• Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
AnonyViet - English Version
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
AnonyViet - English Version
No Result
View All Result

North Korean hackers take advantage of Windows vulnerabilities to attack with Rootkits

AnonyViet by AnonyViet
March 2, 2024
in News
0

The notorious hacker group Lazarus from North Korea exploited a “zero-day” security vulnerability in the Windows operating system to escalate privileges to mistakenly attack users. This is part of their attack campaign using a rootkit called FudModule.

North Korean hackers take advantage of Windows vulnerabilities to attack with Rootkits

This vulnerability, codenamed CVE-2024-21338, discovered by Avast during Lazarus attacks last year. The company created a test exploit (PoC) and submitted a report to Microsoft in August 2023.

Microsoft patched the vulnerability during its “Patch Tuesday” security update in February 2024. However, the initial announcement of CVE-2024-21338 did not mention that it had been exploited In reality. On Wednesday, the tech giant updated its notification to warn customers that the exploit was still ongoing.

Avast's blog post on Wednesday provided a detailed technical description of the vulnerability and how Lazarus exploited this CVE to distribute the rootkit. The location of the attack is located in the 'appid.sys' driver related to Microsoft's AppLocker security feature. Instead of installing malicious drivers themselves (BYOVD), Hackers will target a driver available in many systems to avoid detection.

Rootkits is a type of malware (malware. malware) is designed to hide its or other malware's existence in the computer system. Rootkits penetrate deeply into the system with high-level access (root or administrator), allowing hackers to control the entire system without being detected. Rootkits can cause many security problems, including stealing personal information, monitoring user activity, and installing additional malware. Due to their high level of concealment, rootkits are difficult to detect and remove.

Avast explains: “By exploiting such vulnerabilities, Hackers minimize saving or downloading other malicious drivers.” This helps Hackers attack the system kernel (kernel) so they can bypass most detection mechanisms and even work on systems that apply driver control.

Through CVE-2024-21338, hacker Lazarus has elevated User rights on the compromised system and created a direct read/write mechanism at the operating system kernel level. This trick allows them to directly manipulate kernel objects in the updated version of the FudModule rootkit (appearing in 2022).

The new rootkit version has improvements that increase stealth and disable security software AhnLab V3 Endpoint Security, Windows Defender, CrowdStrike Falcon and HitmanPro.

The Lazarus campaign tracked by Avast also used a remote access trojan (RAT) new, detailed information will be announced by the company later.

Tags: advantageAttackhackersKoreanNorthRootkitsVulnerabilitiesWindows
Previous Post

How to get free Microsoft AI certificate – ASIA AI ODYSSEY

Next Post

How to create a file with arbitrary capacity using CMD

AnonyViet

AnonyViet

Related Posts

Don’t rush to buy a new MacBook if you don’t know these differences
News

Don’t rush to buy a new MacBook if you don’t know these differences

May 20, 2026
Reputable LG repair service in Hanoi & Ho Chi Minh City with LGservicecenter
News

Reputable LG repair service in Hanoi & Ho Chi Minh City with LGservicecenter

April 21, 2026
Japanese Watch Week: Choose the color that suits your destiny, start the new year well at Mobile World
News

Japanese Watch Week: Choose the color that suits your destiny, start the new year well at Mobile World

April 20, 2026
MacBook Air M2 review: 2026 price hits rock bottom, what else?
News

MacBook Air M2 review: 2026 price hits rock bottom, what else?

March 14, 2026
Ứng dụng cầu nguyện của Iran bị hack, gửi thông điệp kêu gọi đầu hàng
News

Ứng dụng cầu nguyện của Iran bị hack, gửi thông điệp kêu gọi đầu hàng

March 1, 2026
How many colors does the Samsung Galaxy S26 Series come in and what are the shades that will cause a stir in 2026?
News

How many colors does the Samsung Galaxy S26 Series come in and what are the shades that will cause a stir in 2026?

February 26, 2026
Next Post
How to create a file with arbitrary capacity using CMD

How to create a file with arbitrary capacity using CMD

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest

guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recent News

Instructions on how to prevent acquaintances from seeing your Tiktok

Instructions on how to prevent acquaintances from seeing your Tiktok

June 2, 2026
How to record reaction videos with Android phones, no app needed

How to record reaction videos with Android phones, no app needed

June 1, 2026
Instructions on how to get Google AI Pro 1 year for free for new accounts

Instructions on how to get Google AI Pro 1 year for free for new accounts

June 1, 2026
Top free AI tools to help write, test and optimize content

Top free AI tools to help write, test and optimize content

June 1, 2026
Instructions on how to prevent acquaintances from seeing your Tiktok

Instructions on how to prevent acquaintances from seeing your Tiktok

June 2, 2026
How to record reaction videos with Android phones, no app needed

How to record reaction videos with Android phones, no app needed

June 1, 2026
Instructions on how to get Google AI Pro 1 year for free for new accounts

Instructions on how to get Google AI Pro 1 year for free for new accounts

June 1, 2026
AnonyViet - English Version

AnonyViet

AnonyViet is a website share knowledge that you have never learned in school!

We are ready to welcome your comments, as well as your articles sent to AnonyViet.

Follow Us

Contact:

Email: anonyviet.com[@]gmail.com

Main Website: https://anonyviet.com

Recent News

Instructions on how to prevent acquaintances from seeing your Tiktok

Instructions on how to prevent acquaintances from seeing your Tiktok

June 2, 2026
How to record reaction videos with Android phones, no app needed

How to record reaction videos with Android phones, no app needed

June 1, 2026
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply