FudModule
Aliases: LIGHTSHOW
- First seen
- 2023-01-01 00:00:00
- Malware type
- rootkit, trojan
- Profile updated
- 2026-07-07 12:47:08
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique. Its main goal is to turn off Windows system monitoring features, which is done by modifying kernel variables and removing kernel callbacks. Its actions may very likely affect various types of security products, e.g. EDRs, firewalls, antimalware and even digital forensics tools.
Detection coverage
- 1 YARA rules
Used by threat actors
- Citrine Sleet Chromium Zero-Day Exploit Activity (CVE-2024-7971) (campaign)
Detection rules
- MALPEDIA_Win_Fudmodule_Auto (yara-rule)
Reports & references
- Microsoft — North Korean Threat Actor Citrine Sleet Exploiting Chromium Zero Day (report)
- splintersfury.github.io — Kernelsight (report)
- ESET — Amazon Themed Campaigns Lazarus Netherlands Belgium (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Fudmodule (report)
- gendigital.com — Lazarus Fudmodule V3 (report)
- asec.ahnlab.com — Analysis Report On Lazarus Groups Rootkit Attack Using Byovd Sep 22 2022 (report)
- virusbulletin.com — Vb2022 Lazarus And Byovd Evil To The Windows Core (report)
- decoded.avast.io — Lazarus And The Fudmodule Rootkit Beyond Byovd With An Admin To Kernel Zero Day (report)
- Mandiant — Lightshift And Lightshow (report)
- asec.ahnlab.com — 40495 (report)
- securityintelligence.com — Defensive Considerations Lazarus Fudmodule (report)
- web.archive.org — From Byovd To A 0 Day Unveiling Advanced Exploits In Cyber Recruiting Scams (report)
- securityintelligence.com — Direct Kernel Object Manipulation Attacks Etw Providers (report)
- decoded.avast.io — From Byovd To A 0 Day Unveiling Advanced Exploits In Cyber Recruiting Scams (report)