Samples

2024-09-02 Contagio

https://contagiodump.blogspot.com/2024/09/2022-2024-north-korea-citrine-sleet.html

Thumbnail for 2022-2024 North Korea Citrine Sleet /Lazarus FUDMODULE ( BYOVD ) Rootkit Samples

Contagio Dump provides a sample collection for North Korea-linked Citrine Sleet and Lazarus FUDMODULE bring-your-own-vulnerable-driver rootkit activity spanning 2022 to 2024. The excerpt references Microsoft's reporting on Citrine Sleet exploiting a Chromium zero-day and a separate deep dive into Lazarus FudModule rootkit operations. The file list includes DLL samples and vulnerable-driver-related artifacts, including a DBUtil 2.3 Sys sample, DSROLE DLL, and several SHA-256 hashes grouped under AhnLab and Avast/GenDigital Black Hat Asia material. The main value is as an evidence and sample index for defenders tracking DPRK-linked kernel-level rootkit tooling and BYOVD tradecraft rather than as a narrative intrusion report.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cbd1634cf7c638f2faf5e3ec79137db… 2024-09-02 2026-04-03
HASH d9add2bfdfebfa235575687de356f0c… 2024-09-02 2024-09-02
HASH 381d3ba5fd446e53f1c71f05a2b9712… 2024-09-02 2024-09-02
HASH 4b1cba57928e02665be444a51937228… 2024-09-02 2024-09-02
HASH 0296e2ce999e67c76352613a718e115… 2022-09-30 2024-09-02

Related Actors

Related Reports

« Back