Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW

2023-03-09 Mandiant

https://www.mandiant.com/resources/blog/lightshift-and-lightshow

Thumbnail for Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW

Mandiant describes how North Korea-linked UNC2970 used Bring Your Own Vulnerable Driver techniques to support intrusion operations and evade endpoint defenses. Investigators recovered Share.DAT, decoded it into the in-memory LIGHTSHIFT dropper, and linked it to LIGHTSHOW, a VMProtect-packed utility that required a host-specific computer-name hash before fully executing. LIGHTSHOW dropped and loaded vulnerable legitimate drivers, including Dell DBUtil 2.3 and ENE Technology drivers seen in KDU-style tooling, registered a dummy SB_SMBUS_SDK.dll caller, and used kernel read/write primitives to patch routines that EDR products may monitor. The report notes overlap with AhnLab’s Lazarus BYOVD reporting and warns that UNC2970 is likely to continue abusing vulnerable vendor drivers.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9176f177bd88686c6beb29d8bb05f20c 2023-03-09 2023-03-09
HASH ad452d161782290ad5004b2c9497074f 2023-03-09 2023-03-09
HASH def6f91614cb47888f03658b28a1bda6 2023-03-09 2023-03-09
HASH 175eed7a4c6de9c3156c7ae16ae85c5… 2023-03-09 2023-03-09
HASH 7e6e2ed880c7ab115fca68136051f9ce 2023-03-09 2023-03-09

Related Actors

Related Reports

« Back