logo

Lazarus & BYOVD: evil to the Windows core

ID: 01538bd4-958b-4fb3-80ce-6e425f1d8e92

STIX ID: report--01538bd4-958b-4fb3-80ce-6e425f1d8e92

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2022-09-19

Last Modified Date: 2022-09-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This technical Virus Bulletin paper analyzes 'FudModule', a Lazarus user-mode DLL observed in an October 2021 campaign that leverages the BYOVD technique and CVE-2021-21551 in Dell's signed DBUtil_2_3.sys to obtain kernel write access and then disable multiple Windows monitoring mechanisms (registry/object/process/image callbacks, non-legacy filesystem minifilters, WFP callouts, ETW providers, and prefetch tracing). The report provides deep kernel-level analysis of seven disabling mechanisms, runtime configuration details, proof-of-concept demonstrations, related research, and two IOCs (SHA256 of FudModule.dll and Dbutil_2_3.sys).