Malware
FudModule
Also known as: LIGHTSHOW
FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique. Its main goal is to turn off Windows system monitoring features, which is done by modifying kernel variables and removing kernel callbacks. Its actions may very likely affect various types of security products, e.g. EDRs, firewalls, antimalware and even digital forensics tools.
Indicators of Compromise 7
MITRE ATT&CK TTPs 10
T1055 T1068 T1071.001 T1078 T1085 T1090 T1134 T1203 T1218 T1480
Process Injection
Defense Evasion
Exploitation for Privilege Escalation
Privilege Escalation
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
T1085
Proxy
Command And Control
Access Token Manipulation
Defense Evasion
Exploitation for Client Execution
Execution
System Binary Proxy Execution
Defense Evasion
Execution Guardrails
Defense Evasion
Source Articles
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor Lazarus Group has exploited a Windows zero-day vulnerability, CVE-2026-68820, in the AFD.sys driver to escalate privileges to SYSTEM and deploy a new in-memory backdoor named Troy. The attack is part of Operation Dream Job, a long-running cyber espionage campaign using fake job offers on LinkedIn to lure victims into downloading trojanized software or opening malicious PDFs. Two infection chains were observed: one using DLL side-loading with the malicious libmupdf.dll and another via a trojanized SecurityPDF viewer that triggers payload execution upon detecting a specific marker in a PDF. The attackers also use compromised legitimate infrastructure, including WordPress, SharePoint, and vulnerable Roundcube servers (CVE-2025-49113), to host C2 communications and distribute the ForestTiger (ScoringMathTea) backdoor.
hacker-news ·3w ago
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Microsoft's August 2026 Patch Tuesday addresses 400 vulnerabilities, including three zero-days. One of these, CVE-2026-68820, was actively exploited in the wild by the North Korean threat actor Lazarus Group to elevate privileges and deploy a kernel-mode rootkit called FudModule. The other two zero-days, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed but not confirmed as exploited. Check Point linked the exploitation of CVE-2026-68820 to Lazarus, highlighting ongoing targeting using local privilege escalation in Windows drivers.
bleeping-computer ·3w ago