FudModule

Aliases: LIGHTSHOW

First seen
2023-01-01 00:00:00
Malware type
rootkit, trojan
Profile updated
2026-07-07 12:47:08

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique. Its main goal is to turn off Windows system monitoring features, which is done by modifying kernel variables and removing kernel callbacks. Its actions may very likely affect various types of security products, e.g. EDRs, firewalls, antimalware and even digital forensics tools.

Detection coverage

  • 1 YARA rules

Used by threat actors

  • Citrine Sleet Chromium Zero-Day Exploit Activity (CVE-2024-7971) (campaign)

Detection rules

  • MALPEDIA_Win_Fudmodule_Auto (yara-rule)

Reports & references

  • Microsoft — North Korean Threat Actor Citrine Sleet Exploiting Chromium Zero Day (report)
  • splintersfury.github.io — Kernelsight (report)
  • ESET — Amazon Themed Campaigns Lazarus Netherlands Belgium (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Fudmodule (report)
  • gendigital.com — Lazarus Fudmodule V3 (report)
  • asec.ahnlab.com — Analysis Report On Lazarus Groups Rootkit Attack Using Byovd Sep 22 2022 (report)
  • virusbulletin.com — Vb2022 Lazarus And Byovd Evil To The Windows Core (report)
  • decoded.avast.io — Lazarus And The Fudmodule Rootkit Beyond Byovd With An Admin To Kernel Zero Day (report)
  • Mandiant — Lightshift And Lightshow (report)
  • asec.ahnlab.com — 40495 (report)
  • securityintelligence.com — Defensive Considerations Lazarus Fudmodule (report)
  • web.archive.org — From Byovd To A 0 Day Unveiling Advanced Exploits In Cyber Recruiting Scams (report)
  • securityintelligence.com — Direct Kernel Object Manipulation Attacks Etw Providers (report)
  • decoded.avast.io — From Byovd To A 0 Day Unveiling Advanced Exploits In Cyber Recruiting Scams (report)

External references