PowerPoint Presentation
ID: 78dab125-74d5-4c3e-8c2c-a4a04871b708
STIX ID: report--78dab125-74d5-4c3e-8c2c-a4a04871b708
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2024-04-22
Last Modified Date: 2024-04-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Black Hat ASIA 2024 briefing presents a technical dissection of a Lazarus recruiting-scam campaign that delivers a multi-stage Windows infection (Skill Assessment.iso → AmazonVNC.exe → RollFling → RollSling → RollMid → Kaolin RAT) using social-engineered job offers; it documents exploitation of CVE-2024-21338 to gain kernel capabilities and describes FudModule 2.0, a data-only rootkit employing DKOM, ETW/minifilter/WFP tampering and direct attacks on security software to achieve stealth and persistence.
