Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW
2023-03-09 • Mandiant •
https://www.mandiant.com/resources/blog/lightshift-and-lightshow
Mandiant describes how North Korea-linked UNC2970 used Bring Your Own Vulnerable Driver techniques to support intrusion operations and evade endpoint defenses. Investigators recovered Share.DAT, decoded it into the in-memory LIGHTSHIFT dropper, and linked it to LIGHTSHOW, a VMProtect-packed utility that required a host-specific computer-name hash before fully executing. LIGHTSHOW dropped and loaded vulnerable legitimate drivers, including Dell DBUtil 2.3 and ENE Technology drivers seen in KDU-style tooling, registered a dummy SB_SMBUS_SDK.dll caller, and used kernel read/write primitives to patch routines that EDR products may monitor. The report notes overlap with AhnLab’s Lazarus BYOVD reporting and warns that UNC2970 is likely to continue abusing vulnerable vendor drivers.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9176f177bd88686c6beb29d8bb05f20c | 2023-03-09 | 2023-03-09 |
| HASH | ad452d161782290ad5004b2c9497074f | 2023-03-09 | 2023-03-09 |
| HASH | def6f91614cb47888f03658b28a1bda6 | 2023-03-09 | 2023-03-09 |
| HASH | 175eed7a4c6de9c3156c7ae16ae85c5… | 2023-03-09 | 2023-03-09 |
| HASH | 7e6e2ed880c7ab115fca68136051f9ce | 2023-03-09 | 2023-03-09 |