Lazarus & BYOVD: evil to the Windows core
ID: 01538bd4-958b-4fb3-80ce-6e425f1d8e92
STIX ID: report--01538bd4-958b-4fb3-80ce-6e425f1d8e92
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2022-09-19
Last Modified Date: 2022-09-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This technical Virus Bulletin paper analyzes 'FudModule', a Lazarus user-mode DLL observed in an October 2021 campaign that leverages the BYOVD technique and CVE-2021-21551 in Dell's signed DBUtil_2_3.sys to obtain kernel write access and then disable multiple Windows monitoring mechanisms (registry/object/process/image callbacks, non-legacy filesystem minifilters, WFP callouts, ETW providers, and prefetch tracing). The report provides deep kernel-level analysis of seven disabling mechanisms, runtime configuration details, proof-of-concept demonstrations, related research, and two IOCs (SHA256 of FudModule.dll and Dbutil_2_3.sys).
