When the Absence of Noise Becomes Signal: Defensive Considerations for Lazarus FudModule

2023-03-20 IBM

https://securityintelligence.com/posts/defensive-considerations-lazarus-fudmodule/

Thumbnail for When the Absence of Noise Becomes Signal: Defensive Considerations for Lazarus FudModule

IBM Security X-Force examined defensive detection opportunities for Lazarus FudModule, a malware component previously analyzed for tampering with Event Tracing for Windows. The source says FudModule installs a Dell driver vulnerable to CVE-2021-21551 to gain kernel-mode privileges in a bring-your-own-vulnerable-driver attack, enabling Direct Kernel Object Manipulation against ETW registration handles. By nulling ETW provider handles, the malware can reduce telemetry available to operating system, antivirus, and EDR consumers without necessarily preventing defenders from creating new ETW sessions. X-Force recommends monitoring data-stream health and comparing expected telemetry across ETW sessions as a way to detect blind spots caused by this kind of Lazarus defense-evasion tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0296e2ce999e67c76352613a718e115… 2022-09-30 2024-09-02
HASH 97c78020eedfcd5611872ad7c57f812… 2022-09-30 2023-03-20

Related Reports

« Back